Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

See also this VP's blog post https://seclists.org/isn/2015/Aug/4 which reinforces Oracle's worst stereotypes


Wow - that's shockingly tone-deaf.

He's virtually goading people into releasing discoveries to the public first (but of course they have already discovered these bugs and the fix was ready anyway - so THERE!).

Aren't we past the days when decompiling code would offer any real advantage?


In his defense, there is a real problem with people running code analysis tools and assuming the results to be correct. It can be difficult to deal with a constant barrage of incorrect "security findings".

It still doesn't excuse some of the things said in that post, though, of course.


I think he's doing his job very, very well [0]. The vulnerability in linked post is disclosed directly to the public.

[0]: https://news.ycombinator.com/item?id=18395855




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: