Hacker News new | ask | show | jobs
by haswell 408 days ago
I agree with the conclusion that we need safer software from the start.

But we also have to deal with the reality of the situation in front of us.

I will maintain that the differences between the implications of revealing a crack in a bridge vs. prematurely revealing a vulnerability to literally the entire world are stark. I find it pretty problematic to continue comparing them and a rather poor analogy.

> There are large numbers of state funded exploit groups and otherwise blackhat organizations that find and store these vulnerabilities

This underscores my point. What you’ve been describing is a scenario in which those organizations are handed new ammunition for free (assuming they don’t already have the vuln in their catalog).