I think it's better over the long run to keep the CVE as the "canonical" name and just treat the others like nicknames. Instead we have branding, logos, domain names etc. Some argue that it's easier to get attention or shame a vendor by going all-out, but it seems like overkill for a simple mnemonic.
I think a lot of it is that there are folks who want to contribute to security awareness, and their skills lie with design/branding rather than with low level security concepts.
I can't speak for what the value-add is there, but I don't see any harm from it.
Comments
What is a vuln name, other than a binding of a CVE to a real word to make it easier to reference or promote.
It draws public attention to an issue better than any CVE-2017-XXXXX would do.
No, keep it up. Dictionary words are far easier to remember than specific numbers.
I think it's better over the long run to keep the CVE as the "canonical" name and just treat the others like nicknames. Instead we have branding, logos, domain names etc. Some argue that it's easier to get attention or shame a vendor by going all-out, but it seems like overkill for a simple mnemonic.
I think a lot of it is that there are folks who want to contribute to security awareness, and their skills lie with design/branding rather than with low level security concepts.
I can't speak for what the value-add is there, but I don't see any harm from it.