3 ms·
They should just multiply a base rate against the severity level. Say the base rate is ranged so low-severity stuff is $500-1K base but high-severity stuff is $
by rglover 1mo ago
They should just multiply a base rate against the severity level. Say the base rate is ranged so low-severity stuff is $500-1K base but high-severity stuff is $10K base. That would net a researcher ~$88K for this specific bug (8.8 severity).
- vlovich123 1mo agoCVE severity is a terrible way to do this. If you follow the cybersecurity space you should know why.
- rglover 1mo agoIt's a simple multiplier number and you can set a cap on it (and payout amounts). Where's the fire?
- vlovich123 1mo agoCVEs are handed out like candy for non issues, the severity rating system isn’t a serious evaluation of the actual severity (eg a vulnerable function may not even be compiled in), the scoring is inconsistent and subjective and frequently inflated to make the severity seem worse, and with the AI flood they have a massive backlog of handing out CVEs. Like look at CVEs curl dealt with at one point that were just completely bogus and given huge severity ratings to start with. But honestly if you’re the one proposing a “simple solution” maybe do some research yourself.
- rglover 1mo ago> But honestly if you’re the one proposing a “simple solution” maybe do some research yourself. It's an off the cuff idea on a nerd forum. Relax buddy.
- SteveNuts 1mo agoThat would create a perverse incentive to inflate the severity levels even more than they already are
- rglover 1mo agoIt doesn't have to. Just put a cap and say "we officially recognize 1-10" and be done with it.