Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

301–310 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#301

To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.

Everything is political now by design. It's meant to reach into every facet of society and community and restructure it.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#302

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

Try if you can find some help here https://openssf.org/

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#303

Earlier quoted context omitted.

It's a legitimate term. It's like criticizing use of the word startup or demanding someone put a dash in frontend or backend .

term is real... but is more like criticizing misuse of word startup. to be even more accurate it is what I said and not anything else

Maybe you don't see how it's bikeshedding. Ah well, let me try to explain.

It's because it's like if someone had forgotten to validate the user's role in an endpoint in a Django app, and someone said that they should have used Rails because it's easier to understand. In reality both are easy enough to understand to be able to do an authorization check, and the framework isn't the issue. So the person suggesting Rails is bikeshedding.

Likewise, if someone made another vulnerability database it would likely have the same issue, and this isn't really the place to solve it. If somehow this does trigger the realization to solve it, then it will be by luck.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#304
post #76
post #48

Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?

The scores were never going to be that accurate across people's environments (IDK how much other places relied on them, places I worked never did that much) and issues with the scores don't seem to be a good justification to torch the whole CVE system anyway.

This^ and to add to that, at the very least MITRE assigned IDs which is great. Plus they did an initial scoring, which, well… will never be perfect like you said and I’m sure these things evolve throughout time and get better (not talking necessarily CVSS vX).

What a shame on this current gov. administration, if you can even call it that.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#305
post #196

Earlier quoted context omitted.

I still find it wild that so many people are trying to frame these decisions through a political lens. This is the actions of a foreign bad actor dismantling critical institutions from within, not "bad policy". Surely there's an antibody response.

> I still find it wild that so many people are trying to frame these decisions through a political lens. Why? The decisions are pretty well politically aligned with the ideology which detests the size and scope of the government (realistically, those aspects which the ideologues feel are not in their interest). What is unexpected is the swiftness and the brutality of action, but revolutions tend to be messy, and make…

They are not. Trump is no libertarian or small government guy. The build the wall guy is the opposite of that. Even with stuff like social security he usually at least rhetorically claimed to be for more benifits (as long as it goes to "real Americans") and he is all for increasing police and military spending. And generally spending more on stuff that gives him money. Plus giant tax increases (tarrifs). He doesn't care much if government is dismembered as long as it owns the libs and gets rid of the public corruption prosecutors/others who might stand up to him

Trump's actions towards Putin are highly irrational. Maybe he's being blackmailed, maybe he's being bought, maybe he just has likes Putins style but there is a reason people suspect him despite it being unlikely in the general case.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#306

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

The EU should just buy MITRE. Move it to the EU and make it a EU based project.

MITRE is a non-profit. All the EU has to do is reach out to MITRE and be willing to fund the project.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#307
As a newly minted cynic, this seems like a cynical play to save someone's budget.

Step 1: Post discreetly to a forum with minimal information and an absurdly short deadline

Step 2: Phone your friend, the former board member, to make your case on LinkedIn

Step 3: Ring up a friendly journalist and give them a tip

Step 4: Reference the insuing chaos as justification for keeping your project funded

Note that the article carefully avoids pinning the blame on DOGE or the Whitehouse while heavily implying it. MITRE is technically a private entity, albeit a non-profit. And the very last paragraph of the article states:

> A CISA spokesperson told CSO, “CISA is the primary sponsor for the Common Vulnerabilities and Exposure (CVE) program… Although CISA’s contract with the MITRE Corporation will lapse after April 16, we are urgently working to mitigate impact and to maintain CVE services on which global stakeholders rely.”

To be clear, the point isn't to say that the CVE program isn't valuable, nor is it to say that it's good for a shenanigan like this to be necessary.

The point is that, unless you're directly involved in this subject (not impacted—involved), it's probably best to maintain a "wait and see" attitude rather than succumb to catastrophizing this news.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#308

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

The EU should just buy MITRE. Move it to the EU and make it a EU based project.

[dead]

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#309

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

Depending on deployment strategy I could help with Kubernetes stuff.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#310

Earlier quoted context omitted.

>>They thought they voted for something different Like what exactly? I mean the guy ran on cutting the budget by 2 trillion. In his last term he gave tax breaks yo the rich. Where did they think the cuts were coming from? He ran very hard on raising tarrifs. Which demonstrably raise prices (thats literally their goal.) But now people claim "I didn't vote for this." In truth they voted for him because he was the Repub…

> In truth they voted for him because he was the Republican on offer and they're die-hard Republican. The Republican party has made no secret of its agenda for decades. This is actually simply not true. The Republican party before the Tea Party looked nothing at all like this. Trump won the presidency last year riding a wave of distinctly not-your-typical-Republican lower class voters. As he rose the old guard Republ…

Populism is not an agenda it's a style. Also the majority of poor people voted Democrat, the majority of people with low education levels voted for Trump (which is not the same thing as dumb, although voting for Trump is dumb regardless of PhD or lack of HS diploma). There's overlap between low levels of education and income but if you define class by income then low income people mostly voted Dem
Post reply on HN