Hacker News new | ask | show | jobs
by somat 257 days ago
> "practically every CVE is on code you can read."

This is probably true due to a sort of survivorship bias. code you can read is much easier to analyze and test and report. Closed source internal code has a lot of security by obscurity built into it. Not to dismiss security by obscurity, I am sure it keeps an absolute frightening amount of code safe.

1 comments

> Not to dismiss security by obscurity, I am sure it keeps an absolute frightening amount of code safe.

“The oldest and strongest emotion of mankind is fear, and the oldest and strongest kind of fear is fear of the unknown.” H.P. Lovecraft