- cross-posted to:
- technology@beehaw.org
- linux@programming.dev
- linux@lemmy.ml
- cross-posted to:
- technology@beehaw.org
- linux@programming.dev
- linux@lemmy.ml
If you dont know, already knowing what to look for is a very big help in finding vulnerabilities. Its like handing an architect a build for a house and saying „There may be a problem, but there may be none.” vs saying „There is a problem in the 3rd floor, because last time it collapsed after having to hold over 200kg”. For one, you don’t look into it too much, but for the other you already know where to look and what to look for.
Don’t forget the 28/100 false positive rate.
So only 8% success rate, and 28% false positive rate (even worse than just failing to find the issue) in ideal conditions.