Just a rumour of a bug is enough to find a security exploit these days

27 points by pushcx


pushcx

I quietly opened cohttp#1145 publicly to get more eyes⁠ on it... Within about ten minutes (!) this website was fielding probes for percent-encoded traversal sequences

This caught my eye as it nearly meets a prediction I made.

bediger4000

Why is the rumor even necessary? Can't some nation-state hacker with a budget turn a model loose on a code base (Apache portable runtime comes to mind) and reap the benefits?

apromixately

3.1 Super sekrit private patch development

The text in this section is a bit odd. I think this is a reasonable strategy and the only arguments against it seem to be

  1. inconvenience because it's not well supported in the tooling now and
  2. that it's difficult to decide who should get access in an open source world, but I don't see how that is different from the initial advisory.