I must have, the sentence does not make sense to me. Here it is, shortened: "this vuln in mongodb server does not impact mongodb, managed mongodb server, or our systems". If the first clause is referring to their systems, why do they say the same thing in the third clause?
Also i just noticed, how come they say atlas wasn't affected but say they patched it in their timeline?
>give them the benefit of doubt that they'd have said so
Statements like this are basically legal admissions of guilt, i expect there to be as little truth as possible.
>You are familiar with things like SOC and SIEM, and you're confused by this?
I work in IT, I'm not a coder... so yes :) hundreds of hours seems excessive. Remember, this isn't a safe deployment or rollout plan, that's the next block of time. Hundreds of man hours is more than one person's full month of work. Do you expect it to take you a whole, dedicated month to fix 1 bug at a time?
>That's what SIEMs do if they're adequately configured.
This is a bit of a no true Scotsman. The intended error log is "error: {cstring payload nullterm} broke" and the mongobleed log is "error: {cstring payload MISSINGNULLTERM cstring payload nullterm} broke". Those two things look identical, how is any amount of configuration supposed to catch that?