Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

41–50 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#41
post #10

Earlier quoted context omitted.

I think sneak would volunteer to do it since it is pretty simple according to them.

Any work people don't understand must be easy and replaceable by chatgpt. Just look at how easy people here think farming is.

Grok becoming an artificial nepobaby running the entire CVE program with zero oversight sounds so fucking funny I don't even care, PLEASE god make this real holy shit I can't breathe at the thought

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#42

I'm trying to steelman but I really can't think of a non- nefarious justification for this

We have a 2tn deficit. If Congress wants to fund this, they need to make it mandatory spending and raise taxes.

That's a good idea to raise during the budget time or with some warning ahead of time. But even discussing the cost of CVE program itself is likely a waste of time and money. When trying to deal with 2tn deficit, looking at things that historically got ~$5M is just a distraction. And the lack of it may cost even more given how many existing agreements/contracts rely on cve to be a thing - maybe just in gov lawyers having to rewrite things.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#43
post #21

Earlier quoted context omitted.

I've noticed that there's a post like this in most articles on HN that could be construed as negative for the current administration: some vague false statement followed by either a factually incorrect explanation or some quote that does not support the statement.

What is incorrect about the post above? There are citations from multiple reputable news outlets for each claim. People who actually work with CVEs have been posting about this problem on HN for 18 months.

Your post has now been edited to be factually correct. But the misleading implication that this abrupt cut is part of some other cuts that started before remains.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#44

I'm trying to steelman but I really can't think of a non- nefarious justification for this

We have a 2tn deficit. If Congress wants to fund this, they need to make it mandatory spending and raise taxes.

Selling bonds is not the same thing as a family budget being in the red. Either you know this and you're making this argument in bad faith, or you don't and, well...

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#45
post #43

Earlier quoted context omitted.

What is incorrect about the post above? There are citations from multiple reputable news outlets for each claim. People who actually work with CVEs have been posting about this problem on HN for 18 months.

Your post has now been edited to be factually correct. But the misleading implication that this abrupt cut is part of some other cuts that started before remains.

The post (currently AND previous to comments being moved here from a different HN thread) links to the official _2024_ (not 2025) statement about NVD cutbacks. Here's a 3000 word article with quotes from Linux Foundation and commercial vendors, around the same time, https://news.ycombinator.com/item?id=43700884

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#48
Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#49

What are the implications of this? No more centralized store of vulnerability information?

Basically when any software/library/whatever has a vulnerability, they have to communicate that out themselves, in some format.

If I'm developing a product built on 20 libraries, it won't just be a matter of scanning CVEs for major vulnerabilities any more, so I'm more likely to miss one.

"always update" doesn't always work, when to manage a product you realistically have to version pin.

Post reply on HN