Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

71–80 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#71
post #48

Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?

These sound like downstream effects of funding stress to me, no?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#72

Earlier quoted context omitted.

I think it’s ignorance and arrogance. The US seems to be on a path to lose technological and science leadership. The current leadership doesn’t seem to understand things that aren’t flashy. I wonder when they’ll dial back on food safety. I am sure RFK knows some vitamins that protect against salmonella

important to note: the US's food safety is already really bad. salmonella isn't a thing you have to worry about in first world countries. can't wait to see what plague demon spawns out of a food industry running amok after the FDA gets gutted.

That’s just not true.

https://www.npr.org/sections/shots-health-news/2025/04/15/nx...

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#75
post #51

I wish this hadn't happened. I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do t…

> I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? This was not a carefully-weighed decision based on a cost-benefit analysis. This was a political order, consistent with the administration's policy of "cut everything, recklessly, indiscriminately."

Destroy, destroy, destroy. Promise to rebuild but don't. Take it all.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#76
post #48

Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?

The scores were never going to be that accurate across people's environments (IDK how much other places relied on them, places I worked never did that much) and issues with the scores don't seem to be a good justification to torch the whole CVE system anyway.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#77
post #51

I wish this hadn't happened. I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do t…

it might be ignorance; it might be malice.

it might also be deliberate: that they actually don't think the government should be involved in this sort of thing. after all, someone could be making a profit on this, and that seems to be their highest value. if gov is involved, that makes it a communal effort, and you know what else starts with "commun-"?

yes, those reasons are stupid and ignorant AND intentional.

but is there any evidence against that interpretation?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#78

I'm trying to steelman but I really can't think of a non- nefarious justification for this

> I'm trying to steelman Why? This administration is not acting in good faith, you don't have to act as if they are. People and institutions doing that is part of how we got here in the first place.

Imagine being eaten alive by a cackling hyena that ambushed you and all the while being like "hmm what is the appropriate steelman here? why do I deserve this? why is this just?"

In reality this would never happen so all these people playing steelman are just detached/insulated.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#79
post #52

Earlier quoted context omitted.

and then a random 9.8 critical comes that affects some software you have in a way that makes it a 0 in your environment but it doesn't matter cause the cve tanks your organizational Security Score (tm) by 10 arbitrary points and management is wondering when you'll secure the company again because the Security Score is their only tangible deliverable to measure success

Yeah like when we bundled in a .js library for client side date processing that has a CVE affecting node.js servers with high score. Our auditors don’t care they tag the whole app as high risk. It doesn’t even run on the server!

the auditors that sign off on your security to meet your clients requirements usually know way less about your security posture than your clients do

its all just surface-level box-checking. most companies required to get 'penetration tests' just get an overpriced Nessus scan sold as a pentest and that meets their reqs.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#80
post #51

I wish this hadn't happened. I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do t…

it might be ignorance; it might be malice. it might also be deliberate: that they actually don't think the government should be involved in this sort of thing. after all, someone could be making a profit on this, and that seems to be their highest value. if gov is involved, that makes it a communal effort, and you know what else starts with "commun-"? yes, those reasons are stupid and ignorant AND intentional. but is…

Hanlon's razor. I also tend to impute malice to things I don't like, but I think it's hard to go past stupidity.
Post reply on HN