5 ms·
On the one hand it seems like, if you are reporting a security issue, you should presumably have some kind of PoC. On the other hand we’ve seen plenty of exploi
by grepknfss 3y ago
On the one hand it seems like, if you are reporting a security issue, you should presumably have some kind of PoC. On the other hand we’ve seen plenty of exploits that required chaining a half dozen not-obviously-exploitable issues to achieve a successful exploit. If someone at MITRE has to adjudicate these issues for every CVE in all possible programming languages for all possible exploits for all possible software… well that seems like a tough job anyway.
I think the people using the CVE database as some kind of official source of actual security issues, as opposed to reported potential issues, is the problem.
- mistrial9 3y agowhat if certain institutionally affiliated people are paid to use the CVE to report potential issues, and management gets paid to approve that?
- TomSwirly 3y agoI'm technically aware, but do I really have the expertise and bandwidth to tell the difference between an actual CVE and one that isn't, for the whole database? The database isn't really much use unless it's pretty accurate, as few of us have the ability to evaluate correctness. In this case, where there's an anonymous report, and a clear, near-elementary level explanation of how the code in question cannot be a security violation and has since been removed, the CVE should just be deleted, to save bandwidth for everyone.
- deleted 3y ago[deleted]
- grepknfss 3y ago> I'm technically aware, but do I really have the expertise and bandwidth to tell the difference between an actual CVE and one that isn't, for the whole database? I sure don’t. But who does? Who gets paid by whom to make this all work? Apparently whatever is happening now ain’t it.