Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

231–240 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#232

Earlier quoted context omitted.

War with China and doing enough reprehensible acts to stoke protests to declare martial law to stay in power indefinitely.

I feel like we're only a few weeks away from someone "home grown" experiencing an "administrative error." The slide into madness continues.

More like only a few days away, honestly.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#233
There are quite a few threads on hackernews that were cautiously optimistic about doge with, frankly, pretty naive libertarian takes about how the government works.

The government is not particular (in the sense of particularism) and cannot be easily tuned to fix particular problems; rather, its best solutions come through institutional procedure and design, such as the tension between the FAA and the NTSB that, at a first glance, would seem like obviously needless duplication and waste.

It is a broad, blunt, wasteful instrument to solve broad, blunt problems in a way that may not be the best but that work far, far better than alternatives that have been tried.

That the effort to treat government like a personal budget has ended up destroying important things is a sad inevitability of such efforts. I hope it goes remembered.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#234
post #199

Earlier quoted context omitted.

Yes, the next elections are all I have to look forward to really.

Given the current government has blown off an unanimous 9-0 supreme court decision, right now I can't feel too optimistic there will even be more elections.

I think there will be more elections, but I think they will be fraudulent, because I think Trump has shown he is adept at turning things around and then trying to pretend that what he's doing is analogous to what the other side has done.

For example, a lot of people have forgotten, but the phrase "fake news" originally came about in the wake of the 2016 election about all the (actually false) misinformation that was spread on social media in the run up to the election. Trump adeptly then co-opted the term, so any news he didn't like he could just call it "fake news", and who was to say any news he called fake was any less fake than what people were calling fake before?

My guess is the 2028 elections will be marked by fraud, and then when people protest or object, Trump and the Republicans will just say "Hey, you called all those Jan 6 protesters traitors and said the election was secure, how is now any different? Now you're all the traitors."

The only belief that gives me hope these days is "History will judge the complicit."

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#235

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

Try to talk to the people from the Sovereign Tech Fund, they have a history of sponsoring security relevant projects in the EU.

And maybe the sidn fund?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#236
post #160

Now the NSA can hoard more 0days and the general public suffers. Win win for this administration

It's more likely to boost the zero day black market. I don't know if I want to attribute this to idiocy (indiscriminate cost cutting), greed (contracts for their crony pals) or malice (hoarding and trading 0 days).

¿Por qué no los tres?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#237

Earlier quoted context omitted.

No, it's definitely DOGE doing all of this. Each one of these young fools need to be named and shamed. The level of damage they have done is unprecedented. They will, in their later years, hopefully look back at this time in their life with a great deal of shame and embarrassment.

I have the feeling that there will be no redemption arc for those ones and the repenting would be for show before a court of public opinion. I'm going to be to the point here, if you guys over there don't start to heavily push and organise, and I said it already, you're one Reichstag fire away from something very bad, and from my point of view, there is probably one kristallnacht pending in the mix. This is not a hyp…

I'm an Australian. We have a guy called Clive Palmer, who has formed a party called (no joke) the "Trumpet of Patriots". It's certain nobody will vote for him. The opposition leader married himself to MAGA (and close to Trump) and now it appears like this will prevent him from winning.

The rest of the world is mostly against Trump.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#239
post #52

Earlier quoted context omitted.

and then a random 9.8 critical comes that affects some software you have in a way that makes it a 0 in your environment but it doesn't matter cause the cve tanks your organizational Security Score (tm) by 10 arbitrary points and management is wondering when you'll secure the company again because the Security Score is their only tangible deliverable to measure success

It’s Way Better than what we had before: software vendors making even arbitrarier decisions about how to classify them. There are far too many bad actors for us to operate as an industry with no yardstick.

I disagree that it is Way Better than before. A judgement call is worth more than a team wasting effort chasing irrelevant pseudo-vulnerabilities being reported as vulnerabilities. A broken yardstick is worse than no yardstick.
Post reply on HN