Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

As Lulzsec so clumsily illustrated, you can't know because most vulnerabilities are silently patched, or undiscovered (but still in use without the site's knowledge.) Any such index would more likely penalize the most honest than the most vulnerable.


Are you saying its better not to know? It wouldn't be hard determine is a site is CSRF vulnerable.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: