Hacker News new | ask | show | jobs
by loop22 792 days ago
> No damage-control lawyerly BS, no 'ego'

And no cutesy name for the vulnerability

3 comments

The "Dragon Eater Vulnerability", that all managers will agitate about mitigating for the next 4 weeks...
SillyPutty
Canon now.
Seconded.
I think named vulnerabilities are useful when it's a "STOP THE WORLD" kind of vulnerability like Heartbleed and Shellshock. It's much easier to talk about Heartbleed than "CVE-2014-0160".

The problem, IMO, is when medium-severity vulnerabilities are given names, like Terrapin. I think it makes people think a vulnerability is much worse than it really is.

Heartbleed was a decade ago? JFC I’m getting old