Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It’s Way Better than what we had before: software vendors making even arbitrarier decisions about how to classify them.

There are far too many bad actors for us to operate as an industry with no yardstick.



I disagree that it is Way Better than before. A judgement call is worth more than a team wasting effort chasing irrelevant pseudo-vulnerabilities being reported as vulnerabilities. A broken yardstick is worse than no yardstick.


But that's an issue organizations bring upon themselves, by defining semi-arbitrary KPIs that are used without proper interpretation. It's not directly caused by CVEs or assigned scores. It's like blaming git that it count lines in diffs, because your company created a KPI that measures developer's based on LOC changes.


Fair point. I was not blaming CVE for the situation, simply bemoaning the situation.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: