If you work on OSS software on CVE management, then you already know that NVD funding reductions have been ongoing for more than a year. April 2024, https://nvd.nist.gov/general/news/nvd-program-transition-ann... NIST maintains the National Vulnerability Database (NVD).. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing backlog of vulnerabilities.. based on.. an increase in software…
CVE program faces swift end after DHS fails to renew contract [updated]
21–30 of 1001 posts
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#22If you work on OSS software on CVE management, then you already know that NVD funding reductions have been ongoing for more than a year. April 2024, https://nvd.nist.gov/general/news/nvd-program-transition-ann... NIST maintains the National Vulnerability Database (NVD).. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing backlog of vulnerabilities.. based on.. an increase in software…
I've noticed that there's a post like this in most articles on HN that could be construed as negative for the current administration: some vague false statement followed by either a factually incorrect explanation or some quote that does not support the statement.
People who actually work with CVEs have been posting about this problem on HN for 18 months.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#23Re: CVE program faces swift end after DHS fails to renew contract [updated]
#24Re: CVE program faces swift end after DHS fails to renew contract [updated]
#25Re: CVE program faces swift end after DHS fails to renew contract [updated]
#26I'm trying to steelman but I really can't think of a non- nefarious justification for this
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#27Earlier quoted context omitted.
> I'm trying to steelman Why? This administration is not acting in good faith, you don't have to act as if they are. People and institutions doing that is part of how we got here in the first place.
Force of habit. We don't have a framework for talking under these circumstances, so we apply our outdated ones. As you say, that's exactly what got us here. But the alternatives are very unclear, and seem deeply unpleasant.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#28Mr. President, Do you want China to get the reports instead, or do you want the NSA to have a lead time where the vuln's are useful tools?