Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

[flagged]


Thanks for volunteering to manage the "300-600 CVEs each month"!

The world needs more volunteers like you.


Make that 3,000-4,000 on average per month, according to NISTs stats on CVEs for last year. ~40,000 for 2024.


I imagine most of those CVEs not being anything meaningful and just script kiddies trying to put something on their portfolio

all the meaningful ones will show up on HN


You manage the system and not the CVEs themselves. The simplist thing would be a list of numbers that correspond to Google docs. The owner of the Google doc can share it with the needed parties and eventually set it as public.


You truly believe that the CVE database (and others like CWE) are only about assigning serial numbers to random reports, don't you? I see people underestimating and understanding the work of others in matters like this. Is that a trend now?


I saw this same behavior quite a while back. While I'm out of the CVE game these days, it seems that there is a forever rotating new group of people who simply don't and can never see the complexities on the process.

I think it's a testament to the previous stewardship that it appears so simple.


No I don't believe that, but it might as well operate like that. The extra stuff isn't truly needed and was being outsourced to the companies that own the products since it wasn't providing much value. Take a look at Daniel's blog posts about CVEs for curl for what happens when you let them handle it.


How do you get your volunteers in the first place and manage them so you know it's time to get a new one if the quality of their work is slipping?


Yet so far no volunteer has emerged and people who do run CNA are pretty busy with it.


I think sneak would volunteer to do it since it is pretty simple according to them.


Any work people don't understand must be easy and replaceable by chatgpt. Just look at how easy people here think farming is.


Grok becoming an artificial nepobaby running the entire CVE program with zero oversight sounds so fucking funny I don't even care, PLEASE god make this real holy shit I can't breathe at the thought


There were some, short-lived, projects/groups trying to run their own processes. DWF is one that I recall, though it is dead again:

https://lwn.net/Articles/851849/


Who needs volunteers? Let AI handle it!


Found the blackhat


This is like saying the patent system is just an incrementing counter.


Have you seen the patents they have been giving out lately?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: