@adamshostack@infosec.exchange
2026-06-30 15:38 UTC
@zmanion@infosec.exchange @pgl@infosec.exchange @jayjacobs@infosec.exchange
Thanks, and yes, we absolutely need both.
This is the value of a published threat model: you can decide that based on a prior commitment.
For example, Wikipedia works while allowing remote unauthenticated changes, most other folks don't do so.
Also, as I somehow managed to get through MS PR, "Autorun isn't a bug, it's a feature." As much as the world would have liked to, you can't credibly slap a CVE on a questionable design choice.
Which leads to a wrinkle for your definition: Autorun had an understood possible disposition towards abuse. (I think Charlie Kaufman had an internal paper on that in the runup to XP or maybe SP2.)
Replies (0)
No replies.