|
|
Log in / Subscribe / Register

The CVE program itself is an unauthenticated remote DoS vulnerability

The CVE program itself is an unauthenticated remote DoS vulnerability

Posted Aug 3, 2026 18:19 UTC (Mon) by hunger (subscriber, #36242)
In reply to: The CVE program itself is an unauthenticated remote DoS vulnerability by linuxrocks123
Parent article: SQLite Critical CVEs or LLM Slop? (JFrog blog)

Most governments are way less clueless than you make them out to be. Companies have a way worse track record here.

Go and check the rules you need to follow when accepting credit card data from customers... you will be surprised how "banking" can be a challenge to IT departments.


to post comments

The CVE program itself is an unauthenticated remote DoS vulnerability

Posted Aug 7, 2026 2:24 UTC (Fri) by linuxrocks123 (guest, #34648) [Link] (4 responses)

payment card processing != banking

Visa, Mastercard, American Express, and Discover are not banks. Discover is owned by a bank -- Capital One -- but that's only because Capital One acquired Discover, and the Discover Network is still its own "thing" inside of Capital One.

And, before you start to say otherwise, no, you do not have to have an agreement with a bank to take credit cards. You can just use Stripe. And send your funds to a brokerage account even instead of a normal bank account if that floats your boat.

Now, you _ARE_ correct that the payment card industry promulgates a bunch of really stupid IT requirements. Those idiotic requirements are one big reason I would never in 10 billion years take payment cards. The other big reason would be not wanting to lose over 3% of my gross revenue to bullshit card processing fees. Either reason alone would be sufficient for me to "nope" the fark right out of there if anyone ever tried to convince me to take payment cards.

Maybe LWN should stop taking payment cards and use Zelle instead. Instant 3% gross revenue increase unless subscribers decide it's too annoying. So to avoid that maybe keep taking the cursed cards but pass on your processing fees to us and let us avoid them by using Zelle or a check.

I get 4%+ cash back on everything I buy as a consumer, and that's great for me, but I'm not an idiot. I know that "cash back" money is coming out of merchants' pockets. I know payment cards are evil and would love to see merchants no longer have to suffer an invisible tax from taking them. Down with all four of the payment card networks, thieving bastards every one.

The CVE program itself is an unauthenticated remote DoS vulnerability

Posted Aug 7, 2026 2:47 UTC (Fri) by dskoll (subscriber, #1630) [Link] (1 responses)

Maybe LWN should stop taking payment cards and use Zelle instead

Zelle is USA-only. So LWN would still need to take cards (or find other ways) for non-US subscribers to pay.

The CVE program itself is an unauthenticated remote DoS vulnerability

Posted Aug 7, 2026 4:28 UTC (Fri) by linuxrocks123 (guest, #34648) [Link]

Early Warning Services is working on fixing that: https://www.prnewswire.com/news-releases/zelle-heads-to-i...

The CVE program itself is an unauthenticated remote DoS vulnerability

Posted Aug 7, 2026 6:02 UTC (Fri) by Cyberax (✭ supporter ✭, #52523) [Link] (1 responses)

Zelle does not have proper customer _and_ merchant protection. It also does not have a proper payment story (how do you link a Zelle transaction?).

> Zelle® Heads to India, Unveils ZelleUSD℠ Stablecoin For Other Markets

It's dead. Cryptocrap kills everything.

The CVE program itself is an unauthenticated remote DoS vulnerability

Posted Aug 8, 2026 2:59 UTC (Sat) by NYKevin (subscriber, #129325) [Link]

In general, Zelle is highly questionable for almost all purposes. The banks like to pretend[1] that Regulation E does not apply to Zelle, which in plain English means "no chargebacks, no refunds, and we specifically don't want to hear about how you thought he really was the deposed prince of Nigeria." I wouldn't touch Zelle for anything other than giving money to a personal friend or family member.

[1]: See https://www.bitsaboutmoney.com/archive/regulation-e/ for a more precise explanation of what the banks claim and how legally plausible it is. But note that the average consumer is not in a great position to start a legal battle with the average bank.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds