I have zero CVEs. However, to date I've shipped well over 500 of them via Patch Tuesday. I know a little about them & have some thoughts. CVEs simply merely universal bug numbers. That's it. Using them as a metric of ones contribution to InfoSec is flawed logic (1/3)
-
-
Whilst I agree that CVEs doesn't prove you skills, you seem to doubt the CVE process in general. Hell yea you should have a CVE on unsupported software. Imagine CVE-2017-0144 was only vulnerable on XP. Should one not have been issued because XP is no longer supported?
-
I don't doubt the process; my point is CVEs aren't a metric of skill (or lack thereof) MS17-010 affected many platforms & XP was simply one of them - that XP got the CVE means we patched it. Some ppl find vulns only affecting XP, demand a CVE, get denied, then go ask MITRE

- Još 3 druga odgovora
Novi razgovor -
-
-
I’m struggling to find the link, but this reminds me of the guy who got a CVE for finding vulns in someone’s Sophmore college project. You can request a CVE for almost anything.
- Još 1 odgovor
Novi razgovor -
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.

Be better to each other.