Content for the CERT Guide to Coordinated Vulnerability Disclosure
8 stars 4 forks source link

Portal interoperabillity #14

Closed ahouseholder closed 2 months ago

ahouseholder commented 3 months ago

MPCVD requires coordination across potentially large groups of participants (vendors, reporters, coordinators, etc.). Yet the increasing tendency towards portal-based CVD (including VINCE) means that everyone has to have some level of account or access to everyone else's tracking system(s). In the long run, this is unsustainable. There are two possible directions: centralization or decentralized interoperability. Vultron is intended to enable the decentralized option. The guide should talk about that as an emerging issue as things shift away from email-based ad-hoc coordination.