2026-06-30 15:27 UTC
Replies (1)
-
@adamshostack@infosec.exchange 2026-06-30 15:38
@zmanion@infosec.exchange @pgl@infosec.exchange @jayjacobs@infosec.exchange Thanks, and yes, we absolutely need both. This is the value of a published threat model: you can decide that based on a prior commitment. For example, Wikipedia works while allowing remote unauthenticated changes, most other folks don't do so. Also, as I somehow managed to get through MS PR, "Autorun isn't a bug, it's a feature." As much as the world would have liked to, you can't credibly slap a CVE on a questionable design choice. Which leads to a wrinkle for your definition: Autorun had an understood possible disposition towards abuse. (I think Charlie Kaufman had an internal paper on that in the runup to XP or maybe SP2.)