ASW Episode 402
• Mike Shema
Going From Bug Bounty Bugs to More Secure Systems
Hello Packages, Parsers, and Programs,
How does appsec measure software quality failures?
With CVSS, which is a common vulnerability scoring system that turns severity into decimal points.
Those scores are assigned to CVEs, which are common vulnerability enumerations that turn bugs into unique identifiers.
And all those vulns share almost universal underlying problems that we call CWEs, that turn all that bug tracking into commonly wasted efforts.
I don't think it's a waste of effort to catalog all these vulns and weaknesses. The trap is using them as task queues. Appsec has adjusted the tactics of dealing with CVEs by defining thresholds for what to fix and talking about reachability and exploitability. But a better strategy has always felt like creating more effective controls around software (network isolation, granular access, observability) and setting higher expectations on software owners to deliver secure designs with secure defaults.
But even that strategy has been a common discussion throughout the decades of enumerating common vulnerabilities and common weaknesses. And that's why this week I departed from my usual modern synthwave shoutout to a track that captures the spirit of the 90s when these CVEs and CWEs were just starting.
Enjoy "Common People" by Pulp.