Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Security by obscurity. Surely the information on the vulnerability is already out there by the time the patch is released?


No, not necessarily. That's the point of those disclosure timelines.


Security by obscurity can work just fine when it's a two week extension on a bug that has existed for years.


But it never ends at two weeks. Time and time again the vendors will put it off for years if you let them.


I'm defending monthly patches here, not giving vendors extra time.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: