Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

51–60 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#51
I wish this hadn't happened.

I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides?

I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do their own research (tm) and mis-understand what they saw in how other people work with CVE, and who funds it.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#52
post #48

Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?

and then a random 9.8 critical comes that affects some software you have in a way that makes it a 0 in your environment but it doesn't matter cause the cve tanks your organizational Security Score (tm) by 10 arbitrary points and management is wondering when you'll secure the company again because the Security Score is their only tangible deliverable to measure success

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#53

I'm trying to steelman but I really can't think of a non- nefarious justification for this

We have a 2tn deficit. If Congress wants to fund this, they need to make it mandatory spending and raise taxes.

Dear god, you don't just stop running government completely because you have a deficit.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#54
post #52
post #48

Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?

and then a random 9.8 critical comes that affects some software you have in a way that makes it a 0 in your environment but it doesn't matter cause the cve tanks your organizational Security Score (tm) by 10 arbitrary points and management is wondering when you'll secure the company again because the Security Score is their only tangible deliverable to measure success

[deleted]

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#55
post #52
post #48

Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?

and then a random 9.8 critical comes that affects some software you have in a way that makes it a 0 in your environment but it doesn't matter cause the cve tanks your organizational Security Score (tm) by 10 arbitrary points and management is wondering when you'll secure the company again because the Security Score is their only tangible deliverable to measure success

I feel that. So tired of management being completely uninterested in actual, actionable security holes but getting wildly spun up because they saw a notice with a big scary number that has absolutely no relevance in our architecture.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#56

Earlier quoted context omitted.

I think it’s ignorance and arrogance. The US seems to be on a path to lose technological and science leadership. The current leadership doesn’t seem to understand things that aren’t flashy. I wonder when they’ll dial back on food safety. I am sure RFK knows some vitamins that protect against salmonella

important to note: the US's food safety is already really bad. salmonella isn't a thing you have to worry about in first world countries. can't wait to see what plague demon spawns out of a food industry running amok after the FDA gets gutted.

> important to note: the US's food safety is already really bad. salmonella isn't a thing you have to worry about in first world countries.

There were 65,000 cases of salmonellosis in the EU in the most recent data I could find (2022). Thats a lower per capita rate than the US, but definitely not zero.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#57

I'm trying to steelman but I really can't think of a non- nefarious justification for this

I think it’s ignorance and arrogance. The US seems to be on a path to lose technological and science leadership. The current leadership doesn’t seem to understand things that aren’t flashy. I wonder when they’ll dial back on food safety. I am sure RFK knows some vitamins that protect against salmonella

the guy is ultimate small gov. he wants to rip it out by the roots.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#58

If you work on OSS software on CVE management, then you already know that NVD funding reductions have been ongoing for more than a year. April 2024, https://nvd.nist.gov/general/news/nvd-program-transition-ann... NIST maintains the National Vulnerability Database (NVD).. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing backlog of vulnerabilities.. based on.. an increase in software…

I did find this post to be non-helpful and confusing. It would be helpful to edit it (or write differently in the future) to clarify that the sudden defunding event occurring today is separate and not related to the previous funding cuts. If that's the case.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#59

I'm trying to steelman but I really can't think of a non- nefarious justification for this

I think it’s ignorance and arrogance. The US seems to be on a path to lose technological and science leadership. The current leadership doesn’t seem to understand things that aren’t flashy. I wonder when they’ll dial back on food safety. I am sure RFK knows some vitamins that protect against salmonella

[deleted]

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#60
post #7

Earlier quoted context omitted.

[flagged]

Thanks for volunteering to manage the "300-600 CVEs each month"! The world needs more volunteers like you.

You manage the system and not the CVEs themselves. The simplist thing would be a list of numbers that correspond to Google docs. The owner of the Google doc can share it with the needed parties and eventually set it as public.
Post reply on HN