I'm starting to wonder if social networking sites (@facebook, @Twitter) and search sites (@Google) of today are similar to web browser engines around 2003 (?) or so, around when use-after-free had just been demonstrated to be a reliable security exploit.
If you work at a social media platform and you're not spending most of your day agitating for internal reform—on so many fronts—what are you doing?
1
1
5
And to be clear: norms in the browser engine world are moving towards multiple layers of protection: writing code in safer languages, aggressively fixing even potential vulnerabilities, tools for software auditing, sandboxing that prevents many APIs from being called, etc.
1
1
2
