Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

91–100 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#91
post #75

Earlier quoted context omitted.

> I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? This was not a carefully-weighed decision based on a cost-benefit analysis. This was a political order, consistent with the administration's policy of "cut everything, recklessly, indiscriminately."

Destroy, destroy, destroy. Promise to rebuild but don't. Take it all.

So much for the wunderkinds in DOGE.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#92

If you work on OSS software on CVE management, then you already know that NVD funding reductions have been ongoing for more than a year. April 2024, https://nvd.nist.gov/general/news/nvd-program-transition-ann... NIST maintains the National Vulnerability Database (NVD).. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing backlog of vulnerabilities.. based on.. an increase in software…

There is nothing in that article mentioning funding reductions. That article is about how the volume of software vulnerabilities are increasing, resulting in difficulty keeping up by the CVE and NVD projects. Please stop spamming this thread with political spin.

[deleted]

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#93
post #43

Earlier quoted context omitted.

Your post has now been edited to be factually correct. But the misleading implication that this abrupt cut is part of some other cuts that started before remains.

The post (currently AND previous to comments being moved here from a different HN thread) links to the official _2024_ (not 2025) statement about NVD cutbacks. Here's a 3000 word article with quotes from Linux Foundation and commercial vendors, around the same time, https://news.ycombinator.com/item?id=43700884

NVD != CVE

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#94

If you work on OSS software on CVE management, then you already know that NVD funding reductions have been ongoing for more than a year. April 2024, https://nvd.nist.gov/general/news/nvd-program-transition-ann... NIST maintains the National Vulnerability Database (NVD).. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing backlog of vulnerabilities.. based on.. an increase in software…

There is nothing in that article mentioning funding reductions. That article is about how the volume of software vulnerabilities are increasing, resulting in difficulty keeping up by the CVE and NVD projects. Please stop spamming this thread with political spin.

[deleted]

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#95
post #48

Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?

This is bikeshedding. The point is an authoritative process and an identifier

All this does is help Putin and other rich grifters.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#96

What are the implications of this? No more centralized store of vulnerability information?

Basically when any software/library/whatever has a vulnerability, they have to communicate that out themselves, in some format. If I'm developing a product built on 20 libraries, it won't just be a matter of scanning CVEs for major vulnerabilities any more, so I'm more likely to miss one. "always update" doesn't always work, when to manage a product you realistically have to version pin.

They surprise is: they won't. This will weaken the West.

This is dangerously stupid.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#99
post #51

I wish this hadn't happened. I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do t…

This sort of thing is happening across the federal government. There is no rhyme or reason. DOGE has been given an unrealistic target for cuts and they're desperately cutting whatever they can get their hands on. If you look at the federal budget it's nearly impossible for DOGE to hit their stated goals without touching benefits like medicare and social security (which are off limits so far) so the only option is deep, deep cuts into the narrow slice of the federal budget that excludes those protected categories.

There is no rhyme or reason to what gets cut, other than someone under pressure to hit KPIs (dollars cut) was desperately searching for things that looked easy to cancel.

This is happening everywhere the federal government touches. Most people aren't aware of it until they come around and pull the rug on something that intersects with your own life.

Even my die-hard Republican distant relatives are suddenly shocked because programs they benefited from are being cut. They thought they voted for something different.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#100

Trump stupidity hurts the country and world. But maybe this is an opportunity to do CVE better.

> But maybe this is an opportunity to do CVE better.

Okay, how? This sounds like looking for lemonade in a genocide.

Post reply on HN