Skip Navigation

The Linux kernel is a CNA - so what?

www.codethink.co.uk The Linux kernel is a CNA - so what?

<p>This is big news. It may not seem like it at first glance, but the impact could be huge.</p>

The Linux kernel is a CNA - so what?
6

You're viewing a single thread.

6 comments
  • Short version: A bunch of shitty companies have as business model to sell open databases to companies to track security vulnerabilities - at pretty much zero effort to themselves. So they've been bugging the kernel folks to start issuing CVEs and do impact analysis so they have more to sell - and the kernel folks just went "it is the kernel, everything is critical"

    tl;dr: this is pretty much an elaborate "go fuck yourself" towards shady 'security' companies.

    • and the kernel folks just went “it is the kernel, everything is critical”

      tl;dr: this is pretty much an elaborate “go fuck yourself” towards shady ‘security’ companies.

      Apologies for my ignorance, but could you elaborate?

      I'm sincerely not seeing the connection between saying everything is critical as a go fuck yourself towards those companies.

      Is it a 'death by quantity' thing?

      Anti Commercial-AI license (CC BY-NC-SA 4.0)

      • Is it a ‘death by quantity’ thing?

        Pretty much that - those companies rely on open projects to sort it for them, so they're pretty much scraping open databases, and selling good data they pull from there. That's why they were complaining about the kernel stuff - the info required was there already, just you needed to put effort in, so they were asking for CVEs. Now they got their CVEs - but to profit from it they'd still need to put the same effort in as they'd had to without CVEs in place.

You've viewed 6 comments.