Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

31–40 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#31
post #13

I'm trying to steelman but I really can't think of a non- nefarious justification for this

Privatize all teh things?

This neo-liberal approach has no place for soft diplomacy, which is what US hegemoney relies on.

This isn't just a rapid disassembly of economic structures, any trust and goodwill is completely obliterated as well.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#32

I'm trying to steelman but I really can't think of a non- nefarious justification for this

I think it’s ignorance and arrogance. The US seems to be on a path to lose technological and science leadership. The current leadership doesn’t seem to understand things that aren’t flashy. I wonder when they’ll dial back on food safety. I am sure RFK knows some vitamins that protect against salmonella

important to note: the US's food safety is already really bad. salmonella isn't a thing you have to worry about in first world countries. can't wait to see what plague demon spawns out of a food industry running amok after the FDA gets gutted.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#35

I'm trying to steelman but I really can't think of a non- nefarious justification for this

> I really can't think of a non- nefarious justification for this

Tragedy of the commons - NVD and the CVE project havr been backlogged and facing funding issues for a couple years now, and most security vendors are either cagey about providing vulns in a timely manner (as it can reduce their own comparative advantage), or try upsell their own alternative risk prioritization scores.

Every company will gladly use NVD and CVE data, but no one wants to subsidize it and help a competitor, especially in an industry as competitive as cybersecurity.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#36

I'm trying to steelman but I really can't think of a non- nefarious justification for this

We have a 2tn deficit. If Congress wants to fund this, they need to make it mandatory spending and raise taxes.

Or cut from $877B in defense spending instead?

https://usafacts.org/government-spending/

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#37

I'm trying to steelman but I really can't think of a non- nefarious justification for this

> I'm trying to steelman Why? This administration is not acting in good faith, you don't have to act as if they are. People and institutions doing that is part of how we got here in the first place.

I still find it wild that so many people are trying to frame these decisions through a political lens. This is the actions of a foreign bad actor dismantling critical institutions from within, not "bad policy".

Surely there's an antibody response.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#38
post #13

I'm trying to steelman but I really can't think of a non- nefarious justification for this

Privatize all teh things?

April 2024 article on the result of NVD funding cutbacks, with comments by Linux Foundation OpenSSF, security startups like ChainGuard and commercial vendors, https://www.securityweek.com/cve-and-nvd-a-weak-and-fracture...

  Threat intelligence firm Flashpoint noted in March 2024 it was aware of 100,000 vulnerabilities with no CVE number and consequently no inclusion in NVD. More worryingly, it said that 330 of these vulnerabilities (with no CVE number) had been exploited in the wild.. Since the start of 2024 there have been a total of 6,171 total CVE IDs with only 3,625 being enriched by NVD. That leaves a gap of 2,546 (42%!) IDs.
Despite all those private companies and various OSS projects being willing to contribute ideas, infrastructure and code, they have somehow failed to coalesce into a decentralized replacement for NVD, built on CC0 data and OSS tooling.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#39

I'm trying to steelman but I really can't think of a non- nefarious justification for this

It's incredibly foolish. Whatever the justification is, it doesn't matter as much as the horrible outcome.

This is one of those things the government does for the benefit of the whole.

Post reply on HN