5 ms·
What are the implications of this? No more centralized store of vulnerability information?
by bytematic 1y ago
What are the implications of this? No more centralized store of vulnerability information?
- neuronexmachina 1y agoAccording to Brian Krebs: https://infosec.exchange/@briankrebs/114343835430587973 https://infosec.exchange/@briankrebs/114343835430587973 > Hearing a bit more on this. Apparently it's up to the CVE board to decide what to do, but for now no new CVEs will be added after tomorrow. the CVE website will still be up.
- Incipient 1y agoBasically when any software/library/whatever has a vulnerability, they have to communicate that out themselves, in some format. If I'm developing a product built on 20 libraries, it won't just be a matter of scanning CVEs for major vulnerabilities any more, so I'm more likely to miss one. "always update" doesn't always work, when to manage a product you realistically have to version pin.
- cantrecallmypwd 1y agoThey surprise is: they won't. This will weaken the West. This is dangerously stupid.
- delulucrew 1y ago[dead]
- OhioMan2943 1y agoThis is deliberate. I just want to figure out the avenues of communication and coordination between trump admin and moscow so we can pin them down better.
- worthless-trash 1y agoSo, while arguably true, there wont be a single source of truth of new cve's. It doesn't however mean there wont be. I would imagine the only SANE option would be some kind of git repository where CNA's can collaborate. Probably run some code across to make the website that people can easily access. It's going to be a mess.