Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

271–280 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#271

Earlier quoted context omitted.

The CVE program was started over 25 years ago. It is very reputable (until yesterday) and it was very much in the interest of the US to be seen as the stewards of this. The funding requirements can't be that high and I'm willing to bet that other countries and entities would have happily stepped up if they had the chance. Up until recently CVE was very centralized and only in the last few years have there been steps…

They have the chance to step up now. Every Comercial company that is supposedly so reliant on this for their very existence has the opportunity today. They can fund it.

What commercial company is going to "fund" this? It's such a strange idea, disconnected from the real world. You may as well say "companies can start doing road maintenance, as they are so reliant on them for their very existence."

And perhaps if there had been more than a days notice, some consortium could be pulled together, but who's going to pay? Why would private companies do this, how do they profit? CVE program was the roads that everybody could drive on.

The basic lack of understanding of how the world works is killing the US. Why do people think we have such a massive GDP? Where do people think that comes from? We've given control of everything in society over to our dumbest and greediest members that have no clue about how anything works.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#272
post #203

Earlier quoted context omitted.

Yes, NVD funding cuts and a growing CVE backlog began in late 2023. May 2024, https://therecord.media/nist-database-backlog-growing-vulnch... > Moving forward, cybersecurity companies will have to “fill the void” .. NVD said in April [2024] that it is “working to establish a consortium to address challenges in the NVD program and develop improved tools and methods.” .. CISA acknowledged the concerns and outrage of th…

That says nothing about a funding cut, see my comment below

Following your comment's reference leads to a claim of NVD needing 300 to 550 million (?!) per year, but only receiving 4 million in funding. If anyone has pre-2024 data on NVD or MITRE CVE funding, that would be helpful, https://news.ycombinator.com/item?id=43701532

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#273

Earlier quoted context omitted.

It's a near certitude that Russia and China each have databases of exploitable software errors and prize zero days. It was to the advantage of the US and allies to coordinate and lead in tracking and fixing such errors. Multiple countries, companies, and individuals contributed finding and fixing bugs. The administrative task of keeping track was one part of a greater picture, a part that came with first to be advise…

> It was to the advantage of the US and allies to coordinate and lead in tracking and fixing such errors. From what I understand of the article, none of these allies were funding it. > Multiple countries, companies, and individuals contributed finding and fixing bugs. Clearly that itself isn't enough. Someone has to pay for maintaining this service. It appears that no one other than USA spent money in funding it.

Why would other companies pay for it if they had never been asked?

Why would it be shut down without asking for others to fund it, if it's some sort of burden on the US?

Programs like this pay for themselves many times over. There are only two reasons for cutting this: absolute idiocy, or active sabotage of the US.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#274

Earlier quoted context omitted.

I did find this post to be non-helpful and confusing. It would be helpful to edit it (or write differently in the future) to clarify that the sudden defunding event occurring today is separate and not related to the previous funding cuts. If that's the case.

Is there no connection between 2025 funding cuts and previous ones? e.g. If a year of work after the previous cuts resulted in an open-data collaboration between NVD and commercial vendors to share a subset of CC0 vulnerability metadata, could that industry collective now argue for government to share (with companies) the burden of funding an open, decentralized program for CVE tracking? Commercial vendors could stil…

I am now more confused and not less.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#275
post #125

> In a stunning development Who is still stunned by these things? They want you to be stunned; they want you to tell everyone else that you're stunned to spread feelings of terror and powerlessness. If you actually are stunned, you are stunningly ignorant. If you are not and still saying it, perhaps to emphasize your unhappiness, you are a 'useful idiot'. Either way, if you are saying it, you are a useful idiot. You…

Project 2025 literally calls for dismantling the DHS. Seems pretty unsurprising that the CVE database wouldn’t be in the list of things they’d care to maintain in that process.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#276
post #214

Earlier quoted context omitted.

Both CVE (MITRE contract) and NVD are funded by NIST, https://www.securitymagazine.com/articles/100795-understandi... > Since February 2024, the National Institute of Standards and Technology’s (NIST) National Vulnerability Database (NVD) has encountered delays in processing vulnerabilities.. caused by factors such as software proliferation, budget cuts and changes in support.. NIST, an agency within the United State…

Reading that article closely it says nothing about an NVD budget cut, only a NIST one. They were trackijg the changes after NIST's budget was cut, not NVD's. As pointed out below, CISA announced a cut and then NIST more than made up for it by reallocating funds, for an NVD funding increase, even though NIST had their overall budget cut.

One of your references has budget numbers that are two orders (?!) of magnitude higher than the CISA number. Hopefully someone can chime in with granular historical data for NIST NVD and MITRE-via-NIST CVE funding.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#277

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

Im also interested in helping

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#278

Earlier quoted context omitted.

They have the chance to step up now. Every Comercial company that is supposedly so reliant on this for their very existence has the opportunity today. They can fund it.

What commercial company is going to "fund" this? It's such a strange idea, disconnected from the real world. You may as well say "companies can start doing road maintenance, as they are so reliant on them for their very existence." And perhaps if there had been more than a days notice, some consortium could be pulled together, but who's going to pay? Why would private companies do this, how do they profit? CVE progra…

Ask the person I was responding to:

> I'm willing to bet that other countries and entities would have happily stepped up if they had the chance.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#279

Earlier quoted context omitted.

> It was to the advantage of the US and allies to coordinate and lead in tracking and fixing such errors. From what I understand of the article, none of these allies were funding it. > Multiple countries, companies, and individuals contributed finding and fixing bugs. Clearly that itself isn't enough. Someone has to pay for maintaining this service. It appears that no one other than USA spent money in funding it.

[flagged]

Funnily this was on the front page recently: https://seths.blog/2025/04/how-to-win-an-argument-with-a-tod...

Don't bother; they're a brand new user trying to cause trouble

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#280

Earlier quoted context omitted.

Is there no connection between 2025 funding cuts and previous ones? e.g. If a year of work after the previous cuts resulted in an open-data collaboration between NVD and commercial vendors to share a subset of CC0 vulnerability metadata, could that industry collective now argue for government to share (with companies) the burden of funding an open, decentralized program for CVE tracking? Commercial vendors could stil…

I am now more confused and not less.

Do you have any visibility into pre-2024 funding for the NIST NVD and MITRE CVE programs?

MITRE CVE/CWE contract, $29M for 2024-2025, https://www.usaspending.gov/award/CONT_AWD_70RCSJ24FR0000018...

Post reply on HN