Elektrine lite

← Feed

@pgl@infosec.exchange

2026-06-29 16:11 UTC

On defining exactly what a "vulnerability" actually is: https://research.empiricalsecurity.com/research/the-vulnerability-identity-crisis Really interesting discussion and proposals on how to define a "vulnerability" by @jayjacobs@infosec.exchange

Replies (4)

  • @pgl@infosec.exchange @jayjacobs@infosec.exchange This is really fascinating. I think another aspect of a vulnerability is that the security failure either (a) violates an explicit requirement or (b) inarguably violates an implicit requirement. This ties to the long argument in the early days of CVE about fingerd: fingerd failed to meet (a) or (b). I think a big chunk of CVE success was that we didn't do a lot of those.

    Open ##3492480

  • @wolf480pl@mstdn.io 2026-06-29 17:55

    @pgl@infosec.exchange @jayjacobs@infosec.exchange Noob question: Does C have to include at least one attacker-controlled condition, to exclude things like (hypothetical) "restarting the database engine (S) during a leap second (C) causes a race condition (f) which results in all data files being overwritten with zeros (F)" ?

    Open ##3517553

  • @vex@kolektiva.social 2026-06-29 18:04

    @pgl@infosec.exchange @jayjacobs@infosec.exchange I find it interesting that vulnerability has been half defined for so long, & predict our social/economic system's dependence on vulnerabilities as being related.

    Open ##3517557

  • @jbm@infosec.exchange 2026-07-27 08:08

    @pgl@infosec.exchange @jayjacobs@infosec.exchange for reference, @zmanion@infosec.exchange and @jayjacobs@infosec.exchange presentation from VulnCon in April: https://www.first.org/conference/vulncon26/program#pA-Paradigm-Shift-in-Vulnerability-Identity-Why-Vulnerability-Databases-Struggle https://www.youtube.com/watch?v=3_s61rBvIVo&list=PLBAUUhONOrO_yESOH6JnwWBoRdDRVXDr0&index=23 Great pres, AFAIC 2026 best so far.

    Open ##4132199