Stop doing CVEs

And other vulnerability management rules to live by

An intro

A decade+ fightingsecuring computers.

Currently @ Tailscale.

Likes cameras, bikes, and synths more than keyboards.

Black and white self-portrait of the speaker holding a camera

Stop doing CVEs and CVSS

CVEs produce tickets not updates.

Context >> CVSS scores.

LOW/MED/HIGH is all you need.

Comic: the short path goes fix issued, read the bulletin, update; the CVE path goes scanner flags CVE, ticket filed, triage meeting, risk accepted

Threat model like a startup

Scope small to start.

Revisit after each incident learning opportunity.

Frameworks to check vs constrain work.

Publish bulletins

Use plain language. Never hide the ball.

Explain the implications.

Near misses are cool too.

Cartoon of a man changing a 'Days since last accident' sign

Stop doing bug bounties

Be the first to point agents at your code.

Public credit compounds.

Pay for time, not findings.

Meme of a man grinning at a gravestone labeled 'Bug bounties', his shirt labeled 'Agentic vuln hunting'

Prioritize safe updates

Remember backwards compatibility.

Permit old behavior with flags if necessary.

“Latest is greatest” – me, today

Vulnerability management rules to live by

  1. Stop doing CVEs and CVSS
  2. Threat model like a startup
  3. Stop doing bug bounties
  4. Publish bulletins
  5. Prioritize safe updates

Trust is all you have