Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What are the implications of this? No more centralized store of vulnerability information?


According to Brian Krebs: https://infosec.exchange/@briankrebs/114343835430587973

> Hearing a bit more on this. Apparently it's up to the CVE board to decide what to do, but for now no new CVEs will be added after tomorrow. the CVE website will still be up.


Basically when any software/library/whatever has a vulnerability, they have to communicate that out themselves, in some format.

If I'm developing a product built on 20 libraries, it won't just be a matter of scanning CVEs for major vulnerabilities any more, so I'm more likely to miss one.

"always update" doesn't always work, when to manage a product you realistically have to version pin.


So, while arguably true, there wont be a single source of truth of new cve's. It doesn't however mean there wont be.

I would imagine the only SANE option would be some kind of git repository where CNA's can collaborate. Probably run some code across to make the website that people can easily access.

It's going to be a mess.


They surprise is: they won't. This will weaken the West.

This is dangerously stupid.


This is deliberate. I just want to figure out the avenues of communication and coordination between trump admin and moscow so we can pin them down better.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: