Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

161–170 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#162
post #80

Earlier quoted context omitted.

it might be ignorance; it might be malice. it might also be deliberate: that they actually don't think the government should be involved in this sort of thing. after all, someone could be making a profit on this, and that seems to be their highest value. if gov is involved, that makes it a communal effort, and you know what else starts with "commun-"? yes, those reasons are stupid and ignorant AND intentional. but is…

Hanlon's razor. I also tend to impute malice to things I don't like, but I think it's hard to go past stupidity.

I love Hanlon's razor. Super-helpful in certain contexts: "Never attribute to malice that which is adequately explained by stupidity."

But, having known about it for a dozen years now, I also find it inadequate alone as a razor without the following caveats/corollaries:

Hubbard's corollary to Hanlon's Razor: "Never attribute to malice or stupidity that which can be explained by moderately rational individuals following incentives in a complex system". ( https://en.m.wikipedia.org/wiki/Hanlon's_razor#Exceptions )

Or (HN) Nerdponx's punchier simplification: "When money is at stake, never attribute to incompetence what could be attributed to greed." ( https://news.ycombinator.com/item?id=41066724 )

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#163

Reminds me of Trump's first term where he said if we stopped testing for Covid, we'd stop catching new cases and case numbers would go down. If you stop testing for vulnerabilities then vulnerabilities go down. Easy stuff.

That's exactly what they're saying about the HHS cuts and the measles outbreak.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#164
post #150

Earlier quoted context omitted.

You manage the system and not the CVEs themselves. The simplist thing would be a list of numbers that correspond to Google docs. The owner of the Google doc can share it with the needed parties and eventually set it as public.

You truly believe that the CVE database (and others like CWE) are only about assigning serial numbers to random reports, don't you? I see people underestimating and understanding the work of others in matters like this. Is that a trend now?

I saw this same behavior quite a while back. While I'm out of the CVE game these days, it seems that there is a forever rotating new group of people who simply don't and can never see the complexities on the process.

I think it's a testament to the previous stewardship that it appears so simple.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#165

I don't see why this should be publicly funded, so I don't really see an issue with this. The industry benefits from having a CVE database, so the industry should fund it.

Because secure systems benefit the public generally, not just the corporations that make a profit operating those systems.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#166

Earlier quoted context omitted.

Smug, cryptic remarks aren't helpful. If you have a point, say it.

They are breaking down the federal government intentionally. DOGE was never going to hit their goals, they were impossible to hit. The goals were just cover to take full control over anything they can get their hands on. > Even my die-hard Republican distant relatives are suddenly shocked because programs they benefited from are being cut. They thought they voted for something different. They voted for others to be h…

[flagged]

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#167
post #48

Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?

This is bikeshedding. The point is an authoritative process and an identifier All this does is help Putin and other rich grifters.

you like to say word 'bikeshedding', adoption of formal intellectualish sounding terminology even when inappropriate is orange-site affliction I advise against. I am saying this for your own sake... speak truths with POWER

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#168

What are the implications of this? No more centralized store of vulnerability information?

Basically when any software/library/whatever has a vulnerability, they have to communicate that out themselves, in some format. If I'm developing a product built on 20 libraries, it won't just be a matter of scanning CVEs for major vulnerabilities any more, so I'm more likely to miss one. "always update" doesn't always work, when to manage a product you realistically have to version pin.

So, while arguably true, there wont be a single source of truth of new cve's. It doesn't however mean there wont be.

I would imagine the only SANE option would be some kind of git repository where CNA's can collaborate. Probably run some code across to make the website that people can easily access.

It's going to be a mess.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#169
post #52
post #48

Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?

and then a random 9.8 critical comes that affects some software you have in a way that makes it a 0 in your environment but it doesn't matter cause the cve tanks your organizational Security Score (tm) by 10 arbitrary points and management is wondering when you'll secure the company again because the Security Score is their only tangible deliverable to measure success

Don’t let the perfect be the enemy of good. It is(was?) a very useful and important system.

Trump must be receiving a lot of emails from companies wanting to fill the void, and I bet the Trumpiest of them all is going to be awarded a contract worth 10x the budget CVE had, and do a much worse job.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#170
post #80

Earlier quoted context omitted.

it might be ignorance; it might be malice. it might also be deliberate: that they actually don't think the government should be involved in this sort of thing. after all, someone could be making a profit on this, and that seems to be their highest value. if gov is involved, that makes it a communal effort, and you know what else starts with "commun-"? yes, those reasons are stupid and ignorant AND intentional. but is…

Hanlon's razor. I also tend to impute malice to things I don't like, but I think it's hard to go past stupidity.

Hanlon's Razor is susceptible to pathological inputs, causing unbounded runtime.

A large amount of things related to Trump fall into that category, and it's important to recognize when you need to instead treat it as a superposition: It is both malice and incompetence, unless the perpetrators decide to plead just one or the other.

Post reply on HN