Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Every time a vulnerability like this comes out, especially if it's a company that has some people with a chip against them (and most companies do), people say "See, that's why you can't trust Company With Vulnerabilty, I never use their software."

But if you actually pay attention you'll realize that vulnerabilities happen everywhere. Not all software is created equal, some might be more secure and have fewer vulnerabilities than others. But a single exposed vuln, no matter how severe, is pretty much never enough to judge which software is which.

I remember hearing about this exact bug in Facetime, but I had no idea that, as OP demonstrated, an analagous bug effected pretty much every popular similar A/V group chat software. Including the vaunted Signal.

Did this one OP find and reveal it in all of them? wow.

Also, I really wonder how many of these the NSA knew about before we did, but who can say (except the NSA).



This extends beyond vulnerabilities to bugs in general too. No company, or programmer for that fact, is immune to making mistakes. Some people like to think that if you're a very good programmer you'll magically write bug-free code, but that just doesn't happen. This is why extensive testing and having multiple eyes look at something is good practice. And even then, with the multiple layers of redundancy and everything, you still see AWS/GCP/Azure having downtimes, you still see bugs and crashes and exploits, from the small startups to the top tech companies.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: