Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

CVE severity is a terrible way to do this. If you follow the cybersecurity space you should know why.
 help



It's a simple multiplier number and you can set a cap on it (and payout amounts). Where's the fire?

CVEs are handed out like candy for non issues, the severity rating system isn’t a serious evaluation of the actual severity (eg a vulnerable function may not even be compiled in), the scoring is inconsistent and subjective and frequently inflated to make the severity seem worse, and with the AI flood they have a massive backlog of handing out CVEs.

Like look at CVEs curl dealt with at one point that were just completely bogus and given huge severity ratings to start with.

But honestly if you’re the one proposing a “simple solution” maybe do some research yourself.


> But honestly if you’re the one proposing a “simple solution” maybe do some research yourself.

It's an off the cuff idea on a nerd forum. Relax buddy.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: