Hacker News new | ask | show | jobs
by yorwba 2339 days ago
That article is based on Finite State's report, who sell static analysis software and are highly incentivized to not check too closely whether everything flagged by their tool is actually a vulnerability. They probably did find a bunch, but not nearly as much as they claim.

There was some good discussion on the report 6 months ago: https://news.ycombinator.com/item?id=20421148