Earlier quoted context omitted.
Listen, I hate the debt, but we have an income problem, not a spending problem. The military looks like a waste, but it does more than build bombs i.e research etc. The issue we have is that republican every chance they get since the 1970s have cut taxes. And then blamed democrats for causing the deficits. We don't need smaller governments. We need a reasonable tax system that taxes people. It can be progressive like…
Military also employs a bunch of people who otherwise would be poor. Also provides a gentrification path for a bunch of previously poor people extending throughout their lives.
CVE program faces swift end after DHS fails to renew contract [updated]
241–250 of 1001 posts
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#242I'm surprised that it was USA's responsibility to fund this in the first place. Why weren't other countries providing funds?
The funding requirements can't be that high and I'm willing to bet that other countries and entities would have happily stepped up if they had the chance.
Up until recently CVE was very centralized and only in the last few years have there been steps in more decentralization with CNAs taking more responsibility, Red Hat as a CNA of last-resort etc. So, the cost of doing all of this work has already been shifted partially (!) away from the US but I have not seen any movement towards e.g. moving the program to a foundation which could have been done.
Personally I would conclude that it was the responsibility of the US to pay for this because they wanted to and it was in their best interest to control this program.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#243I wish this hadn't happened. I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do t…
This sort of thing is happening across the federal government. There is no rhyme or reason. DOGE has been given an unrealistic target for cuts and they're desperately cutting whatever they can get their hands on. If you look at the federal budget it's nearly impossible for DOGE to hit their stated goals without touching benefits like medicare and social security (which are off limits so far) so the only option is dee…
Like what exactly? I mean the guy ran on cutting the budget by 2 trillion. In his last term he gave tax breaks yo the rich. Where did they think the cuts were coming from?
He ran very hard on raising tarrifs. Which demonstrably raise prices (thats literally their goal.) But now people claim "I didn't vote for this."
In truth they voted for him because he was the Republican on offer and they're die-hard Republican. The Republican party has made no secret of its agenda for decades.
I get it, people are good at cognitive dissonance. But this is the place for blunt truth. They voted for this. I'm not letting Republicans got off the hook here. They voted for this.
Just like to my Republican friends who are upset that CVE is cut. You voted for this. The general public benefit from CVE even though they dont know it exists. Just like you benefitted from dozens of other programs you didn't know existed, but have also been cut.
That's the problem with cuts. They ultimately end up hurting everyone.
Now clearly there's some fat that could be trimmed. Companies do it all the time. Done well its good. Swinging a hatchet in a crowded elevator does not seem like "Done well".
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#244Earlier quoted context omitted.
I think you mean wonder kids.
wunderkind is a loanword, it's one of those cases of a German word being used but being odd in English since it's so similar. Like kindergarten which is often speller as "garden". https://en.m.wikipedia.org/wiki/Wunderkind_(disambiguation)
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#245Earlier quoted context omitted.
It's a near certitude that Russia and China each have databases of exploitable software errors and prize zero days. It was to the advantage of the US and allies to coordinate and lead in tracking and fixing such errors. Multiple countries, companies, and individuals contributed finding and fixing bugs. The administrative task of keeping track was one part of a greater picture, a part that came with first to be advise…
> It was to the advantage of the US and allies to coordinate and lead in tracking and fixing such errors. From what I understand of the article, none of these allies were funding it. > Multiple countries, companies, and individuals contributed finding and fixing bugs. Clearly that itself isn't enough. Someone has to pay for maintaining this service. It appears that no one other than USA spent money in funding it.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#246Mr. President, Do you want China to get the reports instead, or do you want the NSA to have a lead time where the vuln's are useful tools?
I was trying to convey (with levity/humor) WHY it should continue to be funded as well as the argument that should be made to the one currently in control of the spineless US Congress.
Yes, fixing the vulnerabilities is important. However what the government probably does gain from it is an inside advantage in the lead time for vulnerabilities to protect against, as well as to exploit on adversaries.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#247This industry relentlessly lionized Trump and Musk, elevating them to positions of power and handing them the power to destroy at will. This is your moment! Enjoy it!
It’s astounding that the users here watched all the horrendous things going on and ignored them. But now the CVE numbers are gone it’s shocking and too far.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#248Re: CVE program faces swift end after DHS fails to renew contract [updated]
#249Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?
and then a random 9.8 critical comes that affects some software you have in a way that makes it a 0 in your environment but it doesn't matter cause the cve tanks your organizational Security Score (tm) by 10 arbitrary points and management is wondering when you'll secure the company again because the Security Score is their only tangible deliverable to measure success
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#250Earlier quoted context omitted.
Military also employs a bunch of people who otherwise would be poor. Also provides a gentrification path for a bunch of previously poor people extending throughout their lives.
Yes, a big part of the size is because the military is a massive and horrendously inefficient jobs, education, housing, and healthcare program.