Hacker News new | past | comments | ask | show | jobs | submit login

All products will have defects that are not CVEs, hopefully by a large margin.

But every sufficiently complicated product will have defects of this type, and a higher probability of defects does increase the probability of CVEs.

So, it follows in practice, as can be seen by looking at CVE rates from projects with high defect rates (web browsers, kernels, ...) vs projects with low defect rate.

Note that defect rate differences can be caused by multiple things.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: