Hacker News new | ask | show | jobs
by rrdharan 988 days ago
Agree with everything you said except possibly:

> The risk that attackers will suddenly find the flaw after years because they were told "there's a flaw in cURL" seems low.

I’m not so sure about that. Still understand why they’re handling it this way but this is bait like a big red bullseye or rainbow with a pot of gold at the bottom …