Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

81–90 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#81
post #70

Earlier quoted context omitted.

Or cut from $877B in defense spending instead? https://usafacts.org/government-spending/

Listen, I hate the debt, but we have an income problem, not a spending problem. The military looks like a waste, but it does more than build bombs i.e research etc. The issue we have is that republican every chance they get since the 1970s have cut taxes. And then blamed democrats for causing the deficits. We don't need smaller governments. We need a reasonable tax system that taxes people. It can be progressive like…

Military also employs a bunch of people who otherwise would be poor. Also provides a gentrification path for a bunch of previously poor people extending throughout their lives.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#82
post #64

I guess their new business model is to sell zero days to the highest bidder

The private sector zero day market collapsed last year with Zerodium - corporate bug bounties, nation states in-housing offensive security operations, and the democratization of knowhow destroyed the Zero Day market.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#83
post #70

Earlier quoted context omitted.

Or cut from $877B in defense spending instead? https://usafacts.org/government-spending/

Listen, I hate the debt, but we have an income problem, not a spending problem. The military looks like a waste, but it does more than build bombs i.e research etc. The issue we have is that republican every chance they get since the 1970s have cut taxes. And then blamed democrats for causing the deficits. We don't need smaller governments. We need a reasonable tax system that taxes people. It can be progressive like…

Yeah republicans claim to want to run the government like a business, but the first thing a business should do when they have a deficit is raise revenue! And especially in the case of the US government, the the only barriers to doing that are self-imposed.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#84

Reminds me of Trump's first term where he said if we stopped testing for Covid, we'd stop catching new cases and case numbers would go down. If you stop testing for vulnerabilities then vulnerabilities go down. Easy stuff.

[flagged]

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#85
post #80

Earlier quoted context omitted.

it might be ignorance; it might be malice. it might also be deliberate: that they actually don't think the government should be involved in this sort of thing. after all, someone could be making a profit on this, and that seems to be their highest value. if gov is involved, that makes it a communal effort, and you know what else starts with "commun-"? yes, those reasons are stupid and ignorant AND intentional. but is…

Hanlon's razor. I also tend to impute malice to things I don't like, but I think it's hard to go past stupidity.

Stupidity rarely has a consistent destructive track record. You score occasional wins. Only malice allows every decision to do damage. (The other razor, essentially - Occam)

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#87
post #13

Earlier quoted context omitted.

Privatize all teh things?

This neo-liberal approach has no place for soft diplomacy, which is what US hegemoney relies on. This isn't just a rapid disassembly of economic structures, any trust and goodwill is completely obliterated as well.

For decades, the US could be counted upon to fund things with little immediate benefit but massive long-term positive externalities. I don't think its likely that the republican party will "go back to normal" post-Trump, so we can all kiss the long-term reputation building that American hegemony relied upon goodbye. Short of a great depression-esque political reset, I do not see things changing for the better.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#88

If you work on OSS software on CVE management, then you already know that NVD funding reductions have been ongoing for more than a year. April 2024, https://nvd.nist.gov/general/news/nvd-program-transition-ann... NIST maintains the National Vulnerability Database (NVD).. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing backlog of vulnerabilities.. based on.. an increase in software…

There is nothing in that article mentioning funding reductions.

That article is about how the volume of software vulnerabilities are increasing, resulting in difficulty keeping up by the CVE and NVD projects.

Please stop spamming this thread with political spin.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#90
post #75

Earlier quoted context omitted.

> I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? This was not a carefully-weighed decision based on a cost-benefit analysis. This was a political order, consistent with the administration's policy of "cut everything, recklessly, indiscriminately."

Destroy, destroy, destroy. Promise to rebuild but don't. Take it all.

Vampire capitalism. They want civilization to break down so they can offer a solution for profit. The enemies of all people and life on the planet are a tiny group of oligarchs and their supplicants.
Post reply on HN