"Hi! Here's an output of a series of automated scans. False positives? No idea. That's outside the scope of work. Good luck!"
Top-level
"Hi! Here's an output of a series of automated scans. False positives? No idea. That's outside the scope of work. Good luck!" 3 comments
@steve@mastodon.nexusuk.org @neil@mastodon.neilzone.co.uk @stefano@mastodon.bsd.cafe |
@neil @stefano "Here's an automated scan, if there are any false +vs you need to provide proof for each one individually."
"We're running a fully up to date RHEL 9, please exclude all the known false +vs for that OS"
"We don't do that, you need to provide proof for each individually"
I mean, these people are getting paid to do these scans, surely the least they could do is maintain a database of false +vs for common OSes so they could be automatically excluded?! (spoiler: none of them do!)