| ▲ | loloquwowndueo 5 hours ago | |||||||||||||||||||||||||
Depending on those vaunted “security researchers” to take point and find all vulnerabilities in all packages is also fairly naive. That process costs money and produces a fairly valuable result - why would they give it away for free? So this will inevitably evolve into targeting only the high-value most popular packages and the exploiters will retreat to the long tail of less-popular ones. Lower payoff? Sure, but beats zero payoff. | ||||||||||||||||||||||||||
| ▲ | shengpuerh 5 hours ago | parent [-] | |||||||||||||||||||||||||
Finding vulns in popular OSS and disclosing is probably good for your reputation as a security researcher, even if it's not immediately profitable. | ||||||||||||||||||||||||||
| ||||||||||||||||||||||||||