top | item 36623587

(no title)

tantalic | 2 years ago

This is problem of misaligned incentives: if you are making a security scanner the last thing you want to do is miss a vulnerability. The result is many false positives.

discuss

order

fsociety|2 years ago

Alternatively, companies aren’t willing to pay for an automated security scanner that attempts to exploit potential vulnerabilities under fear of what it might do to their systems.

didntcheck|2 years ago

As is often the case, people only think about sensitivity and don't consider specificity