[HN Gopher] Bogus CVE Follow-Ups
       ___________________________________________________________________
        
       Bogus CVE Follow-Ups
        
       Author : HieronymusBosch
       Score  : 41 points
       Date   : 2023-09-05 17:19 UTC (5 hours ago)
        
 (HTM) web link (daniel.haxx.se)
 (TXT) w3m dump (daniel.haxx.se)
        
       | orf wrote:
       | CVEs are not what they once (ever?) where. With the proliferation
       | of automated systems involved with vulnerability management and
       | dependency updates, it's possible for a single GitHub PR close
       | event to create a CVE for an issue that verifiably, 100% does not
       | actually exist[1].
       | 
       | Interesting times ahead.
       | 
       | 1. https://tomforb.es/cve-2022-0329-and-the-problems-with-
       | autom...
        
       | tedunangst wrote:
       | Related: https://opensourcewatch.beehiiv.com/p/now-postgresqls-
       | turn-b...
        
       | voakbasda wrote:
       | This situation exposes some arbitrary and capricious aspects of
       | the CVE process, which in turn devalues the entire system. It
       | makes me personally less likely to take any of their assessments
       | at face value, and I imagine others will feel the same. That is a
       | net loss for security.
        
         | delfinom wrote:
         | CVEs have been questionable for awhile as I have seen quite a
         | few over the years that amount to "the attacker already has
         | root on the machine".
         | 
         | The problem now, is we are entering a phase of the general IT
         | market due to government mandates and insurers for all kinds of
         | cybersecurity junkware. Following a CVE database and pushing
         | scary CVEs are basically the end result and the overreaction
         | will still be the same as many of the cybersecurity positions
         | are no different than checklist readers since companies don't
         | want to pay for actual engineers or skilled sysadmins.
        
       | donutshop wrote:
       | Been seeing an uptick of researchers using CVEs to get street
       | cred. There definitely should be better governance with how
       | things are done.
        
       ___________________________________________________________________
       (page generated 2023-09-05 23:02 UTC)