Artwork

Indhold leveret af Open Source Security and Josh Bressers. Alt podcastindhold inklusive episoder, grafik og podcastbeskrivelser uploades og leveres direkte af Open Source Security and Josh Bressers eller deres podcastplatformspartner. Hvis du mener, at nogen bruger dit ophavsretligt beskyttede værk uden din tilladelse, kan du følge processen beskrevet her https://da.player.fm/legal.
Player FM - Podcast-app
Gå offline med appen Player FM !

CVE for EOL with Aaron Frost

30:00
 
Del
 

Manage episode 476867163 series 1502626
Indhold leveret af Open Source Security and Josh Bressers. Alt podcastindhold inklusive episoder, grafik og podcastbeskrivelser uploades og leveres direkte af Open Source Security and Josh Bressers eller deres podcastplatformspartner. Hvis du mener, at nogen bruger dit ophavsretligt beskyttede værk uden din tilladelse, kan du følge processen beskrevet her https://da.player.fm/legal.

Aaron Frost explores the overly complex world of vulnerability identifiers for end of life software. We discuss how incomplete CVE reporting creates blind spots for users while arming attackers with knowledge. The conversation uncovers the ethical tensions between resource constraints and security transparency, highlighting why the "vulnerable until proven otherwise" approach is the best path forward for end of life software.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-04-cve_eol_aaron_frost/

  continue reading

506 episoder

Artwork

CVE for EOL with Aaron Frost

Open Source Security

277 subscribers

published

iconDel
 
Manage episode 476867163 series 1502626
Indhold leveret af Open Source Security and Josh Bressers. Alt podcastindhold inklusive episoder, grafik og podcastbeskrivelser uploades og leveres direkte af Open Source Security and Josh Bressers eller deres podcastplatformspartner. Hvis du mener, at nogen bruger dit ophavsretligt beskyttede værk uden din tilladelse, kan du følge processen beskrevet her https://da.player.fm/legal.

Aaron Frost explores the overly complex world of vulnerability identifiers for end of life software. We discuss how incomplete CVE reporting creates blind spots for users while arming attackers with knowledge. The conversation uncovers the ethical tensions between resource constraints and security transparency, highlighting why the "vulnerable until proven otherwise" approach is the best path forward for end of life software.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-04-cve_eol_aaron_frost/

  continue reading

506 episoder

All episodes

×
 
Loading …

Velkommen til Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Hurtig referencevejledning

Lyt til dette show, mens du udforsker
Afspil