Skip to content

Security thinking: "But what can you *not* do with the attack?" #9

@dbosk

Description

@dbosk

When a vulnerability occurs in a system, they tend to ask the question "but what can you do with it?". That's the wrong question, from a security perspective it's better to ask "what can you not do with it?". As long as you cannot prove that you cannot do something bad, there is a risk that you can.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions