|
|
|
|
|
by despera
2181 days ago
|
|
I understand that completely and i already know your thoughts on that and in some extend i do agree. Still, i think we do have in hand a very characteristic issue that even without knowing the details, simply by searching commit messages for "crypto" "key" "buffer" etc it should alert somebody to give it a second and third look. |
|
The only thing (far!) worse than no impact marking is incomplete impact marking. That's just giving people a way to cop out, and they WILL use it.