Message for Partners
CF: When you have these types of findings, is there a message in there for partners? Does it point to opportunities and/or challenges for them?
JF: So the Tarfile Python vulnerability was one which we identified, but at the same time it’s like, OK, we don’t want to shout off the rooftops saying like, oh, this is so bad. It’s 15 years old. We look at what can we do about it instead of just writing a blog. So one of the things that we did was we launched a scanning tool that anyone can download and you can find out if you’re vulnerable because … we saw that it was already very tough to establish if you have systems that are actually vulnerable. So we’ve written a special script for this and everybody can run that on demand. But we took it even a step further. We’re working together with GitHub and we’re actually having an automated way of identifying vulnerable repositories that have that vulnerability. And we’re going out to be sending out pull requests to get it patched automatically. That is a clear example of we don’t only find fault, but we try to find remedy as well.