4 ms·
> Going forward, NIST says its staff will only add data—in a process called enrichment—only for important vulnerabilities. Now - I am not saying I disagree wit
by shevy-java 6mo ago
> Going forward, NIST says its staff will only add data—in a process called enrichment—only for important vulnerabilities.
Now - I am not saying I disagree with everything here, mind you; I guess everyone may agree that CVEs may range in severity. But then the question also is ... what is the point of an organisation that is cut down to, say, handle 1% of CVEs - and ignore the rest? Why have such an organisation then to begin with?
I don't have enough data to conclude anything, but from a superficial glance it kind of seems like trying to cut down on standards or efficiency.
- tsimionescu 6mo agoNIST does many other things in addition to handling the CVE database.
- tptacek 6mo agoLike producing the world's most premium peanut butter! https://shop.nist.gov/ccrz__ProductDetails?sku=2387 https://shop.nist.gov/ccrz__ProductDetails?sku=2387 (The only problem with it is that it's backdoored the NSA.)
- prophesi 6mo agoAssuming this is in reference to the great Veritasium video[0] going over what these reference materials are used for and why they're so expensive. [0] https://www.youtube.com/watch?v=esQyYGezS7c https://www.youtube.com/watch?v=esQyYGezS7c
- lesuorac 6mo agoYou mean to tell me that the peanut butter at my store has junk besides peanut butter in it? I'm gunna call RFK right now and tell him to fix this!
- chuckadams 6mo agohttps://shop.nist.gov/ccrz__ProductDetails?sku=2782&cclcl=en_US https://shop.nist.gov/ccrz__ProductDetails?sku=2782&cclcl=en... Who doesn't love a jar of Industrial Sludge?
- dragonwriter 6mo ago> but from a superficial glance it kind of seems like trying to cut down on standards or efficiency. That's kind of the norm in the current US administration, so it shouldn't be surprising.
- vetrom 6mo agoI think you have to look at the history of disclosure from the 90s to get a good grip here -- The CVE system arose as something of a mediating factor to enable coordinated disclosure of discovered issues and make something of a standard that vendors could point to and they they were being responsive, vs wondering if a random exposure on Bugtraq in the 90s would ruin your week. If it no longer aids in that, then it has ceased to be a system useful for its original purpose, and it would be foolish to continue to feed it resources. It probably doesn't help that all sides viciously game the CVE system these days.