Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

221–230 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#221
post #51

I wish this hadn't happened. I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do t…

If you made this careful analysis, you'd hear "CRISSAKE WE NEED THIS DONT TOUCH IT" for almost everything (and it likely would be right for a significant portion but not everything). That's why the current approach seems to be to axe everything, listen to how much screaming there is, then reinstate only the projects where the screaming is really loud.

So the dumbest way to do anything. Got it.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#223

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

Maybe something to bring up to one of these e.V.'s if it ends up being difficult to get started: Codeberg.org, nlnet.nl, ccc.de

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#224

This industry relentlessly lionized Trump and Musk, elevating them to positions of power and handing them the power to destroy at will. This is your moment! Enjoy it!

It’s astounding that the users here watched all the horrendous things going on and ignored them. But now the CVE numbers are gone it’s shocking and too far.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#225
post #126

Earlier quoted context omitted.

> Your words don't make any sense in this environment. The idea that any person at an agency could stand up to or convince the DOGE team of anything is preposterous. Your comment embraces and spreads the powerlessness they want you to feel and spread. Of course you can stop them - like any other negotiation in life, especially non-friendly ones, you need to make it in Trump's interest either by carrot or stick. Trump…

No, it's definitely DOGE doing all of this. Each one of these young fools need to be named and shamed. The level of damage they have done is unprecedented. They will, in their later years, hopefully look back at this time in their life with a great deal of shame and embarrassment.

I have the feeling that there will be no redemption arc for those ones and the repenting would be for show before a court of public opinion.

I'm going to be to the point here, if you guys over there don't start to heavily push and organise, and I said it already, you're one Reichstag fire away from something very bad, and from my point of view, there is probably one kristallnacht pending in the mix.

This is not a hyperbole and if someone wonders why this has relevance to the discussions, in this case most of the people around here are blue team, and it does feel like the red team has already taken anything that wasn't attached and now taking the time to take what's bolted on...

I guess the silver lining of all this, is in their hubris, they forgot the bread and games motto, so they're might still be a chance to turn things around somewhat... But the window is closing at an impressive speed.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#226

I'm trying to steelman but I really can't think of a non- nefarious justification for this

> I'm trying to steelman Why? This administration is not acting in good faith, you don't have to act as if they are. People and institutions doing that is part of how we got here in the first place.

It is the belief that it is not in good faith that makes it more important that you try to steelman it.

If the steelmanning fails then you can you can be even more confident that it is in bad faith.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#227
CVE was anti-American woke.

No, more seriously, just like with shutting down NOAA services, it seems the goal is to:

1. cut services (we saved taxpayer money!!)

2. at some point later: oh, we actually need those services

3. pay to provide the service (see! we don't need to pay gov employees!!) (fine print: the vendor costs 2-3x the original cost). But by then no one is looking at the spending numbers anymore.

Slick moves.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#228

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

Try to talk to the people from the Sovereign Tech Fund, they have a history of sponsoring security relevant projects in the EU.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#229

I'm surprised that it was USA's responsibility to fund this in the first place. Why weren't other countries providing funds?

It's called providing leadership. Worth the money. China will happily fill the void.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#230

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

Great idea. I'm interested in helping. I'll dm you.
Post reply on HN