Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

11–20 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#11
post #7

I'm trying to steelman but I really can't think of a non- nefarious justification for this

[flagged]

How do you get your volunteers in the first place and manage them so you know it's time to get a new one if the quality of their work is slipping?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#12

I'm trying to steelman but I really can't think of a non- nefarious justification for this

The process seems to be to dismantle anything not nailed down in government.

Now if you want that (even just funding) to be a thing ... you have to go through Trump & Co and pay your bribe to get it back up.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#14

If you work on OSS software on CVE management, then you already know that NVD funding reductions have been ongoing for more than a year. April 2024, https://nvd.nist.gov/general/news/nvd-program-transition-ann... NIST maintains the National Vulnerability Database (NVD).. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing backlog of vulnerabilities.. based on.. an increase in software…

What has been ongoing for more than a year?

The funding appears to have been cut off today, and both of these comments seem to talk about continuing work and how important it is.

Do you mean to say that some form of threat to the NVD has been around for over a year now? Just want to be sure I'm parsing correctly!

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#16
post #10
post #8

Earlier quoted context omitted.

Yet so far no volunteer has emerged and people who do run CNA are pretty busy with it.

I think sneak would volunteer to do it since it is pretty simple according to them.

Any work people don't understand must be easy and replaceable by chatgpt. Just look at how easy people here think farming is.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#18

I'm trying to steelman but I really can't think of a non- nefarious justification for this

> I'm trying to steelman

Why? This administration is not acting in good faith, you don't have to act as if they are. People and institutions doing that is part of how we got here in the first place.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#19
post #14

If you work on OSS software on CVE management, then you already know that NVD funding reductions have been ongoing for more than a year. April 2024, https://nvd.nist.gov/general/news/nvd-program-transition-ann... NIST maintains the National Vulnerability Database (NVD).. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing backlog of vulnerabilities.. based on.. an increase in software…

What has been ongoing for more than a year? The funding appears to have been cut off today, and both of these comments seem to talk about continuing work and how important it is. Do you mean to say that some form of threat to the NVD has been around for over a year now? Just want to be sure I'm parsing correctly!

Yes, NVD funding cuts and a growing CVE backlog began in late 2023.

May 2024, https://therecord.media/nist-database-backlog-growing-vulnch...

> Moving forward, cybersecurity companies will have to “fill the void” .. NVD said in April [2024] that it is “working to establish a consortium to address challenges in the NVD program and develop improved tools and methods.” .. CISA acknowledged the concerns and outrage of the security community and said it is starting an enrichment effort called “Vulnrichment," which will add much of the information described by Garrity to CVEs.

The second VulnCon event took place last week and no silver bullet has appeared, https://ygreky.com/2025/04/vulncon-2025-impressions/

  Vulnerability enrichment was mentioned in many talks. However, most organizations seem to handle it internally. There doesn’t appear to be momentum toward a shared or open source solution – at least not yet.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#20

I'm trying to steelman but I really can't think of a non- nefarious justification for this

> I'm trying to steelman Why? This administration is not acting in good faith, you don't have to act as if they are. People and institutions doing that is part of how we got here in the first place.

Force of habit. We don't have a framework for talking under these circumstances, so we apply our outdated ones.

As you say, that's exactly what got us here. But the alternatives are very unclear, and seem deeply unpleasant.

Post reply on HN