Hacker News new | ask | show | jobs
by vngzs 16 days ago
It lets organizations (Tailscale) control the timing and narrative around the disclosure more directly. Organizations sometimes avoid the bureaucracy of going through CVE Numbering Authorities by self-publishing. Often a CVE assignment follows self-disclosure, especially when there's pressure to interoperate with vuln-scanning/compliance tooling
1 comments

And sometimes it’s just impossible to get a CVE number in a reasonable amount of time, or indeed at all.
In my experience it is really very quick and easy to get a CVE if you contact MITRE directly, and on paper you do not need to disclose too much. The GitHub CNA is (ironically) very slow by comparison but that is a GitHub issue.

Tailscale can also just apply to be their own CNA and issue CVEs for their products themselves, eliminating any such issues entirely.