Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

371–380 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#371
This makes me wonder what other stuff most people don't know exists but is important to our society has quietly disappeared in the last few weeks. We know about this one because we know it's important. What are the things we don't know about?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#372

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

There are already many security trackers, why writing a new one? The issue is paying people to handle the advisories.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#373
It’s a reckless move to cut funding so abruptly, but taking a step back from the short-term chaos, it probably is an anomaly that this was government funded. All of private tech relies on it, and private tech is big enough to pay for it. I hope that the trillion dollar babies consider this an opportunity to pool together to form a foundation that funds this, and a bunch of other open source projects run by one random person in Nebraska.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#374
post #48

Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?

As an active consumer of CVEs: yea there are major problems. No there's nothing better and no I don't have any better ideas.

The scores are mostly useless, I would not care if they disappeared, I do not look at them. I don't really understand why people get so upset about garbage scores though. If a high CVSS score creates a bunch of work for you then your vuln mag process is broken IMO. (Or alternatively, you are in the business of compliance rather than security. If you don't like working in compliance, CVSS scores aren't the root cause of your misery).

Having a central list of "here's a bunch of things with stable IDs that you might or might not care about" is very valuable.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#375
post #235

Earlier quoted context omitted.

And maybe the sidn fund?

Nlnet for opensource

Yes, maybe reach out to Michiel Leenaars from the NLNet foundation. But IIRC NLNet mostly funds shorter development tracks, not ongoing upkeep/maintenance.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#376

To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.

People trying to ignore politics are like fish trying to ignore water.

Not talking about politics is itself a political position (in favor of status quo).

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#378

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

I'm not European but I'd love to help.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#379

To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.

Everything is political now by design. It's meant to reach into every facet of society and community and restructure it.

That's because we got reliant on the funds from government. Maybe it's time to break the dependency.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#380

Earlier quoted context omitted.

This sort of thing is happening across the federal government. There is no rhyme or reason. DOGE has been given an unrealistic target for cuts and they're desperately cutting whatever they can get their hands on. If you look at the federal budget it's nearly impossible for DOGE to hit their stated goals without touching benefits like medicare and social security (which are off limits so far) so the only option is dee…

>>They thought they voted for something different Like what exactly? I mean the guy ran on cutting the budget by 2 trillion. In his last term he gave tax breaks yo the rich. Where did they think the cuts were coming from? He ran very hard on raising tarrifs. Which demonstrably raise prices (thats literally their goal.) But now people claim "I didn't vote for this." In truth they voted for him because he was the Repub…

> Where did they think the cuts were coming from?

When someone hands you a pencil, you don't wonder what variety of tree the wood came from, or what paint chemistry was used for the coating. It's a pencil. You might have broad opinions on whether the one in your hand is comfortable to use, and sharp - but you leave the details to the pencil makers.

About 70% of the population engage with politics the same way: Leave the details to the people who do this stuff for a living.

Do they expect to be disappointed? Sure, but everyone who engages with politics expects to be disappointed.

Post reply on HN