Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

151–160 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#151
post #80

Earlier quoted context omitted.

it might be ignorance; it might be malice. it might also be deliberate: that they actually don't think the government should be involved in this sort of thing. after all, someone could be making a profit on this, and that seems to be their highest value. if gov is involved, that makes it a communal effort, and you know what else starts with "commun-"? yes, those reasons are stupid and ignorant AND intentional. but is…

Hanlon's razor. I also tend to impute malice to things I don't like, but I think it's hard to go past stupidity.

Sufficiently advanced stupidity is indistinguishable from malice.

(Leaving aside that there's plenty of evidence of malice here.)

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#153
post #126

Earlier quoted context omitted.

> Your words don't make any sense in this environment. The idea that any person at an agency could stand up to or convince the DOGE team of anything is preposterous. Your comment embraces and spreads the powerlessness they want you to feel and spread. Of course you can stop them - like any other negotiation in life, especially non-friendly ones, you need to make it in Trump's interest either by carrot or stick. Trump…

DOGE is doing this, it's not a "scapegoat", and Trump is not going to negotiate anything here, that's ridiculous. What leverage do you have for the DOGE boys? What power? Resigning? Because on the Defense side of the government the best leverage that some teams have found is mass resignation, meaning that nothing happens. There is no negotiating with bullies, it merely breeds more concessions.

> DOGE is doing this, it's not a "scapegoat", and Trump is not going to negotiate anything here, that's ridiculous.

DOGE follows Trump's direction and acts on his behalf, as you must know. They make a big deal out of DOGE so Trump's name is less attached to these actions. Then they can take much of the blame with them when they go away, with Trump and the GOP blaming them for 'excesses'.

> Trump is not going to negotiate anything here, that's ridiculous.

> What leverage do you have for the DOGE boys?

You don't understand how negotiations work. Everyone has interests, strengths and weaknesses, and power. You need to make it in Trump's interest to keep the CVE program.

Everyone saying they are helpless, and that anything else is ridiculous, are panicking. Very unfortunately - dangerously - many people legitimize the panic. It's so normalized that it's "ridiculous" not to panic.

Every day you continue this behavior, you fall further and further behind and lead others in that direction. Will you wake up in time?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#154
post #130
post #48

Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?

> Weren't there major problems with the current CVE implementation Absolutely. And if the headline was "DHS proposes improvements and streamlining to the CVE program" we'd all probably be cheering. Leaping from "This is Flawed" to "Let's kill This" is a logical fallacy. A flawed security registry is clearly better than no security registry.

There are a lot of logical fallacies. Have you heard of the sunk-cost one? Or fallacy fallacy maybe? Or ten-tendril eschatomon fallacy?

In honesty to say "logical fallacy" is spoddy, I advise against for aesthetic reason.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#156
post #48

Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?

This will get lost in the noise, but i think you mean cvss.

CVE is simply identification of a flaw, not a scoring system.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#157
post #67

Earlier quoted context omitted.

We have a 2tn deficit. If Congress wants to fund this, they need to make it mandatory spending and raise taxes.

This is an absolute pittance compared to the total budget. And considering the current administration wants a $4T tax cut they are not interested in trimming the deficit at all.

Yep, DOGE is a song and dance distraction. If they were serious about lowering the deficit they wouldn't have laid off ~12K IRS workers (whom show a 7x ROI per head.) They also wouldn't be asking to increase the military budget to $1 trillion per year. Trump has spent 1/3 of his days in office so far golfing; $30 million+ so far paid to Trump properties for the privilege of that. This is the biggest capture in US history and it's all out in the open.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#158
post #143

I don't see why this should be publicly funded, so I don't really see an issue with this. The industry benefits from having a CVE database, so the industry should fund it.

There are going to be all kinds of messed up incentives if this is funded from industry.

True, although Google's Project Zero seems to be run pretty well.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#159
post #150

Earlier quoted context omitted.

You manage the system and not the CVEs themselves. The simplist thing would be a list of numbers that correspond to Google docs. The owner of the Google doc can share it with the needed parties and eventually set it as public.

You truly believe that the CVE database (and others like CWE) are only about assigning serial numbers to random reports, don't you? I see people underestimating and understanding the work of others in matters like this. Is that a trend now?

No I don't believe that, but it might as well operate like that. The extra stuff isn't truly needed and was being outsourced to the companies that own the products since it wasn't providing much value. Take a look at Daniel's blog posts about CVEs for curl for what happens when you let them handle it.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#160

Now the NSA can hoard more 0days and the general public suffers. Win win for this administration

It's more likely to boost the zero day black market. I don't know if I want to attribute this to idiocy (indiscriminate cost cutting), greed (contracts for their crony pals) or malice (hoarding and trading 0 days).
Post reply on HN