Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

411–420 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#411

To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.

"You can stay out of politics, but politics will always come and find you." No, it's just recognising that it is silly to talk about politics, as certain views are just downvoted.

Of all places I find this one the most shielded from this behavior as long as you're civil.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#412

Why is this sponsored by such an American gov entity? I guess it's one of those things you never think about until it goes wrong. The world would do well to move this kind of stuff out of the US quickly, just like ICANN and stuff.

Because gov infra also relies on CVE?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#413

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

messaged on linkedin fyi

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#414

Earlier quoted context omitted.

Not talking about politics is itself a political position (in favor of status quo).

Depends. We’re a small, very international startup and have a super strict “no politics” policy. Politics and work are not a good combination when you’re employing people from all over the world. But I would not consider it a political statement to adopt this policy.

I am torn.com player which is a MMORPG as far removed from politics as can be. But when large part of dev team are ukrainians that were suddenly unable to work from clearly political reasons you can't ignore it.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#415

Earlier quoted context omitted.

Not talking about politics is itself a political position (in favor of status quo).

Depends. We’re a small, very international startup and have a super strict “no politics” policy. Politics and work are not a good combination when you’re employing people from all over the world. But I would not consider it a political statement to adopt this policy.

One might argue that it's even more important to discuss international politics these days, considering how interconnected the world is and how so many countries seem to be facing many of the same issues.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#416
post #314

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

The AGPL is a nonfree (and nonsensical) license. There’s nothing wrong with normal GPL.

[deleted]

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#418

I'm trying to steelman but I really can't think of a non- nefarious justification for this

Reduce government spending; since it's not actually a government organization (as far as I can tell, I never looked into it before), other organizations can fund it. How much goes into this organization a year anyway? I'm seeing a Mitre corporation that does lots of other stuff too that has a revenue of 2.2 billion a year. Multi-trillion-dollar companies benefit from and contribute to this system, surely they can spa…

Yes, I'm sure corporations funding the CVE system would go wonderfully. "It would be best if we don't see any severe CVEs for our products this quarter, if you want our funding next quarter."

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#419

Earlier quoted context omitted.

Everything was always political. Laws, the economy, conflcit. How is any person not affected by these? The government is responsible for all or a large part of how a country functions. People who say "I'm not political" are deflecting to avoid conflict

When this is discussed, what's being meant is that everday party politics are spilling out and overwhelming a project's or industry's individual, internal politics, which are often a completely disconnected meta. Appealing to "well everything is connected" I'm not sure is useful. It's interesting from a semantics perspective the first few times you come across it maybe, then swaps around into being plain frustrating,…

Two things:

"Party politics" is ill-defined, and so a "no politics" rule becomes an arbitrary hammer that bosses can use to smash employees. If I say "I'm going to get a COVID vaccine this afternoon" is that discussing party politics? In the UK, where I live, the vaccine was provided by the government, so I'm implicitly discussing the actions of the government. That is under any reasonable definition a discussion of politics.

"everyday party politics are spilling out and overwhelming a project's or industry's individual, internal politics" is how "no politics" rules are usually justified, but this was not what happened in the poster child cases of implementing "no politics" rules (37signals, Coinbase). 37signals in particular tried to spin it this way, but it was the actions of a group within the company approved by the founders that caused the problem. (Coinbase was just completely incoherent from the start. Their mission is something like "End economic inequality" which a reasonable person could take to mean anarchist or communist discussion is on topic.)

Post reply on HN