▲ | motorest 6 days ago | ||||||||||||||||
> And it’s easy to fix - sponsor a contributor. It’d be cheaper than the many meetings that were needed to make the removal decision. I don't think that's how it works. I mean, how many problems did you ever fixed by dictating how others should spend their own money? Also, apparently some of these issues exist for over a decade. That alone tells you how serious the problem is, and how urgent it needs fixing. | |||||||||||||||||
▲ | hmcq6 5 days ago | parent | next [-] | ||||||||||||||||
> Also, apparently some of these issues exist for over a decade. That alone tells you how serious the problem is The "serious problem" is that they've known about bugs for 20 years and not committed resources to fix it. The problem is the money. | |||||||||||||||||
| |||||||||||||||||
▲ | baq 6 days ago | parent | prev [-] | ||||||||||||||||
I'm just saying they've got a bug bounty program but not a bug prevention bounty program, or even a fix a known bug bounty program. The security team has a budget for the realized risks but predictably not for managing unrealized risk in the open source community which they depend on. | |||||||||||||||||
|