Earlier quoted context omitted.
> I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? This was not a carefully-weighed decision based on a cost-benefit analysis. This was a political order, consistent with the administration's policy of "cut everything, recklessly, indiscriminately."
Destroy, destroy, destroy. Promise to rebuild but don't. Take it all.
CVE program faces swift end after DHS fails to renew contract [updated]
91–100 of 1001 posts
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#92If you work on OSS software on CVE management, then you already know that NVD funding reductions have been ongoing for more than a year. April 2024, https://nvd.nist.gov/general/news/nvd-program-transition-ann... NIST maintains the National Vulnerability Database (NVD).. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing backlog of vulnerabilities.. based on.. an increase in software…
There is nothing in that article mentioning funding reductions. That article is about how the volume of software vulnerabilities are increasing, resulting in difficulty keeping up by the CVE and NVD projects. Please stop spamming this thread with political spin.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#93Earlier quoted context omitted.
Your post has now been edited to be factually correct. But the misleading implication that this abrupt cut is part of some other cuts that started before remains.
The post (currently AND previous to comments being moved here from a different HN thread) links to the official _2024_ (not 2025) statement about NVD cutbacks. Here's a 3000 word article with quotes from Linux Foundation and commercial vendors, around the same time, https://news.ycombinator.com/item?id=43700884
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#94If you work on OSS software on CVE management, then you already know that NVD funding reductions have been ongoing for more than a year. April 2024, https://nvd.nist.gov/general/news/nvd-program-transition-ann... NIST maintains the National Vulnerability Database (NVD).. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing backlog of vulnerabilities.. based on.. an increase in software…
There is nothing in that article mentioning funding reductions. That article is about how the volume of software vulnerabilities are increasing, resulting in difficulty keeping up by the CVE and NVD projects. Please stop spamming this thread with political spin.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#95Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?
All this does is help Putin and other rich grifters.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#96What are the implications of this? No more centralized store of vulnerability information?
Basically when any software/library/whatever has a vulnerability, they have to communicate that out themselves, in some format. If I'm developing a product built on 20 libraries, it won't just be a matter of scanning CVEs for major vulnerabilities any more, so I'm more likely to miss one. "always update" doesn't always work, when to manage a product you realistically have to version pin.
This is dangerously stupid.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#97Re: CVE program faces swift end after DHS fails to renew contract [updated]
#98These four years are going to be the death of all of us.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#99I wish this hadn't happened. I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do t…
There is no rhyme or reason to what gets cut, other than someone under pressure to hit KPIs (dollars cut) was desperately searching for things that looked easy to cancel.
This is happening everywhere the federal government touches. Most people aren't aware of it until they come around and pull the rug on something that intersects with your own life.
Even my die-hard Republican distant relatives are suddenly shocked because programs they benefited from are being cut. They thought they voted for something different.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#100Trump stupidity hurts the country and world. But maybe this is an opportunity to do CVE better.
Okay, how? This sounds like looking for lemonade in a genocide.