|
|
|
|
|
by IshKebab
41 days ago
|
|
I dunno, if you think about it for more than a few seconds you can see the obvious holes in it, like it's definitely true that some bugs are "may allow RCE", but you also can do a LOT better than not even trying. And even if you do say "we're not putting the effort in to backport security fixes" (which is fine), that doesn't entail "security bugs are just bugs". These are smart people. If it wasn't about their own project I really think they'd have a different point of view. I wonder what they say about Microsoft's security bugs for example! |
|
People can earnestly believe illogical or inconsistent things. Arguably those are even easier to get stuck believing, as you already had to accept some friction in the inconsistencies earlier in your internalizing them, so now you're even further into sunk costs around it.