• sunbunman@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    27
    ·
    edit-2
    8 months ago

    The world really needs to work on decoupling their dependency on the US especially for something this vital. This should already have been a UN funded and run program at a minimum.

  • giacomo@lemm.ee
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    26
    ·
    9 months ago

    can they put cve on a blockchain? or some publicly auditable distributed database?

    its worrisome that all it takes is a funding cut to shut it down.

    • Echo Dot@feddit.uk
      link
      fedilink
      English
      arrow-up
      30
      ·
      9 months ago

      Oh yes blockchain the solution to the world’s problem. Provided the world’s problem is that the current solution works too well and we don’t like that.

      We need to back this data up but that doesn’t require anything anywhere near as complicated and over-engineered as blockchain, we can just have something as simple as multiple servers.

      • giacomo@lemm.ee
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        6
        ·
        8 months ago

        That works too, but who controls the servers, and how is the authority handled? Backing up the data is one thing, and that can be easily done I believe. But what about for future advisories? They are published via one of the authoritative servers and synced to the other authoritative servers? How is that information verified to ensure bad actors aren’t publishing bullshit information?

        I don’t think blockchain is necessarily the answer. The whole thing can just be done with signing keys, yeah?

        I know everyone hates on blockchain, but I think its kinda neat and would like to see some cool applications with it one day.

        • Echo Dot@feddit.uk
          link
          fedilink
          English
          arrow-up
          4
          ·
          edit-2
          8 months ago

          That’s an easy problem to solve you just hash the database. Blockchain is good at solving the problem when you don’t have a reliable central authority but if you do have a reliable central authority there’s no point adding blockchain to it.

          And we already have the reliable central authority, we have the original database.

    • Elvith Ma'for@feddit.org
      link
      fedilink
      English
      arrow-up
      3
      ·
      9 months ago

      And a blockchain helps to solve which part of the problem? Some were working on mirroring all data to a git repository. In theory, that allows for easy access on all the data, versioning (with commits) and - through forks and merge requests - collaboration and distribution. Also git is a distributed repository that clones the whole history to your local drive.

      https://github.com/MITRE-Cyber-Security-CVE-Database/mitre-cve-database

      But with the announcement of the cve foundation, I don’t know whether they will really import all the data in this git repository.