Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> I really can't think of a non- nefarious justification for this

Tragedy of the commons - NVD and the CVE project havr been backlogged and facing funding issues for a couple years now, and most security vendors are either cagey about providing vulns in a timely manner (as it can reduce their own comparative advantage), or try upsell their own alternative risk prioritization scores.

Every company will gladly use NVD and CVE data, but no one wants to subsidize it and help a competitor, especially in an industry as competitive as cybersecurity.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: