Security feeds give you a CVE id, a score, and one line: an attacker may bypass authentication. As a developer that sentence is useless, because the part I can actually learn from is how the bypass works, the exact check that got skipped, the exact character that changed a query. See the shape once and you catch it in your own code, which is worth far more then the score. That is the whole point of this series, and the mindset is in the CVE stigma post.
Most security feeds hand you a CVE id, a CVSS number, and one sentence saying an attacker may do something bad. As a developer that tells me almost nothing I can use. The part worth knowing is the mechanism: the exact buffer with no ceiling, the exact class filter that checks one path and forgets another. See the shape once and you recognise it in your own code, which is worth far more then the score. That is the whole reason for this series, and I wrote about the mindset in the CVE stigma post.
Most security news is useless to me as a developer: a CVE number, a score, one line saying an attacker may do something bad, and nothing about why. The part worth knowing is the mechanism, the exact queue with no limit, the exact name that turns out to be guessable. See the shape once and you spot it in your own code, which is worth far more then the score. I wrote about that in the CVE stigma post.
Two questions sit underneath almost every distributed system, and most of the security work anyone does is really about answering them well. Who is calling me. And are they allowed to do what they are asking for. The first is authentication, the second is authorization, and the reason they are worth keeping apart is that the good answers to them look nothing alike.
I keep this series going because most security news is useless to me as a developer. You get a CVE number, a CVSS score, a one line summary that says “an attacker may be able to execute arbitrary code”, and then nothing. You close the tab having learned that a thing is bad, which you already assumed, and not one word about why the thing happened or whether the same mistake is sitting in your own code.