Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

381–390 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#381
post #364

Earlier quoted context omitted.

I mean I think The Republican Incumbent was chosen specifically as a tool because he is so extreme, pervasive and demoralising and creeps into everything. Definitely by Russia, maybe also by our "friend" in the ME. Although it's not that reported on they are on friendly terms. Disaffection lends itself easily to creating a Russia-style society. This all feels pretty Dugin-esque, and his proposition (return to values,…

What is "ME" referring to?

"Middle East" is the usual expansion, and fits in context here.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#383

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

The European, GDPR compliant subnet of the Internet Computer could suit your needs. The app would be decentralized out of the box and it can't be shut down by a single entity like a traditional cloud provider or nation state. Hosting 100GB costs about 500$ per year [0]. This is not a traditional hosting provider, it's a decentralized cloud. Reach out on the forum [1] or to me if this sounds like a good fit to you (I think it does, from your list of requirements).

[0] https://internetcomputer.org/docs/building-apps/essentials/c... [1] https://forum.dfinity.org/

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#384
post #351
post #331

Earlier quoted context omitted.

Well, that's kind of the point? The current administration doesn't care about cyber defense, any less than it cares about protecting the environment, protecting consumers, having top-notch universities and research, foreign aid etc. etc. Actually, it takes pride in not caring about all of these things.

My guess is that they feel they are supplying something the whole world is benefiting from, and they believe that unfair. That ignores the fact that the US benefits immensely from this, and that they benefit domestically from providing that benefit more widely by getting a lot of free contributions from the outside. But the US foots the bill of those who do get payed, so its unfair...

It's so unfair that I have an great job so I can treat my friends to dinner all the time! I hate being rich.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#385

Earlier quoted context omitted.

People trying to ignore politics are like fish trying to ignore water.

Not talking about politics is itself a political position (in favor of status quo).

Depends. We’re a small, very international startup and have a super strict “no politics” policy. Politics and work are not a good combination when you’re employing people from all over the world.

But I would not consider it a political statement to adopt this policy.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#386

I'm trying to steelman but I really can't think of a non- nefarious justification for this

Reduce government spending; since it's not actually a government organization (as far as I can tell, I never looked into it before), other organizations can fund it. How much goes into this organization a year anyway? I'm seeing a Mitre corporation that does lots of other stuff too that has a revenue of 2.2 billion a year. Multi-trillion-dollar companies benefit from and contribute to this system, surely they can spa…

> surely they can spare 0.01% of their revenue

They would, if we made companies pay their taxes.

Yes, you can also run such a system based on donations. But I personally think that such a system is important enough to be paid for by the government. When you run on donations, there will always be conflicts of interest and the risk of running out of funds.

But yeah, Mitre being a private organization that was paid for by the government was a problem.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#387

To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.

HN and founders will say "no politics here" on the regulated internet, drinking regulated water, eating regulated food, breathing regulated air.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#388

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

The EU should just buy MITRE. Move it to the EU and make it a EU based project.

I don't think the EU has any interest in this. They've been aware of the risk of relying on the US for software security for years, but AFAIK there have been no efforts to do anything about it. Maybe the current situation will kick some butts into gear ...

Off topic: your username is very appropriate given the situation.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#389
post #75

Earlier quoted context omitted.

Destroy, destroy, destroy. Promise to rebuild but don't. Take it all.

Did they promise to rebuild? If I'm giving them the benefit of the doubt (which I hate), it's a shotgun approach; cut things relentlessly and see what falls apart. Chaos engineering applied to a country and / or the world.

There are various glorious futures floating around about how this will make America better, stronger, more independent.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#390
post #48

Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?

As an active consumer of CVEs: yea there are major problems. No there's nothing better and no I don't have any better ideas. The scores are mostly useless, I would not care if they disappeared, I do not look at them. I don't really understand why people get so upset about garbage scores though. If a high CVSS score creates a bunch of work for you then your vuln mag process is broken IMO. (Or alternatively, you are in…

> you are in the business of compliance rather than security.

So, most businesses. They all need their ISO/NIST/HIPAA/etc certs.

Post reply on HN