| ▲ | apenwarr 43 minutes ago | ||||||||||||||||
(Tailscale CEO) I don't know what to tell you. The problems that are found internally, or via security reviews and pentests we pay for, are ones that we fix before releasing. They don't need bulletins. Bugs that are found by other people are found, by definition, after release. They are therefore more likely to need a bulletin. | |||||||||||||||||
| ▲ | traceroute66 39 minutes ago | parent [-] | ||||||||||||||||
But why should insecure argument handling bugs (as per your recent SSH bulletin) be found after release ? Those are an ancient class of bugs that should be picked up by any competent security review. | |||||||||||||||||
| |||||||||||||||||