Resurrecting DWF
Resurrecting DWF
Posted Apr 8, 2021 8:02 UTC (Thu) by mezcalero (subscriber, #45103)Parent article: Resurrecting DWF
Not sure I get why one needs a central authority for this? Just provide a web form where you enter some data about the vulnerability, than hash that into a 128bit value or so, and prefix the result with "CVE-", and you are done. And you probably don't even need 128bit… And document how you exactly concat the stuff in a spec so that people can reimplement things independently.
The IDs would then be entirely self-managed, distributed but stable.
I mean, content-addressable databases aren't precisely a new concept?
What am I missing?