Comment on CVE Board members launch the CVE Foundation, a dedicated, non-profit to continue identifying vulnerabilities, after the US ended its contract with Mitre

wampus@lemmy.ca ⁨3⁩ ⁨days⁩ ago

I’m honestly not totally sure what to think about this one, though I recognise that it’s a big shift/likely a negative overall result.

Reason I’m humming and hawing, is that there are lots of expensive cybersecurity type ‘things’ that rely on the CVE system, without explicitly paying in to that system / supporting it directly, from what I recall / have seen. Take someone like Tenable security, who sell vulnerability scanners that extensively use/integrate with the CVE/NVD databases… companies pay Tenable huge amounts of money for those products. Has Tenable been paying anything into the ‘shared’ public resource pool? How about all those ‘audit’ companies, who charge like 10-30k per audit for doing ‘vulnerability / penetration tests’.

IT Security has been an expensive/profitable area for a long time, while also relying on generally public/shared resources to facilitate a lot of the work. Maybe an ‘industry’ funded consortium is the more appropriate way to go.

source
Sort:hotnewtop