Did you see that the U.S. is no longer funding the national security CVE program?
I’m glad to see they’re doing away with the “neutral third party” and going with a free market solution.
I’m starting my own CVE service. Here’s my price-list:
- Regular CVE’s: $1,000 evaluation fee
- CVE’s where you get to pick the number: $10,000 (though certain numbers will be sold at auction… how much would you pay to be responsible for CVE-69?)
- Special packages:
- $100,000/year and your company’s products will get a lower severity.
- $10,000,000/year and all CVEs related to your product will be rejected as irreproducible.
I accept Bitcoin, Venmo, and cash in unmarked envelopes slid under my door.