Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

21–30 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#21

If you work on OSS software on CVE management, then you already know that NVD funding reductions have been ongoing for more than a year. April 2024, https://nvd.nist.gov/general/news/nvd-program-transition-ann... NIST maintains the National Vulnerability Database (NVD).. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing backlog of vulnerabilities.. based on.. an increase in software…

I've noticed that there's a post like this in most articles on HN that could be construed as negative for the current administration: some vague false statement followed by either a factually incorrect explanation or some quote that does not support the statement.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#22
post #21

If you work on OSS software on CVE management, then you already know that NVD funding reductions have been ongoing for more than a year. April 2024, https://nvd.nist.gov/general/news/nvd-program-transition-ann... NIST maintains the National Vulnerability Database (NVD).. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing backlog of vulnerabilities.. based on.. an increase in software…

I've noticed that there's a post like this in most articles on HN that could be construed as negative for the current administration: some vague false statement followed by either a factually incorrect explanation or some quote that does not support the statement.

What is incorrect about the post above? There are citations from multiple reputable news outlets for each claim.

People who actually work with CVEs have been posting about this problem on HN for 18 months.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#26

I'm trying to steelman but I really can't think of a non- nefarious justification for this

I think it’s ignorance and arrogance. The US seems to be on a path to lose technological and science leadership. The current leadership doesn’t seem to understand things that aren’t flashy. I wonder when they’ll dial back on food safety. I am sure RFK knows some vitamins that protect against salmonella

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#27
post #20

Earlier quoted context omitted.

> I'm trying to steelman Why? This administration is not acting in good faith, you don't have to act as if they are. People and institutions doing that is part of how we got here in the first place.

Force of habit. We don't have a framework for talking under these circumstances, so we apply our outdated ones. As you say, that's exactly what got us here. But the alternatives are very unclear, and seem deeply unpleasant.

[flagged]

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#28
post #25

Mr. President, Do you want China to get the reports instead, or do you want the NSA to have a lead time where the vuln's are useful tools?

If you /s/China/Russia/, when asking Trump, it’s no longer a rhetorical question.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#30
post #7

I'm trying to steelman but I really can't think of a non- nefarious justification for this

[flagged]

Thanks for volunteering to manage the "300-600 CVEs each month"!

The world needs more volunteers like you.

Post reply on HN