16 ms·
Vulnerability counts are misleading metric for security. They do not include the vulnerabilities which have not yet been discovered or created.
by postmodern_mod3 14y ago
Vulnerability counts are misleading metric for security. They do not include the vulnerabilities which have not yet been discovered or created.
- jpatokal 14y agoAnd you're proposing to get a less misleading metric for undiscovered or uncreated (!?) vulnerabilities how, exactly?
- postmodern_mod3 14y agoMaybe graph the rate of vulnerabilities discovered vs. LoC/files added? It's safer to only use vulnerability counts as a metric for how interesting software is to security researchers.