logoalt Hacker News

izacustoday at 9:04 AM5 repliesview on HN

"An app can bypass OS security system with certain setting enabled" absolutely fits into CVEs. There's no "depends: on it.

I love how quickly you all forget about security and privacy when it gives a chance to angrily rant.


Replies

TeMPOraLtoday at 9:15 AM

Anything can fit into CVE.

"An app can bypass OS security system with certain setting enabled" is absolutely a valid CVE. We have countless examples every day of vendor apps bypassing OS security systems because they're allowed to do so.

"A device can bypass protective layers and cause soft tissue damage when thrown" is an absolutely fine CVE, too.

Whether it matters or is something that should be addressed, is the depends part. Here we're talking about CVE that's at risk of trying to address a feature.

You are forgetting the most important questions of security, without which the whole discussion becomes pointless:

Who is securing what, and from who?

CVEs seem much less like holy writ when they're aimed at protecting the device for commercial interests and from the device owner.

show 1 reply
vrightertoday at 9:22 AM

a lot of cves are of the type "if you leave the keys in the door, then anyone can unlock it and get in! We must destroy all doors, they are insecure!"

This is one of them

show 2 replies
rcxdudetoday at 9:11 AM

When half that security is aimed against the user it's pretty easy to cheer for cracks in it.

J-Kuhntoday at 11:34 AM

I changed the sudo settings to not require a password.

Now an application on my computer can obtain root without user interaction.

Where is my CVE?

crotetoday at 10:19 AM

Sounds like the Settings panel is a CVE, we should immediately get rid of it. And don't forget the Play Store!