Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Having a history of security flaws is better than having a future of security flaws.


Arguably OpenSSL has both.


there are the same amount of security bugs in almost any software, and the number shows some correlation with the lines of code count. Strictly from the code point of view you can follow best practices and actively training the stuff on security. This cost money and time and nobody really wants to do it. The companies started to do this invested serious amount of money into the project and it shows in the statistics.

http://www.gfi.com/blog/most-vulnerable-operating-systems-an...

In open source this is more of a community thing with little discipline, the nature of the software development is less tight, this yields to mediocre results.

I guess the at Apple security is as far is from design as something can be, probably not a high priority.

Knowing the historical flaws is only useful if invest into mining it and act on the results.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: