Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Clearly I was too subtle. It, uh, wasn't actually a hypothetical: zlib had known exploits that bit Microsoft and others for years because they had cut and pasted the library into a zillion places. Linux distros just updated.

There's no theory at work here. Static linkage of common components is a security vulnerability.



And I wasn't saying it never works. I was simply saying that it doesn't work that way regularly, or even often.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: