Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> I suspect its likely because TP-Link tells/is forced to tell the Chinese government...

I think if we are there, then we should assume all 0days are known by various states before patches are available regardless of whether companies are setup to share that information or not. You don't need to get the company to share that information, just one person in a company, and I don't really see that as being a challenging task for a state to do.

Assuming otherwise seems more risky.



Hence zero-trust, buzzwords aside.

You should absolutely assume breach as part of your company's security policy/trust model.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: