Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

141–150 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#141
post #126

Earlier quoted context omitted.

Your words don't make any sense in this environment. The idea that any person at an agency could stand up to or convince the DOGE team of anything is preposterous. Anything that weakens the US or puts our cybersecurity in a place that Russia can exfiltrate data will happen. This is not about the US needing anything and it's silly to think otherwise. See also the NLRB whistleblower and the security backdoors that DOGE…

> Your words don't make any sense in this environment. The idea that any person at an agency could stand up to or convince the DOGE team of anything is preposterous. Your comment embraces and spreads the powerlessness they want you to feel and spread. Of course you can stop them - like any other negotiation in life, especially non-friendly ones, you need to make it in Trump's interest either by carrot or stick. Trump…

DOGE is doing this, it's not a "scapegoat", and Trump is not going to negotiate anything here, that's ridiculous.

What leverage do you have for the DOGE boys? What power? Resigning? Because on the Defense side of the government the best leverage that some teams have found is mass resignation, meaning that nothing happens.

There is no negotiating with bullies, it merely breeds more concessions.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#142

If you work on OSS software on CVE management, then you already know that NVD funding reductions have been ongoing for more than a year. April 2024, https://nvd.nist.gov/general/news/nvd-program-transition-ann... NIST maintains the National Vulnerability Database (NVD).. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing backlog of vulnerabilities.. based on.. an increase in software…

There is nothing in that article mentioning funding reductions. That article is about how the volume of software vulnerabilities are increasing, resulting in difficulty keeping up by the CVE and NVD projects. Please stop spamming this thread with political spin.

Both CVE (MITRE contract) and NVD are funded by NIST, https://www.securitymagazine.com/articles/100795-understandi...

> Since February 2024, the National Institute of Standards and Technology’s (NIST) National Vulnerability Database (NVD) has encountered delays in processing vulnerabilities.. caused by factors such as software proliferation, budget cuts and changes in support.. NIST, an agency within the United States Commerce Department, saw its budget cut by nearly 12% this year.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#143

I don't see why this should be publicly funded, so I don't really see an issue with this. The industry benefits from having a CVE database, so the industry should fund it.

There are going to be all kinds of messed up incentives if this is funded from industry.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#144
post #7

Earlier quoted context omitted.

[flagged]

Thanks for volunteering to manage the "300-600 CVEs each month"! The world needs more volunteers like you.

Make that 3,000-4,000 on average per month, according to NISTs stats on CVEs for last year. ~40,000 for 2024.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#145

I'm trying to steelman but I really can't think of a non- nefarious justification for this

We have a 2tn deficit. If Congress wants to fund this, they need to make it mandatory spending and raise taxes.

Republicans control Congress, this is bait

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#146

I don't see why this should be publicly funded, so I don't really see an issue with this. The industry benefits from having a CVE database, so the industry should fund it.

No, "the industry" is all of us alive in the 21st century who depend on software to make material decisions and to be resilient to attacks and tampering. We were all funding it, and now surely we will see some big tech company now assume responsibility from the federal government (please god don't let it be Oracle...)

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#147
post #52
post #48

Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?

and then a random 9.8 critical comes that affects some software you have in a way that makes it a 0 in your environment but it doesn't matter cause the cve tanks your organizational Security Score (tm) by 10 arbitrary points and management is wondering when you'll secure the company again because the Security Score is their only tangible deliverable to measure success

Most tracking tools have exception processes. But yeah, security as a product family instead of a simple score seems to be a foreign concept at most companies.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#148
post #51

I wish this hadn't happened. I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do t…

No, we’re in a middle of a coup. Palantir or some other odious company will get paid 100x more to do something.

[flagged]

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#149

Earlier quoted context omitted.

I can't believe what a bunch of bollocks this administration is. I couldn't believe it the first time, and this time I thought "Well at least I'm ready, it will be a lot like last time" and it's so much worse

A lot was lost in the midterms and Supreme Court appointments. Hopefully these 4 years energize people to vote. I know protesting and direct action and so on are also important, but the gradient is not negative for voting for every office you can vote for in every election.

Yes, the next elections are all I have to look forward to really.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#150

Earlier quoted context omitted.

Thanks for volunteering to manage the "300-600 CVEs each month"! The world needs more volunteers like you.

You manage the system and not the CVEs themselves. The simplist thing would be a list of numbers that correspond to Google docs. The owner of the Google doc can share it with the needed parties and eventually set it as public.

You truly believe that the CVE database (and others like CWE) are only about assigning serial numbers to random reports, don't you? I see people underestimating and understanding the work of others in matters like this. Is that a trend now?
Post reply on HN