Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

311–320 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#311

These four years are going to be the death of all of us.

I find it a little incredible people are still talking about "four years".

They tried to reject the election result and do a coup, and were rewarded for it by getting back into power. They are refusing to follow the law or the courts. They are sending people to gulags in foreign countries. All the checks and balances were destroyed last time. The party has been stripped of anyone who would fight the admin or reject this illegality. They have set up a power grab over elections.

There will not be free and fair elections in four years unless they are simply too incompetent to rig it, the rubicon was crossed long ago. Without mass protest that makes it impossible for them to hold power, American democracy is dead.

They have tried to do it, they say they want to do it, they have the ability to do it, they are actively doing it, and no one is stopping them. How are people still acting like in four years they are going to neatly hand over power to be prosecuted for their crimes?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#312

As a newly minted cynic, this seems like a cynical play to save someone's budget. Step 1: Post discreetly to a forum with minimal information and an absurdly short deadline Step 2: Phone your friend, the former board member, to make your case on LinkedIn Step 3: Ring up a friendly journalist and give them a tip Step 4: Reference the insuing chaos as justification for keeping your project funded Note that the article…

Have you seen proof that this is what has been happening? Your explanation is much more convoluted than "DHS cut funding, like the administration has said it is going to do".

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#313

Earlier quoted context omitted.

Basically when any software/library/whatever has a vulnerability, they have to communicate that out themselves, in some format. If I'm developing a product built on 20 libraries, it won't just be a matter of scanning CVEs for major vulnerabilities any more, so I'm more likely to miss one. "always update" doesn't always work, when to manage a product you realistically have to version pin.

They surprise is: they won't. This will weaken the West. This is dangerously stupid.

[dead]

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#314

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

The AGPL is a nonfree (and nonsensical) license.

There’s nothing wrong with normal GPL.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#315

To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.

Everything is political now by design. It's meant to reach into every facet of society and community and restructure it.

Everything was always political. Laws, the economy, conflcit. How is any person not affected by these? The government is responsible for all or a large part of how a country functions.

People who say "I'm not political" are deflecting to avoid conflict

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#317

Earlier quoted context omitted.

Vampire capitalism. They want civilization to break down so they can offer a solution for profit. The enemies of all people and life on the planet are a tiny group of oligarchs and their supplicants.

This isn't capitalism, any more than arson, burglary, or extortion is capitalism. Get some new material.

> any more than arson, burglary, or extortion is capitalism

Indeed.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#318

Earlier quoted context omitted.

It’s astounding that the users here watched all the horrendous things going on and ignored them. But now the CVE numbers are gone it’s shocking and too far.

Come again? This is Hacker News, a heavily moderated forum with a narrow focus. We don't discuss Israel or El Salvador here (unless it's tech related.)

I would hope the folks that frequent HN would not be so insular as to only read what happens on HN and not read any other news source.

If you’ve somehow missed Trump’s systematic dismantling of academic freedom or his disappearing of folks he doesn’t like, then we have a far bigger problem than the limits of what is discussed on HN.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#319

Earlier quoted context omitted.

The EU should just buy MITRE. Move it to the EU and make it a EU based project.

MITRE is a non-profit. All the EU has to do is reach out to MITRE and be willing to fund the project.

I know that they are a 501(c)3, but they have significant revenue and intellectual property, so in order to do the lift and shift, there would need to be some money changing hands to accomplish it. Not only that, but being owned by the EU gives the ability for MITRE employees to have the option to immigrate to the EU to protect against any retaliation.

I cannot believe I am typing that second sentence, but here we are.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#320
post #314

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

The AGPL is a nonfree (and nonsensical) license. There’s nothing wrong with normal GPL.

[deleted]
Post reply on HN