CVE program faces swift end after DHS fails to renew contract [updated]
161–170 of 1001 posts
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#162Earlier quoted context omitted.
it might be ignorance; it might be malice. it might also be deliberate: that they actually don't think the government should be involved in this sort of thing. after all, someone could be making a profit on this, and that seems to be their highest value. if gov is involved, that makes it a communal effort, and you know what else starts with "commun-"? yes, those reasons are stupid and ignorant AND intentional. but is…
Hanlon's razor. I also tend to impute malice to things I don't like, but I think it's hard to go past stupidity.
But, having known about it for a dozen years now, I also find it inadequate alone as a razor without the following caveats/corollaries:
Hubbard's corollary to Hanlon's Razor: "Never attribute to malice or stupidity that which can be explained by moderately rational individuals following incentives in a complex system". ( https://en.m.wikipedia.org/wiki/Hanlon's_razor#Exceptions )
Or (HN) Nerdponx's punchier simplification: "When money is at stake, never attribute to incompetence what could be attributed to greed." ( https://news.ycombinator.com/item?id=41066724 )
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#163Reminds me of Trump's first term where he said if we stopped testing for Covid, we'd stop catching new cases and case numbers would go down. If you stop testing for vulnerabilities then vulnerabilities go down. Easy stuff.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#164Earlier quoted context omitted.
You manage the system and not the CVEs themselves. The simplist thing would be a list of numbers that correspond to Google docs. The owner of the Google doc can share it with the needed parties and eventually set it as public.
You truly believe that the CVE database (and others like CWE) are only about assigning serial numbers to random reports, don't you? I see people underestimating and understanding the work of others in matters like this. Is that a trend now?
I think it's a testament to the previous stewardship that it appears so simple.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#165I don't see why this should be publicly funded, so I don't really see an issue with this. The industry benefits from having a CVE database, so the industry should fund it.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#166Earlier quoted context omitted.
Smug, cryptic remarks aren't helpful. If you have a point, say it.
They are breaking down the federal government intentionally. DOGE was never going to hit their goals, they were impossible to hit. The goals were just cover to take full control over anything they can get their hands on. > Even my die-hard Republican distant relatives are suddenly shocked because programs they benefited from are being cut. They thought they voted for something different. They voted for others to be h…
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#167Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?
This is bikeshedding. The point is an authoritative process and an identifier All this does is help Putin and other rich grifters.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#168What are the implications of this? No more centralized store of vulnerability information?
Basically when any software/library/whatever has a vulnerability, they have to communicate that out themselves, in some format. If I'm developing a product built on 20 libraries, it won't just be a matter of scanning CVEs for major vulnerabilities any more, so I'm more likely to miss one. "always update" doesn't always work, when to manage a product you realistically have to version pin.
I would imagine the only SANE option would be some kind of git repository where CNA's can collaborate. Probably run some code across to make the website that people can easily access.
It's going to be a mess.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#169Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?
and then a random 9.8 critical comes that affects some software you have in a way that makes it a 0 in your environment but it doesn't matter cause the cve tanks your organizational Security Score (tm) by 10 arbitrary points and management is wondering when you'll secure the company again because the Security Score is their only tangible deliverable to measure success
Trump must be receiving a lot of emails from companies wanting to fill the void, and I bet the Trumpiest of them all is going to be awarded a contract worth 10x the budget CVE had, and do a much worse job.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#170Earlier quoted context omitted.
it might be ignorance; it might be malice. it might also be deliberate: that they actually don't think the government should be involved in this sort of thing. after all, someone could be making a profit on this, and that seems to be their highest value. if gov is involved, that makes it a communal effort, and you know what else starts with "commun-"? yes, those reasons are stupid and ignorant AND intentional. but is…
Hanlon's razor. I also tend to impute malice to things I don't like, but I think it's hard to go past stupidity.
A large amount of things related to Trump fall into that category, and it's important to recognize when you need to instead treat it as a superposition: It is both malice and incompetence, unless the perpetrators decide to plead just one or the other.