|
|
|
|
|
by dx87
2746 days ago
|
|
I wouldn't be suprised. I've done some unclassified govt contracting and it wasn't uncommon for them to include clauses in software purchase contracts that they had to be re-imbursed a certain amount of money any time a security vulnerability was discovered in the purchased software. The reasoning was that they had to spend money identifying, reporting, and updating systems, so the vendor had to pay for wasted resources. |
|