The Harmless Pi-Hole Bug
kiyell.com
The Harmless Pi-Hole Bug
1–10 of 48 posts
Re: The Harmless Pi-Hole Bug
#2This is just generating CVE numbers for the sake of it.
Re: The Harmless Pi-Hole Bug
#3Re: The Harmless Pi-Hole Bug
#4This stuff is why CVE numbers are meaningless. "Someone can see the temperature of your server if they can get into your home network" is barely a bug, let alone a security bug. This is just generating CVE numbers for the sake of it.
As it is now, I can look at a CVE and determine for myself and my organization whether it something we need to care about. I’d rather that decision stay in my hands, not someone else’s.
Re: The Harmless Pi-Hole Bug
#5This stuff is why CVE numbers are meaningless. "Someone can see the temperature of your server if they can get into your home network" is barely a bug, let alone a security bug. This is just generating CVE numbers for the sake of it.
Re: The Harmless Pi-Hole Bug
#6This stuff is why CVE numbers are meaningless. "Someone can see the temperature of your server if they can get into your home network" is barely a bug, let alone a security bug. This is just generating CVE numbers for the sake of it.
If you don't assign CVE numbers to every security-related flaw, no matter how minor the flaw may be, you must come up with a way to draw the line on what flaws get CVEs and what ones don’t. That would be worse in pretty much every respect. As it is now, I can look at a CVE and determine for myself and my organization whether it something we need to care about. I’d rather that decision stay in my hands, not someone el…
Unless there’s a minimum standard it becomes noise, and the real CVEs are lost.
Re: The Harmless Pi-Hole Bug
#7Earlier quoted context omitted.
If you don't assign CVE numbers to every security-related flaw, no matter how minor the flaw may be, you must come up with a way to draw the line on what flaws get CVEs and what ones don’t. That would be worse in pretty much every respect. As it is now, I can look at a CVE and determine for myself and my organization whether it something we need to care about. I’d rather that decision stay in my hands, not someone el…
So you are happy to have 1 million cves to look for per year per product? Unless there’s a minimum standard it becomes noise, and the real CVEs are lost.
Trying to ignore the extreme hyperbole here...
I want me or my team to see every security-related flaw affecting the products in our network, yes. That's literally our job.
A CVE like this takes maybe 2 minutes for a junior on the team to mark as no risk.
Re: The Harmless Pi-Hole Bug
#8This stuff is why CVE numbers are meaningless. "Someone can see the temperature of your server if they can get into your home network" is barely a bug, let alone a security bug. This is just generating CVE numbers for the sake of it.
Re: The Harmless Pi-Hole Bug
#9This stuff is why CVE numbers are meaningless. "Someone can see the temperature of your server if they can get into your home network" is barely a bug, let alone a security bug. This is just generating CVE numbers for the sake of it.
Re: The Harmless Pi-Hole Bug
#10Earlier quoted context omitted.
So you are happy to have 1 million cves to look for per year per product? Unless there’s a minimum standard it becomes noise, and the real CVEs are lost.
> So you are happy to have 1 million cves to look for per year per product? Trying to ignore the extreme hyperbole here... I want me or my team to see every security-related flaw affecting the products in our network, yes. That's literally our job. A CVE like this takes maybe 2 minutes for a junior on the team to mark as no risk.
Because the people that do conduct sophisticated attacks are studying every knock and cranny for these types of things. If they can find it once, they can automate it and find more. And then they move on to the next piece of their puzzle of "what can I do from here?"