Academia fixes it on paper, industry waits for the zero-day headline
Description
Screenshot of a tweet styled in the standard Twitter interface. A small circular avatar sits at the top left, followed by the bold name "Matthew Green" and the handle “@matthew_d_green.” The tweet text reads: “Academia: we all know that’s broken, you don’t need waste our time exploiting it. Industry: we all know that’s broken, but we’re not going to do a damn thing until someone exploits it.” Beneath the text is the metadata line “19:57 · 05/04/2019 · Twitter for iPhone.” Visually, the layout is simple white background with black text, blue handle and timestamp links. Technically, the post humorously contrasts academic security research - where acknowledged flaws are documented and moved on from - against corporate risk culture, which often delays remediation until an exploit becomes public. It highlights real-world attitudes toward vulnerability management, disclosure, and organizational incentives around fixing known bugs
Comments
7Comment deleted
Security triage flowchart: 1) Academic paper cites the vuln → file a Jira tagged “someday.” 2) PoC exploit tweeted → backlog behind OKRs. 3) HackerNews headline → Sev-1 war room. 4) CFO’s face on Bloomberg → “rewrite it all in Rust by Monday.”
The difference between a CVE and a P0 incident is about three quarterly earnings calls and one CISO's resignation letter
The vulnerability backlog has two states: 'theoretically broken, won't fix' and 'actively exploited, P0 all-hands' - nothing in between ever gets scheduled
The eternal security paradox: Academia publishes a CVE with a 9.8 severity score and a detailed write-up, but Industry's risk register still shows it as 'accepted' until someone drops a working exploit on GitHub. Then suddenly it's P0 and everyone's working weekends - because apparently theoretical cryptographic breaks don't count until they're weaponized in a Metasploit module
Our risk model is event‑driven: nothing is scheduled until the CVE ships with a logo, then it preempts the entire roadmap
Academia footnotes the flaw in a paper; industry footnotes it in the postmortem
Industry threat model: "academic PoC" -> backlog; "same PoC with a logo and a domain" -> sev-0 war room