Remix.run Logo
▲ LoganDark 43 minutes ago

Agree on the talent pipeline. It can take a long time for someone to obtain a CVE that has their name on it. You don't start being a security researcher only once that happens.

Some years back, I was working on generating AVB2 hashes on top of modified Android distributions, to increase the security after an owner has made their desired changes. I was doing this before the age of LLMs. Among other things, this would've enabled the secure features to work again, and reduced the risk of root access being usable by malware. But apparently I'm not a security researcher because I didn't get a CVE about it.