Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

401–410 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#401

Earlier quoted context omitted.

Not talking about politics is itself a political position (in favor of status quo).

Depends. We’re a small, very international startup and have a super strict “no politics” policy. Politics and work are not a good combination when you’re employing people from all over the world. But I would not consider it a political statement to adopt this policy.

Your statements are incoherent. Politics is decision making and power relationships within groups of people. It is 100% a political statement to adopt this policy as it exercises power over a group. You cannot function as a group without politics. "Where do y'all want to go for lunch" is also politics, as it involves group decision making and power relationships (Do you go to the vegetarian place? Do you avoid the spicy place?) It's a completely banal decision but it is still politics.

If what you want is a "don't piss off your coworkers by discussing topics unrelated to work that you know will annoy people" policy, that is fine, but don't pretend you are not engaging in politics.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#403
The latest contract[1] (I hope this is the right one) for MITRE's involvement with CVE and CWE programs was USD$29.1m for the period 2024-04-17 to 2025-04-16 with optional extension of expenditure up to USD$57.8m and to an end date of 2026-04-16.

Seemingly MITRE hasn't been advised yet whether the option to extend the contract from 2025-04-16 to 2026-04-16 will be executed. And there doesn't appear to be any other publicly listed approach to market for a replacement contract.

[1] https://www.fpds.gov/ezsearch/jsp/viewLinkController.jsp?age...

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#404
post #126

Earlier quoted context omitted.

Your words don't make any sense in this environment. The idea that any person at an agency could stand up to or convince the DOGE team of anything is preposterous. Anything that weakens the US or puts our cybersecurity in a place that Russia can exfiltrate data will happen. This is not about the US needing anything and it's silly to think otherwise. See also the NLRB whistleblower and the security backdoors that DOGE…

> Your words don't make any sense in this environment. The idea that any person at an agency could stand up to or convince the DOGE team of anything is preposterous. Your comment embraces and spreads the powerlessness they want you to feel and spread. Of course you can stop them - like any other negotiation in life, especially non-friendly ones, you need to make it in Trump's interest either by carrot or stick. Trump…

No, blaming "someone inside DHS" is what makes no sense. It 100% makes sense to blame DOGE and actual perpetrators. You can stop them only if you start to blame those who do the stuff you dont like instead of blaming everyone else except them.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#405
post #388

Earlier quoted context omitted.

The EU should just buy MITRE. Move it to the EU and make it a EU based project.

I don't think the EU has any interest in this. They've been aware of the risk of relying on the US for software security for years, but AFAIK there have been no efforts to do anything about it. Maybe the current situation will kick some butts into gear ... Off topic: your username is very appropriate given the situation.

>They've been aware of the risk of relying on the US for software security for years, but AFAIK there have been no efforts to do anything about it.

Indeed. Just as Germany knew their economy is vulnerable to Russian gas and did nothing about it, even after the 2014 invasion of Crimea. Just as the west knew moving their entire manufacturing sector to one country would make them vulnerable, but choose to ignore it because it was too profitable.

I never EVER saw politicians act proactively for the good of the nation or the people, all they do is act reactively after the shit hits the fan to control public opinion and blame someone else to make sure they get re-elected, that's it.

Once you realize our rulers aren't competent at their jobs or acting in the peoples' best interest, it all makes sense. They're in it for the grift and to enrich their monopolistic friends in the private sector, to make sure line goes up in the next quarter, that's it.

Yes, I know there are good politicians out there who care and fight for their local communities, but they never make it to rule at national or international stage and actually change the rotten system because the status quo doesn't allow that.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#406
post #373

It’s a reckless move to cut funding so abruptly, but taking a step back from the short-term chaos, it probably is an anomaly that this was government funded. All of private tech relies on it, and private tech is big enough to pay for it. I hope that the trillion dollar babies consider this an opportunity to pool together to form a foundation that funds this, and a bunch of other open source projects run by one random…

> it probably is an anomaly that this was government funded

Companies can definitely fund it. But to be fair the gov, including NIST, also relies on CVE.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#407
post #76
post #48

Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?

The scores were never going to be that accurate across people's environments (IDK how much other places relied on them, places I worked never did that much) and issues with the scores don't seem to be a good justification to torch the whole CVE system anyway.

Why isn't it a good justification?

I think the question everyone in this thread should ask is: why is it the government's job to do this, especially given the prior widespread view that they're doing a bad job? Is the software industry so immiserated by poverty that it cannot organize its own distribution of security bulletins? Clearly not: GitHub already runs its own vuln tracking scheme that's better integrated with the tooling we use for open source software. The industry routinely sets up collaborations like standards bodies, information sharing groups and more. And there is as whole ecosystem of security companies to help you understand vulns in your stack.

So there seems nothing specific to CVEs that requires government involvement, but the existence of the tax funded scheme does discourage the creation of competitors that might function better.

But, to CVE or not to CVE ... that is not the question. US deficit spending is out of control. This sort of thing had to happen some day. It's what Europeans in the 2010s called "austerity" and it always makes some people scream but this graph:

https://fiscaldata.treasury.gov/americas-finance-guide/natio...

... is not sustainable. Up to 1984 overall US debt was stable. Since then its growth rate became dangerous. Debt/GDP ratio is now worse than just after WW2. The federal government is currently spending more on interest than on defense or Medicare:

https://www.crfb.org/blogs/interest-costs-have-nearly-triple...

The US is currently getting its first taste of what parts of Europe started going through in 2008, and unfortunately there's bad news: the cuts you're seeing now are mostly cosmetic. They're what can be done within the current framework of laws, sort of, with lots of bending of the rules and creative interpretations of them and maybe some oversteps. But it's just the start of what's needed. Large scale reform of the laws themselves will be required regardless of whoever wins the next elections.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#408

Earlier quoted context omitted.

"the government" aka "We the people". It is in all our interest. This is like asking why the government is responsible for roads.

> This is like asking why the government is responsible for roads. Thought experiment: If roads were built by private companies, could a Government justify the expense maintaining a database of all the potholes?

Yes, as it would be a public good to everyone to be able to know where the potholes(that aren't profitable to fix for these private companies apparently) are so they can avoid them.

They might take a step back and realize that it would be more cost-effective to just own the roads, in which case your thought experiment ends where we are, because where we are was a place reasoned to(to an extent).

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#409

To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.

I view the archive.org, Wikipedia, CVE program, and Linux Kernel to all have had discussions on HN about how to they should be funded. Is that kind of politics the kind that people wish that HN stayed out from?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#410

I don't see why this should be publicly funded, so I don't really see an issue with this. The industry benefits from having a CVE database, so the industry should fund it.

Don't open source developers and users of their software also benefit from the CVE database?

If it were privately funded, what incentive would these private companies have to track bugs for these open source projects that don't make money?

Post reply on HN