Skip to content

Security thinking: "But what can you *not* do with the attack?" #9

@dbosk

Description

@dbosk

When a vulnerability occurs in a system, they tend to ask the question "but what can you do with it?". That's the wrong question, from a security perspective it's better to ask "what can you not do with it?". As long as you cannot prove that you cannot do something bad, there is a risk that you can.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions