logoalt Hacker News

staticassertionyesterday at 11:25 PM1 replyview on HN

If the system "fails open" then it's not a DoS, it's a privilege escalation. What you're describing here is just a matter of threat modeling, which is up to you to perform and not a matter for CVEs. CVEs are local properties, and DoS does not deserve to be a local property that we issue CVEs for.


Replies

otabdeveloper4today at 6:29 AM

You're making too much sense for a computer security specialist.