Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That blog post seems to contradict what Tavis Ormandy claimed on Twitter a few days ago, when the patch was released:

> Adobe patched around 400 unique vulnerabilities I had sent them in APSB11-21 as part of an ongoing security audit. Not a typo.

https://twitter.com/#!/taviso/status/101046246277521409

> Apparently that number was embarrassingly high, and they're trying to bury the results, so I'll publish my own advisory later today.

https://twitter.com/#!/taviso/status/101046396790128640

Whereas the blog post cites 400 unique crashes, 106 security bugs, and 80 code changes (the same numbers that Adobe used: http://blogs.adobe.com/asset/2011/08/how-did-you-get-to-that...).

---

Regardless of the exact numbers though, this is a supremely awesome feat of security engineering. It's very impressive.



Code changes feels like the best count, unless you believe Adobe's letting crashers slip past this release.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: