Hacker News new | ask | show | jobs
by Retr0id 1184 days ago
I'm quite confident that I'd have spotted the security relevance at the time, and I have a track record of finding "implementation bugs" given only APIs and specifications. But, I'm a security researcher, not a software engineer.

My takeaway would be that they should have security-brained people screening "non-security" bugs, to check for potential security relevance.