Hacker News new | past | comments | ask | show | jobs | submit login

https://thezvi.wordpress.com/2021/12/20/law-of-no-evidence/

> Law of No Evidence: Any claim that there is “no evidence” of something is evidence of bullshit.




What else can you say?

It's impossible to know if a vulnerability was exploited.


"We don't have enough information to determine whether or not this vulnerability was exploited. We are operating under the assumption that is has been." is what I want to hear. I do not want to hear "We have no evidence that the vulnerability has been exploited." which, of course, minimises the fact that it may have been and does nothing to communicate what assumption they're working under - i.e. that they're probably going to assume it hasn't been exploited.

TL;DR: I'd rather them be entirely up front about the fact that they can't tell if it has been exploited and advise you to assume it has been than them try to weasel out of saying their logs aren't good enough but "you'll probably be alright, eh".


> We are operating under the assumption that is has been.

This gets expensive quick.


Probably the reason people try to avoid security incidents

In this case it's already happened, time to spill the bag


"If you think safety is expensive, try an accident!" - Stelios Haji-Ioannou


Which really means that if you discover a vulnerability in your system, you assume that it was fully exploited.


Reality: You can’t prove a negative.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: