We need a single source of truth for this.
So distribute it, like DNS. Have the CVE Foundation be the final authority, but relying solely upon them makes me uneasy.
The CVE Foundation might currently be independent from the US government, but that doesn’t mean they’re not still subject to its whims. I think people underestimate just how awful things are or could get here, and “why is the government doing that stupid/heinous/bizarre thing” has become a daily mantra for many.
CVE needs better protection from hostile governments, and distributing the system seems like the only way to achieve that
billiam0202@lemmy.world 3 days ago
This, exactly.
The whole point of CVE is to make sure everyone is on the same page regarding exploits. That necessitates a single point of truth for the whole operation.