Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

281–290 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#281

Earlier quoted context omitted.

Vampire capitalism. They want civilization to break down so they can offer a solution for profit. The enemies of all people and life on the planet are a tiny group of oligarchs and their supplicants.

This isn't capitalism, any more than arson, burglary, or extortion is capitalism. Get some new material.

I agree, given the right definition of “capitalism”.

Unfortunately “capitalism” has two quite different meanings. Which are rarely clarified in use.

Capitalism with a big C, a too common overarching ideology, gets bent to mean whatever the greedy, unethical and rich want it to mean so they can get more money.

But small c capitalism, evolving from both practical and ethical foundations, is a system so useful it has multiplied the benefits of civilization. But it is just one such system.

It can’t do everything, it needs other independent systems (justice, dispute resolution, rules of clarity, risk & trust limiting systems, for starters) to work, and extending it to places it doesn’t work causes great harm.

(Like when perversely applied to those enabling systems, in big C form, as is happening now.)

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#283
post #143

I don't see why this should be publicly funded, so I don't really see an issue with this. The industry benefits from having a CVE database, so the industry should fund it.

There are going to be all kinds of messed up incentives if this is funded from industry.

Like what?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#284

CVE was anti-American woke. No, more seriously, just like with shutting down NOAA services, it seems the goal is to: 1. cut services (we saved taxpayer money!!) 2. at some point later: oh, we actually need those services 3. pay to provide the service (see! we don't need to pay gov employees!!) (fine print: the vendor costs 2-3x the original cost). But by then no one is looking at the spending numbers anymore. Slick m…

And here lies the problem. Even from a libertarian perspective DOGE is counterproductive because maintaining a system is much more cost effective than starting it anew.

Especially when you cut something recklessly, figure out in month that you need back that capability right now and have very little leverage to negotiate with private providers.

When you look at the last cutting effort in the Clinton administration the difference in jarring.

Combine that with the fact that with a few exceptions DOGE has been cutting the most cost effective programs (i can’t think of a better bang for buck science program than NOAA) it’s saved very little vs the amount of pain it has caused.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#285

Earlier quoted context omitted.

[flagged]

Funnily this was on the front page recently: https://seths.blog/2025/04/how-to-win-an-argument-with-a-tod... Don't bother; they're a brand new user trying to cause trouble

In public spaces like this, though on the face of it the argument might appear to be with the toddler, it's also about batting down the idiocy and not letting it swamp out basic common sense and reason.

Bluesky has a different tact that also works: block and hide and don't engage. However in forums like HN, where earnestness and questions are so prevalent, leaving these baiting questions and statements unanswered instead leaves them as bastions of the mind rot. Because these toddler-level arguments are being repeated daily through propaganda channels all over the internet, and if they are never answered, the constant swarm of propaganda takes in even more people.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#286
post #51

I wish this hadn't happened. I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do t…

This sort of thing is happening across the federal government. There is no rhyme or reason. DOGE has been given an unrealistic target for cuts and they're desperately cutting whatever they can get their hands on. If you look at the federal budget it's nearly impossible for DOGE to hit their stated goals without touching benefits like medicare and social security (which are off limits so far) so the only option is dee…

Remember, DOGE has nothing to do with money or "efficiency". It's a pure ideological dismantling of the Federal government aimed at eliminating oversight, regulations, assistance and entitlements as envisioned by ultra-conservatives for decades.

This isn't speculation or hyperbole, it's specifically laid out in their published plans: By hobbling or outright eliminating federal agencies responsible for executing the laws passed by Congress, the administration can circumvent the democratic process and impose their extreme vision of limited government on the country, regardless of popular support.

The U.S. system of government relies on established norms as much as it does law. Conservatives realized that they can ignore precedent with impunity if they had an executive willing to do so. They then spelled out exactly how, and are now enacting that plan.

Then SCOTUS's decisions last summer turbo boosted their agenda. The ruling that only Congress can hold the President legally accountable essentially means executive power is unchecked if the legislature is unwilling or unable to Impeach and convict. The President can now confidently ignore the law and judicial orders with a veneer of legality. And this is what he's doing.

(The fact that all this just so happens to benefit Russia after their decade long campaign to destabilize their opponents in the West is a topic for speculation.)

DOGE is about permanently altering how our country works modeled on the right wing worldview, plain and simple. Since that's their overall goal, they're not concerned where they swing the wrecking ball - it's all going to get destroyed eventually.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#287

I'm surprised that it was USA's responsibility to fund this in the first place. Why weren't other countries providing funds?

Because USA was a superpower that can afford it easily. Taking the leadership in everything is quite cheap price to pay when the other end of the bargain is everyone else has to follow you.

Now of course USA is ceasing (voluntarily, by stripping down every international soft power effector in government) to be a superpower, to the great glee of dictators all around the world.

The "we can't afford being great" is a direct admission that USA is no longer a superpower. And is not going to become great again, just another nation again (at whims of China).

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#288
post #223

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

Maybe something to bring up to one of these e.V.'s if it ends up being difficult to get started: Codeberg.org, nlnet.nl, ccc.de

+1 for ccc.de

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#289

Am I missing something or was this literally announced with less than 24 hours of warning that one of the critical components to the cyber security landscape was disappearing. What the fuck are you supposed to do about this. This is something that should have had multiple MONTHS of warning in order to allow those who depend on the CVE infrastructure to plan what to do next with their security posture.

Consider this part of the attack on the American infrastructure, economy, and society. Attacks do not abide by laws, official procedures, or come with warnings.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#290
post #51

I wish this hadn't happened. I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do t…

They were at the mercy of 20 year olds from doge. I wonder when doge enters the NSA & NRO WHAT information will they steal & put in their hard drives.

All of this is criminal behavior on the the current regime.

Post reply on HN