Scaling/domain knowledge
Scaling/domain knowledge
Posted Dec 6, 2023 6:22 UTC (Wed) by nickodell (subscriber, #125165)Parent article: Supplementing CVEs with !CVEs
Seems tricky to scale. The current system may have a conflict of interest, but it does at least distribute vulnerability reports among the CNAs, and ensures that the CNAs evaluating their own software for security bugs are domain experts. I think that for a lot of software, it might be hard to tell if a bug is a security issue, without an understanding of what the security model of the software is.