Hacker News new | ask | show | jobs
by sanbor 2938 days ago
In security many things are "potential" threats. Just being unlikely doesn't mean that the threat doesn't exists. For example, a guy found a potential threat in rails[1], and rails developers dismissed his findings as unlikely exploitable. Then the guy go and hacked GitHub to prove that the issue was real[2][3] and that even the best rails developers were vulnerable.

[1] https://github.com/rails/rails/issues/5228

[2] https://github.com/rails/rails/commit/b83965785db1eec019edf1...

[3] https://arstechnica.com/information-technology/2012/03/hacke...