The bogus CVE problem
The bogus CVE problem
Posted Sep 14, 2023 0:04 UTC (Thu) by wahern (subscriber, #37304)In reply to: The bogus CVE problem by geofft
Parent article: The bogus CVE problem
The CVE system has flaws--serious flaws. But I'd argue that these flaws are less severe than the alternative where vendors can more easily waive off reports. Let's not forget from whence we came--a time when vendors didn't take these things seriously unless and until bugs were already being conspicuously exploited in the wild. And we still have problems with too many vendors not taking CVEs seriously. The current system is unfair to conscientious developers and maintainers whose time is wasted by self-aggrandizing bug reporters, but we would never have needed the current CVE system if such conscientious people were the majority of those shipping software.
* There's a reason we can't have nice things. * No good deed goes unpunished. * Etc, etc.
