|
|
|
|
|
by eyeareque
1993 days ago
|
|
Mitre is a us gov supported team, and previously they could not scale to the need of their efforts. They did the best they could, but they still had a lot of angry people out there. The whole world uses CVEs but it is US funded by the way. In come new CNAs, scale the efforts through trusted teams, which makes sense. The mitre team can only do so much on their own. Unfortunately I don’t think anyone will be as strict and passionate about getting CVEs done right, like the original mitre team has. Here is to hoping they can revoke cna status from teams who consistently do not meet a quality bar. |
|
I wonder if maybe, instead of trying to fix CVEs, we could try to think about creating alternatives? I know some companies already use their own identifiers (e.g. Samsung with SVE), so perhaps a big group of respected companies can come together to create a new unified identifier? Just an idea though.