Conversation

Charlotte 🦝 therian

random reminder that CVSS scores don’t mean shit

2
1
5

it’s certainly the “imagine a perfectly spherical cow in a vacuum” of measuring impact of security issues

1
0
5

@charlotte "Users with root privileges can open arbitrary ports" » CVSS 11.69, shut down the internet immediately

0
0
0

so like a cvss 9.9 doesn’t mean you are fucked

it might require running the software in a known insecure configuration (like having a print service open to an untrusted network)

1
2
4

@charlotte It was a revelation to my colleagues when I told them about the 'ignore' button on security reports. It had never occurred to them that it was a valid decision to read the report and determine if our software is affected. XD

1
0
0
@maruno

a friend has had the most absurd security team that wanted the production website taken down because it was a source code leak
1
1
0

@charlotte Was it the website's javascript? XD

1
0
0

@maruno yeah and html and css

0
0
1