|
|
|
|
|
by paddlepop
2517 days ago
|
|
MITREs response to this is a perfect example of the old-school security team mindset.
If I had a nickel for every security team I've worked with that a) treat reporting as gospel and don't validate it, and b) don't talk to the developer.
From my experience the key issue is they don't understand the issue enough to engage in a meaningful discussion with the developer |
|
So, they are the root CNA for VLC bugs, and they don't triage them correctly. And don't update the issues when we mention them.