Hacker News new | ask | show | jobs
by Sohcahtoa82 794 days ago
I think named vulnerabilities are useful when it's a "STOP THE WORLD" kind of vulnerability like Heartbleed and Shellshock. It's much easier to talk about Heartbleed than "CVE-2014-0160".

The problem, IMO, is when medium-severity vulnerabilities are given names, like Terrapin. I think it makes people think a vulnerability is much worse than it really is.

1 comments

Heartbleed was a decade ago? JFC I’m getting old