![]() |
|
Message-Id: <03568CF1-0196-4647-8949-30AB715A9B94@edvina.net> Date: Thu, 17 Apr 2025 08:40:08 +0200 From: "Olle E. Johansson" <oej@...ina.net> To: oss-security@...ts.openwall.com Subject: Re: CVE program averts swift end > On 17 Apr 2025, at 01:44, Alan Coopersmith <alan.coopersmith@...cle.com> wrote: > > On 4/16/25 12:38, Brian Behlendorf wrote: >> For critical infrastructure that requires sustained funding, it seems more important than ever to move to RAID - a Redundant Array of Independent Donors - so as to avoid the complete and total cut-off of any one (or a handful) of financial supporters that could collapse the system. I assume (hope?) that MITRE is pursuing alternative sources right now; if not, someone else should be. > > https://www.thecvefoundation.org/ appears to be doing so, but doesn't have > details ready to share just yet. https://euvd.enisa.europa.eu/ may be another > option, especially for EU folks. I think that we have to work towards a federated distributed global system, not relying on a single state or company. I’ve been working on gathering thoughts on it for a while, starting years ago when I realised that the NVD was poorly funded and only 25 persons. This will take time, but we have to start immediately. I believe the technical aspects will be solved, but we have to focus on building a working organisation for it. The current doc is here: https://docs.google.com/document/d/1u6yPlCla7SO6YuHakjvmcGtcEmHdp-NANaqpTDTA7Q0/edit?usp=sharing global-vuln-db docs.google.com I would very much like feedback, suggestions for change and ideas on the path forward. There is discussion in a discord group and in OpenSSF Vulnerability disclosuers working group too, as well as in other forums like the OWASP SBOM Forum. /O Content of type "text/html" skipped Download attachment "AHkbwyJ7Rd9uXDnl5mLiiMA1meu4gLXAv2ZHowE1UYj5ECZGF0QahMNBV2XmK3S7oYi8Jl3lJnFQBlXNE1Qo9h7hFfXtvpwBM5UOW7dW50YYTDXEwh8ZiTTY=w1200-h630-p.png" of type "image/png" (190064 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.