| ▲ | john_strinlai 4 hours ago | ||||||||||||||||||||||||||||
>Because sometimes I see people online who compare the number of CVEs in Rust and C/C++ software, [...] a rule of thumb i follow is that the second someone starts comparing or talking about the number of CVEs, i just ignore whatever they say next. its hard to think of a more useless metric than "number of CVEs", especially now. (edit: the people disagreeing are encouraged to share how you use "number of CVEs" to inform your decision making) | |||||||||||||||||||||||||||||
| ▲ | mk89 2 hours ago | parent | next [-] | ||||||||||||||||||||||||||||
Oh no, you're in for a surprise. "Especially now" all these infosec folks "need to get CVEs fixed because compliance/SOC2, etc" and they will be even more up your a*! Something has to change with how compliance works. It is so outdated and crazy. | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
| ▲ | kkishahva an hour ago | parent | prev [-] | ||||||||||||||||||||||||||||
[flagged] | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||