@Fork_Merge@mastodon.social
@nerdpr0f@infosec.exchange @cR0w@infosec.exchange
My theory is most vulnerabilities in that class exist because the platform was built on something long exploited but they refused to patch also known as "somebody else's problem"......
@nerdpr0f@infosec.exchange
@Fork_Merge@mastodon.social @cR0w@infosec.exchange My hypothesis is that it's a function of the push for time-to-market. Rather than give people the time needed to develop a complex platform that works well and is sustainable long-term, the market forces incentivize behaviors that prioritize short-term optimization over long-term risk reduction.