Earlier quoted context omitted.
I can't believe what a bunch of bollocks this administration is. I couldn't believe it the first time, and this time I thought "Well at least I'm ready, it will be a lot like last time" and it's so much worse
A lot was lost in the midterms and Supreme Court appointments. Hopefully these 4 years energize people to vote. I know protesting and direct action and so on are also important, but the gradient is not negative for voting for every office you can vote for in every election.
CVE program faces swift end after DHS fails to renew contract [updated]
201–210 of 1001 posts
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#202Earlier quoted context omitted.
I can't believe what a bunch of bollocks this administration is. I couldn't believe it the first time, and this time I thought "Well at least I'm ready, it will be a lot like last time" and it's so much worse
A lot was lost in the midterms and Supreme Court appointments. Hopefully these 4 years energize people to vote. I know protesting and direct action and so on are also important, but the gradient is not negative for voting for every office you can vote for in every election.
You are assuming there will be next elections that are free, fair, and matter.
Trump says a lot of things that ultimately doesn't matter, but he has also said, and is the type of brute to believe it, that he intends to stay in power. He and his cronies have successfully dismantled the checks and balances that should have prevented him from doing they, legally. IMO the only way he leaves the White House without stirring trouble is in a casket.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#203Earlier quoted context omitted.
What has been ongoing for more than a year? The funding appears to have been cut off today, and both of these comments seem to talk about continuing work and how important it is. Do you mean to say that some form of threat to the NVD has been around for over a year now? Just want to be sure I'm parsing correctly!
Yes, NVD funding cuts and a growing CVE backlog began in late 2023. May 2024, https://therecord.media/nist-database-backlog-growing-vulnch... > Moving forward, cybersecurity companies will have to “fill the void” .. NVD said in April [2024] that it is “working to establish a consortium to address challenges in the NVD program and develop improved tools and methods.” .. CISA acknowledged the concerns and outrage of th…
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#204I wish this hadn't happened. I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do t…
This sort of thing is happening across the federal government. There is no rhyme or reason. DOGE has been given an unrealistic target for cuts and they're desperately cutting whatever they can get their hands on. If you look at the federal budget it's nearly impossible for DOGE to hit their stated goals without touching benefits like medicare and social security (which are off limits so far) so the only option is dee…
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#205What the fuck are you supposed to do about this. This is something that should have had multiple MONTHS of warning in order to allow those who depend on the CVE infrastructure to plan what to do next with their security posture.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#206I wish this hadn't happened. I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do t…
it might be ignorance; it might be malice. it might also be deliberate: that they actually don't think the government should be involved in this sort of thing. after all, someone could be making a profit on this, and that seems to be their highest value. if gov is involved, that makes it a communal effort, and you know what else starts with "commun-"? yes, those reasons are stupid and ignorant AND intentional. but is…
Yes, there are apparently various ways of profiting from vulnerabilities. The interesting question would be whether any of the regime insiders have a way to profit.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#207Earlier quoted context omitted.
So much for the wunderkinds in DOGE.
I think you mean wonder kids.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#208I'm trying to steelman but I really can't think of a non- nefarious justification for this
> I'm trying to steelman Why? This administration is not acting in good faith, you don't have to act as if they are. People and institutions doing that is part of how we got here in the first place.
> Why?
It's a sensible practice and good practice
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#209Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar.
Already did a backup of the NVD in the last couple hours, currently backing up the security trackers and OVAL feeds.
Gonna need some sleep now, it's morning again.
My project criteria:
- hosting within the EU
- must have a copyleft license (AGPL)
- must have open source backend and frontend
- dataset size is around 90-148 GB (compressed vs uncompressed)
- ideally an e.V. for managing funds and costs, so it can survive me
- already built my vulnerability scraper in Go, would contribute it under AGPL
- already built all schema parsers, would contribute them also under AGPL
- backend and frontend needs to be built
- would make it prerendered, so that cves can be static HTML files that can be hosted on a CDN
- needs submission/PoC/advisory web forms and database/workflow for it
- data is accumulated into a JSON format (sources are mixed non standard formats for each security tracker. Enterprise distros use odata or oval for the most parts)
If you are interested, write me on linkedin.com/in/cookiengineer or here.