logoalt Hacker News

tptacekyesterday at 9:22 PM2 repliesview on HN

People have said that for decades and it wasn't true until recently.


Replies

joatmon-snootoday at 12:33 AM

Hmm: can you elaborate?

I've never been on a security-specific team, but it's always seemed to me that triggering a bug is, for the median issue, easier than fixing it, and I mentally extend that to security issues. This holds especially true if the "bug" is a question about "what is the correct behavior?", where the "current behavior of the system" is some emergent / underspecified consequence of how different features have evolved over time.

I know this is your career, so I'm wondering what I'm missing here.

show 1 reply
underdeserveryesterday at 9:32 PM

Specifically in software vulnerability research, you mean.

Fixing vulnerable code is usually trivial.

In the physical world breaking things is usually easier.