To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.
CVE program faces swift end after DHS fails to renew contract [updated]
301–310 of 1001 posts
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#302If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#303Earlier quoted context omitted.
It's a legitimate term. It's like criticizing use of the word startup or demanding someone put a dash in frontend or backend .
term is real... but is more like criticizing misuse of word startup. to be even more accurate it is what I said and not anything else
It's because it's like if someone had forgotten to validate the user's role in an endpoint in a Django app, and someone said that they should have used Rails because it's easier to understand. In reality both are easy enough to understand to be able to do an authorization check, and the framework isn't the issue. So the person suggesting Rails is bikeshedding.
Likewise, if someone made another vulnerability database it would likely have the same issue, and this isn't really the place to solve it. If somehow this does trigger the realization to solve it, then it will be by luck.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#304Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?
The scores were never going to be that accurate across people's environments (IDK how much other places relied on them, places I worked never did that much) and issues with the scores don't seem to be a good justification to torch the whole CVE system anyway.
What a shame on this current gov. administration, if you can even call it that.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#305Earlier quoted context omitted.
I still find it wild that so many people are trying to frame these decisions through a political lens. This is the actions of a foreign bad actor dismantling critical institutions from within, not "bad policy". Surely there's an antibody response.
> I still find it wild that so many people are trying to frame these decisions through a political lens. Why? The decisions are pretty well politically aligned with the ideology which detests the size and scope of the government (realistically, those aspects which the ideologues feel are not in their interest). What is unexpected is the swiftness and the brutality of action, but revolutions tend to be messy, and make…
Trump's actions towards Putin are highly irrational. Maybe he's being blackmailed, maybe he's being bought, maybe he just has likes Putins style but there is a reason people suspect him despite it being unlikely in the general case.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#306If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…
The EU should just buy MITRE. Move it to the EU and make it a EU based project.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#307Step 1: Post discreetly to a forum with minimal information and an absurdly short deadline
Step 2: Phone your friend, the former board member, to make your case on LinkedIn
Step 3: Ring up a friendly journalist and give them a tip
Step 4: Reference the insuing chaos as justification for keeping your project funded
Note that the article carefully avoids pinning the blame on DOGE or the Whitehouse while heavily implying it. MITRE is technically a private entity, albeit a non-profit. And the very last paragraph of the article states:
> A CISA spokesperson told CSO, “CISA is the primary sponsor for the Common Vulnerabilities and Exposure (CVE) program… Although CISA’s contract with the MITRE Corporation will lapse after April 16, we are urgently working to mitigate impact and to maintain CVE services on which global stakeholders rely.”
To be clear, the point isn't to say that the CVE program isn't valuable, nor is it to say that it's good for a shenanigan like this to be necessary.
The point is that, unless you're directly involved in this subject (not impacted—involved), it's probably best to maintain a "wait and see" attitude rather than succumb to catastrophizing this news.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#308If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…
The EU should just buy MITRE. Move it to the EU and make it a EU based project.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#309If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#310Earlier quoted context omitted.
>>They thought they voted for something different Like what exactly? I mean the guy ran on cutting the budget by 2 trillion. In his last term he gave tax breaks yo the rich. Where did they think the cuts were coming from? He ran very hard on raising tarrifs. Which demonstrably raise prices (thats literally their goal.) But now people claim "I didn't vote for this." In truth they voted for him because he was the Repub…
> In truth they voted for him because he was the Republican on offer and they're die-hard Republican. The Republican party has made no secret of its agenda for decades. This is actually simply not true. The Republican party before the Tea Party looked nothing at all like this. Trump won the presidency last year riding a wave of distinctly not-your-typical-Republican lower class voters. As he rose the old guard Republ…