AI is Breaking Two Vulnerability Cultures
A week ago the Copy Fail
vulnerability came out, and Hyunwoo Kim immediately realized that the
fixes were insufficient, sharing a patch the same
day. In doing this he followed standard procedure for Linux,
especially within networking: share the security impact with a closed
list of Linux security engineers, while fixing the bug quietly and
efficiently in the open. His goal was that with only the raw fix
public, the knowledge that a serious vulnerability existed
could be "embargoed": the peopl...
Read more at jefftk.com