Comment on CVE Board members launch the CVE Foundation, a dedicated, non-profit to continue identifying vulnerabilities, after the US ended its contract with Mitre

<- View Parent
Telorand@reddthat.com ⁨3⁩ ⁨days⁩ ago

We need a single source of truth for this.

So distribute it, like DNS. Have the CVE Foundation be the final authority, but relying solely upon them makes me uneasy.

The CVE Foundation might currently be independent from the US government, but that doesn’t mean they’re not still subject to its whims. I think people underestimate just how awful things are or could get here, and “why is the government doing that stupid/heinous/bizarre thing” has become a daily mantra for many.

CVE needs better protection from hostile governments, and distributing the system seems like the only way to achieve that

source
Sort:hotnewtop