Hacker News new | past | comments | ask | show | jobs | submit login

I think this is a very key point. OpenSSH gets targeted for vulnerability analysis by very talented people, on a regular basis. I would be surprised if there are more than a dozen organizations on the planet that can deploy those kind of resources against their homegrown code.



how many of those dozen organizations would actually release the results of their analysis?


Given the number of CVEs filed a nonzero number.

In any case more organization than the number of orgs that would bother to check my code.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: