Skip to content
DevMeme
3180 of 7590
Security Post #3501 · source on Telegram

Academia vs Industry on Fixing Known Vulnerabilities Before Exploits Happen

Description

The image is a screenshot of a tweet in the standard Twitter layout: a small circular profile photo is partially blurred for anonymity, next to the bold display name and handle “@matthew_d_green”. The tweet reads in full: “Academia: we all know that’s broken, you don’t need waste our time exploiting it. Industry: we all know that’s broken, but we’re not going to do a damn thing until someone exploits it.” The white background and black text are framed by Twitter’s light-mode UI, with a faint time-stamp and engagement icons cropped out below. Technically, the post humorously contrasts academic security researchers - who document flaws without actively weaponizing them - with commercial engineering teams that postpone remediation until a real-world exploit forces action, highlighting cultural differences in vulnerability management and risk tolerance

Comments

6
Anonymous ★ Top Pick Academia delivers a formal proof the bug exists; industry delivers a formal process to defer the Jira ticket until the CVE gets its own logo
  1. Anonymous ★ Top Pick

    Academia delivers a formal proof the bug exists; industry delivers a formal process to defer the Jira ticket until the CVE gets its own logo

  2. Anonymous

    The real vulnerability here is thinking that a CVE with a logo and marketing website is what finally gets your CISO to approve the security budget you've been requesting since 2019

  3. Anonymous

    The industry's approach to security vulnerabilities follows a well-established pattern: CVE published → CVSS 9.8 → 'We'll add it to the backlog' → Exploit in the wild → 'ALL HANDS ON DECK' → Emergency patch → Postmortem concluding 'we should be more proactive' → Repeat. It's essentially TDD (Threat-Driven Development) where the test is a production breach, and the red-green-refactor cycle is measured in incident response tickets rather than milliseconds

  4. Anonymous

    Academia: 'Vuln trivially known, next.' Industry: 'Vuln trivially known - until the CISO's inbox explodes with breach alerts.'

  5. Anonymous

    In academia, a CVE is proof of concept; in industry, it’s proof of budget

  6. Anonymous

    Academia calls it “trivial to exploit”; enterprise calls it “risk accepted” - until the PoC gets a logo and finally sails through CAB

Use J and K for navigation