Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I mean, I'd say that this fiasco showcased the significant benefits of passionate volunteers doing great work in the open. And yeah, someone at MS may have made a faux pas on the ffmpeg forum but also someone at MS was the one who discovered and responsibly reported the xz vulnerability. Corporations aren't monolithic.

If this had happened and someone's livelihood or next promotion was on the line, the amount of forensics and publicity would likely have been so much less open than it has been in a product driven by community and done in the open.



The xz incident was handled far better, faster, and more open than the Solarwinds incident. If anything, this proves that more eyes do help.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: