Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

TLDR: I strongly disagree.

"...especially if those systems haven't been hardened..."

Well that's just it, isn't it? If the system hasn't been hardened then it wouldn't hold anything of interest and therefore wouldn't be targeted by either friendly researchers or malicious adversaries.

If a system holds value it should be appropriately secured. That must include dealing with attacks as part of business as usual.

As for meaningful, selective pressure - well then why bother with bug bounties? Even Microsoft, the only organisation at that level with a published SDL [edit: security development lifecycle], offers them now.

SDL ref. http://msdn.microsoft.com/en-us/library/windows/desktop/cc30...

I've had my rant. Will shut up now.



Microsoft has been throwing huge amounts of money at this problem for over a decade, and Microsoft's systems are not perfectly or even (if we take a hard, dispassionate look at it) acceptably secured against serious attackers. And I think Microsoft does a better job on this than almost anyone else.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: