|
|
|
|
|
by MZMegaZone
863 days ago
|
|
Yeah, I've been with F5 since 2010 - gotta love those old PortMasters though, Livingston was good times, until Lucent took over. I was there 95-98. I don't know what else there is to say really. The QUIC/HTTP/3 vuln was found in NGINX OSS, which is also the basis for the commercial NGINX+ product. We looked at the issue and decided that, by our disclosure policies, we needed to assign a CVE and make a disclosure. And I was firmly in that camp - my personal motto is "Our customers cannot make informed decisions about their networks if we do not inform them." I fight for the users. Anyway, Maxim did not seem to agree with that position. There wasn't much debate about it - the policy was pretty clear and we said we're issuing a CVE. And this is the result as near I can tell. Honestly, anyone could have gone to a CNA and demanded a CVE and he would not have been able to stop it. That's how it works. |
|
I get that CVEs have been politicized and weaponized by a bunch of people, but it seems weird to object that strenuously to something like this.