Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

111–120 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#111
post #75

Earlier quoted context omitted.

Destroy, destroy, destroy. Promise to rebuild but don't. Take it all.

Vampire capitalism. They want civilization to break down so they can offer a solution for profit. The enemies of all people and life on the planet are a tiny group of oligarchs and their supplicants.

Not unlike the manga Berserk

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#112

Earlier quoted context omitted.

I think it’s ignorance and arrogance. The US seems to be on a path to lose technological and science leadership. The current leadership doesn’t seem to understand things that aren’t flashy. I wonder when they’ll dial back on food safety. I am sure RFK knows some vitamins that protect against salmonella

the guy is ultimate small gov. he wants to rip it out by the roots.

I don't think he's considered a small gov conservative. He increased spending last time and has continued so far this term. His tariffs are one of the biggest expansions in gov interference in modern history. They are also attempting to significantly expand executive power beyond even 9/11 terrorism days.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#113
post #51

I wish this hadn't happened. I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do t…

Your words don't make any sense in this environment. The idea that any person at an agency could stand up to or convince the DOGE team of anything is preposterous.

Anything that weakens the US or puts our cybersecurity in a place that Russia can exfiltrate data will happen. This is not about the US needing anything and it's silly to think otherwise. See also the NLRB whistleblower and the security backdoors that DOGE demanded to allow data exfiltration and the subsequent death threats to the whistle blower.

You mindset is behind the times and needs to adjust to a, frankly, insane current reality.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#114
post #43

Earlier quoted context omitted.

What is incorrect about the post above? There are citations from multiple reputable news outlets for each claim. People who actually work with CVEs have been posting about this problem on HN for 18 months.

Your post has now been edited to be factually correct. But the misleading implication that this abrupt cut is part of some other cuts that started before remains.

Anyone that silently edits their posts after being called out for misleading statements or lies is arguing in bad faith.

If you still have a cached copy of their original post you should publicly edit your earliest reply with their original quote.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#117

Earlier quoted context omitted.

The post (currently AND previous to comments being moved here from a different HN thread) links to the official _2024_ (not 2025) statement about NVD cutbacks. Here's a 3000 word article with quotes from Linux Foundation and commercial vendors, around the same time, https://news.ycombinator.com/item?id=43700884

NVD != CVE

NIST owns the budget for both NVD and CVE, contracting MITRE to operate the CVE program.

NIST budget was cut 12% in FY 2024 (Oct 2023 - Sep 2024).

An earlier bill to supplement NIST funding has been reintroduced in 2025, https://fedscoop.com/public-private-partnerships-bill-nist-h...

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#118
Some companies are already clueless when it comes to CVE management. Probably won’t see the effects immediately but give it a few more years for new generation of vulns to be created/found and we will be back to early 2000s level security.

Open season on American corporations for domestic and foreign hackers.

If program isn’t brought back then CVE database likely to be fragmented amongst the “private” CVE databases.

Sec Corp A has 700 well documented CVEs but Sec Corp B has 702 CVEs in their database since NIST funding pulled. What do corps do? Maybe some of them with massive budgets setup contracts with both to get “full spectrum coverage”. Maybe other non-technical companies that think of IT as strictly a cost will go with the cheapest or forego it all together.

Who knows maybe we get ~~~free labor~~~ open source community to pick up the slack?

This country with the orange man administration is quickly going to shit. Not in a “I dislike {opposing party} way” either. In a “I dislike authoritarian regimes” way.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#119
post #13

Earlier quoted context omitted.

Privatize all teh things?

April 2024 article on the result of NVD funding cutbacks, with comments by Linux Foundation OpenSSF, security startups like ChainGuard and commercial vendors, https://www.securityweek.com/cve-and-nvd-a-weak-and-fracture... Threat intelligence firm Flashpoint noted in March 2024 it was aware of 100,000 vulnerabilities with no CVE number and consequently no inclusion in NVD. More worryingly, it said that 330 of these v…

I tried to look over the history and I only see a funding increase, CISA cut $3.7 million at the end of 2023 for the next year and in response NIST reallocated extra funding to NVD: $8.5 million in 2024

A funding shortfall and strain isn't a funding cut. And from what I see there was a funding increase.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#120
post #66

My tinfoil hat says they want to privatize this through one of the administrations friends. A disastrous decision here.

Why would they spend money to replace it? The idea is to weaken and destroy the US and its institutions. Giving Palantir money might mean that security improves, and that goes against their goals. They have already demanded that Russia stop being treated as a cybersecurity threat in other areas of the government, this is a way to ensure that systems are vulnerable to attack.
Post reply on HN