Security Writer :verified: :donor: on Nostr: I know people have strong opinions about the CVE program and many Infosec ...
I know people have strong opinions about the CVE program and many Infosec professionals actually want to see it fail.
Personally, when all is said and done, I think it’s a net positive that greatly benefits security teams the world over.
It’s flawed, and sometimes too inflexible to keep up with novel vulnerabilities, but without it, we’d be in a much worse position.
Published at
2025-04-16 07:25:45Event JSON
{
"id": "9ef41c129bfc6bab34021a2e419b514541854c1df5930a167f2e60f5b6f39277",
"pubkey": "3f8a30a34262655e8ebc2c64a705a22b00e068ce5bc0b47dd4eb484d2c514014",
"created_at": 1744788345,
"kind": 1,
"tags": [
[
"proxy",
"https://infosec.exchange/users/SecurityWriter/statuses/114346449039369231",
"activitypub"
],
[
"client",
"Mostr",
"31990:6be38f8c63df7dbf84db7ec4a6e6fbbd8d19dca3b980efad18585c46f04b26f9:mostr",
"wss://relay.mostr.pub"
]
],
"content": "I know people have strong opinions about the CVE program and many Infosec professionals actually want to see it fail.\n\nPersonally, when all is said and done, I think it’s a net positive that greatly benefits security teams the world over.\n\nIt’s flawed, and sometimes too inflexible to keep up with novel vulnerabilities, but without it, we’d be in a much worse position.",
"sig": "25a518475d5d25425cd0604727653f3eff7c3de5c894136850a588c0411e29bf3735907271b004834b4793fe1c6efc2612fa1af4d7e81507bdc9560dea804ac1"
}