Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> If the rail industry is ignoring this CVE, then it must be because it's either not practically exploitable or not as severe as the author claims.

> People who work for the railroad are smart, and have a lot more experience with trains than your average Lambda School grad, so I'll defer to their judgemental

That's a very idealistic view of the world, I don't think reality would agree. Ego, indifference, and plain incompetence are extremely common in every industry, then add onto that the fact that hardware companies are already notoriously bad at software, and then you can double the risk for entrenched companies that have little pressure to be proactive about these things.

This is exactly the kind of lax response I would intuitively expect from a company of this nature. I say that as I glance over at Boeing.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: