Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

261–270 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#261

This industry relentlessly lionized Trump and Musk, elevating them to positions of power and handing them the power to destroy at will. This is your moment! Enjoy it!

It’s astounding that the users here watched all the horrendous things going on and ignored them. But now the CVE numbers are gone it’s shocking and too far.

Please, this place has permeated with Trump rage since before he took office. The only way you could think he was ignored is to not have read any comments.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#263
post #193

Earlier quoted context omitted.

Would appreciate a pointer to the source, thank you. 2025 article claims 30% increase in 2024 workload, https://www.securityweek.com/mitre-signals-potential-cve-pro... > According to NIST, while the National Vulnerability Database (NVD) is processing incoming CVEs at the same rate as before the slowdown in spring and early summer 2024, a 32 percent jump in submissions last year means that the backlog continues to gro…

Can search these for the links 2023 > CISA had previously been supporting the NIST NVD program with approximately $3.7 million per year in interagency funding, which they have discontinued 2024 > While NIST has since reallocated $8.5 million to NVD for fiscal years 2024 and 2025 Assuming that's spread over both years it wasn't as big of an increase as I said, but is still an increase even inflation adjusted. > 2025 a…

Thanks for the pointer. Is this a lobbying org? https://www.fdd.org/analysis/policy_briefs/2025/03/21/delaye...

> While NIST has since reallocated $8.5 million to NVD for fiscal years 2024 and 2025, this funding remains a fraction of the $300 million to $400 million estimated to be needed annually to fully restore capacity, with an additional $120 million to $150 million required to prevent further system “deterioration.”

Did NVD receive 300MM annual funding pre-2024? That would be a 98% funding cut.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#264

I'm surprised that it was USA's responsibility to fund this in the first place. Why weren't other countries providing funds?

The CVE program was started over 25 years ago. It is very reputable (until yesterday) and it was very much in the interest of the US to be seen as the stewards of this. The funding requirements can't be that high and I'm willing to bet that other countries and entities would have happily stepped up if they had the chance. Up until recently CVE was very centralized and only in the last few years have there been steps…

They have the chance to step up now. Every Comercial company that is supposedly so reliant on this for their very existence has the opportunity today. They can fund it.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#265
post #143

Earlier quoted context omitted.

There are going to be all kinds of messed up incentives if this is funded from industry.

True, although Google's Project Zero seems to be run pretty well.

Different goals, not cve related.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#266
post #51

I wish this hadn't happened. I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do t…

> "kill it, we don't need this"

"We are paying MITRE how much? Bigballs and co will write a better ststem in 1 week and have it integrated with xAI. How hard could it be? Send out a first draft of an xAI contract to our DHS contact"

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#267

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

The EU should just buy MITRE. Move it to the EU and make it a EU based project.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#268

Earlier quoted context omitted.

They are breaking down the federal government intentionally. DOGE was never going to hit their goals, they were impossible to hit. The goals were just cover to take full control over anything they can get their hands on. > Even my die-hard Republican distant relatives are suddenly shocked because programs they benefited from are being cut. They thought they voted for something different. They voted for others to be h…

There is no in-group and out-group, there is only Trump.

A comment has been deported to El Salvador, in its place

Trump in Nevada: 'I Love the Poorly Educated' https://www.youtube.com/watch?v=Vpdt7omPoa0

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#269
post #8
post #7

Earlier quoted context omitted.

[flagged]

Yet so far no volunteer has emerged and people who do run CNA are pretty busy with it.

There were some, short-lived, projects/groups trying to run their own processes. DWF is one that I recall, though it is dead again:

https://lwn.net/Articles/851849/

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#270

Earlier quoted context omitted.

The CVE program was started over 25 years ago. It is very reputable (until yesterday) and it was very much in the interest of the US to be seen as the stewards of this. The funding requirements can't be that high and I'm willing to bet that other countries and entities would have happily stepped up if they had the chance. Up until recently CVE was very centralized and only in the last few years have there been steps…

They have the chance to step up now. Every Comercial company that is supposedly so reliant on this for their very existence has the opportunity today. They can fund it.

I mention this in another comment. The infrastructure for an alternative is already partially in place.

In my opinion it's mostly the industry needing to adapt to a new setup that needs to happen. It was just "easy" to rely on what's already there. A lot of company policies need to be adapted etc.

Post reply on HN