• scytale@piefed.zip
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    6 hours ago

    I’m aware. But that’s not the point of the comment thread. The point is the dev should’ve handled it better. We receive many notices at work of vulns from independent researchers, and regardless if they are bogus or not, we treat them all the same in the way we respond to them.

    • Orygin@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 hours ago

      You do you, but if I have someone shitting on my project (warranted or not, I’m not going into the political aspects) and make a report that apache is out of date, frankly they can get blocked too.
      Anybody with security experience will know it’s bogus and warrants no response.
      There are tons of “security experts” making “vulnerability reports”… That are just a version check. That’s not a vulnerability report unless you prove there is a vulnerability. They either try to get money or try to disparage you because you did not respond within their chosen timeline (which was too short by industry standards).