Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

171–180 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#172

Earlier quoted context omitted.

They are breaking down the federal government intentionally. DOGE was never going to hit their goals, they were impossible to hit. The goals were just cover to take full control over anything they can get their hands on. > Even my die-hard Republican distant relatives are suddenly shocked because programs they benefited from are being cut. They thought they voted for something different. They voted for others to be h…

[flagged]

> DOGE has been about fighting corruption and reducing wasteful spending

It absolutely staggers me that anyone can still say this with a straight face. I will ask this, though: as part of the DOGE fight against corruption and wasteful spending how many of Elon Musk's government contracts and subsidies have been cut?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#174
post #51

I wish this hadn't happened. I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do t…

No, we’re in a middle of a coup. Palantir or some other odious company will get paid 100x more to do something.

MITRE has a trademark on the term CVE.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#175

Earlier quoted context omitted.

I can't believe what a bunch of bollocks this administration is. I couldn't believe it the first time, and this time I thought "Well at least I'm ready, it will be a lot like last time" and it's so much worse

A lot was lost in the midterms and Supreme Court appointments. Hopefully these 4 years energize people to vote. I know protesting and direct action and so on are also important, but the gradient is not negative for voting for every office you can vote for in every election.

[flagged]

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#176

I'm surprised that it was USA's responsibility to fund this in the first place. Why weren't other countries providing funds?

It's a near certitude that Russia and China each have databases of exploitable software errors and prize zero days.

It was to the advantage of the US and allies to coordinate and lead in tracking and fixing such errors.

Multiple countries, companies, and individuals contributed finding and fixing bugs.

The administrative task of keeping track was one part of a greater picture, a part that came with first to be advised and other perks.

It's not that the US had a responsibility to take on the lead admin task, more that in past times the US saw an advantage to being at the centre of global action.

This is just another part of increasing US isolationism.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#177
post #52
post #48

Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?

and then a random 9.8 critical comes that affects some software you have in a way that makes it a 0 in your environment but it doesn't matter cause the cve tanks your organizational Security Score (tm) by 10 arbitrary points and management is wondering when you'll secure the company again because the Security Score is their only tangible deliverable to measure success

It’s Way Better than what we had before: software vendors making even arbitrarier decisions about how to classify them.

There are far too many bad actors for us to operate as an industry with no yardstick.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#178
post #75

Earlier quoted context omitted.

Destroy, destroy, destroy. Promise to rebuild but don't. Take it all.

Vampire capitalism. They want civilization to break down so they can offer a solution for profit. The enemies of all people and life on the planet are a tiny group of oligarchs and their supplicants.

This isn't capitalism, any more than arson, burglary, or extortion is capitalism. Get some new material.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#179

Earlier quoted context omitted.

So much for the wunderkinds in DOGE.

Given that the Kids at DOGE are all computer experts, this reeks of a calculated move.

I think expert is not the right word for what looks like mostly rookies.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#180
post #79

Earlier quoted context omitted.

Yeah like when we bundled in a .js library for client side date processing that has a CVE affecting node.js servers with high score. Our auditors don’t care they tag the whole app as high risk. It doesn’t even run on the server!

the auditors that sign off on your security to meet your clients requirements usually know way less about your security posture than your clients do its all just surface-level box-checking. most companies required to get 'penetration tests' just get an overpriced Nessus scan sold as a pentest and that meets their reqs.

while this is true it in no way diminishes the value that orgs like cve provide
Post reply on HN