Jerry Gamblin (@JGamblin) on X

1 min read Original article ↗

Post

Post

  • user avatar

    While I understand the intention, there seems to be a disconnect between the policy makers and reality.

  • user avatar

    “There are two kinds of software: those with CVEs and those with vulns that haven’t yet been assigned CVEs.”

  • user avatar

    I can't see this policy being abused at all 🙄

    user avatar

    Replying to @gsuberland

    intent: security will be ensured reality: hackers (including those under the employ of foreign governments) can now perpetually tie up sales deals to the DoD by finding a bunch of bugs in a system and timing their disclosures so there's always at least one open CVE.