oss-sec mailing list archives
Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies
From: Solar Designer <solar () openwall com>
Date: Sun, 6 Mar 2016 13:29:59 +0300
On Sun, Mar 06, 2016 at 09:27:00AM +0300, gremlin () gremlin ru wrote:
On 2016-03-05 20:20:39 +0300, Solar Designer wrote: > Problem solved: > http://www.openwall.com/ove Hmmm... sorry to say, but I've garbaged 21 IDs by simply visiting this page and reloading it twice just to see what would happen :-)
A few people said they felt sorry about that, but I think this is actually OK.
So I'd suggest adding a BRB (Big Red Button) for those who actually need an ID,
I had thought of that and decided to do without it for now. (Also considered captcha.) I like to emphasize how very easy it is to obtain OVE IDs. Not even having to click a button serves that goal well. I don't mind adding a button a bit later, though. We'll see.
and displaying some statistics ("1234 IDs were assigned today") for everyone else.
This is currently available through OVE IDs themselves - they are sequential, starting with 0001 at midnight UTC.
> Having IDs is of some use even without or before all of that. Yes. So prepare for the above link to become really popular.
As it is, it should survive quite a few thousand of unique IPs per day (and yes, it temporarily records per IP address statistics, and it has per-IP and per-netblock limits), before (gradually) denying service for the rest of the day. It might or might not survive a Slashdot-alike event, but even if not then waiting a day for the next batch of IDs is quicker than waiting weeks for CVE IDs. BTW, there is not a hard-coded limit of 9999. There is logic in place to try and keep the daily IDs within 9999 (the service becomes less generous as the 4-digit space gets closer to being exhausted), but if the requests and unique IPs are too numerous this may be crossed anyway, resulting in 5- or 6-digit IDs (and going back to 4-digit the next day). Alexander
Current thread:
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies, (continued)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Adam Caudill (Mar 05)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Solar Designer (Mar 05)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Tim (Mar 05)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies me (Mar 06)
- CVE Replacement Via Blockchains (was: Concerns about CVE coverage shrinking - direct impact to researchers/companies) Tim (Mar 07)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Art Manion (Mar 10)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Simon Ward (Mar 07)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies David A. Wheeler (Mar 09)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies gremlin (Mar 05)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Rahul Pratap Singh (Mar 06)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Solar Designer (Mar 06)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies op7ic \x00 (Mar 06)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Solar Designer (Mar 06)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies op7ic \x00 (Mar 06)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Solar Designer (Mar 06)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Robert Paprocki (Mar 06)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Gsunde Orangen (Mar 06)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Amos Jeffries (Mar 06)
- RE: [security-vendor] Re: [oss-security] Concerns about CVE coverage shrinking - direct impact to researchers/companies Radzykewycz, T (Radzy) (Mar 07)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Tim Brown (Mar 09)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Kurt Seifried (Mar 09)