Earlier quoted context omitted.
I don't think the EU has any interest in this. They've been aware of the risk of relying on the US for software security for years, but AFAIK there have been no efforts to do anything about it. Maybe the current situation will kick some butts into gear ... Off topic: your username is very appropriate given the situation.
>They've been aware of the risk of relying on the US for software security for years, but AFAIK there have been no efforts to do anything about it. Indeed. Just as Germany knew their economy is vulnerable to Russian gas and did nothing about it, even after the 2014 invasion of Crimea. Just as the west knew moving their entire manufacturing sector to one country would make them vulnerable, but choose to ignore it beca…
CVE program faces swift end after DHS fails to renew contract [updated]
431–440 of 1001 posts
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#432Re: CVE program faces swift end after DHS fails to renew contract [updated]
#433If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…
Honest question: Does this not already exist? - https://vulnerability.circl.lu/ - https://osv.dev/ - https://vuldb.com/ And a few others?
The circl.lu might be actually a potential cooperation partner.
(Vuldb is down right now)
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#434Earlier quoted context omitted.
People trying to ignore politics are like fish trying to ignore water.
Not talking about politics is itself a political position (in favor of status quo).
Only a small percentage of people are able to handle fundamental disagreements calmly and without it bleeding over to other interactions.
Will the SE and sales guy work as well together if the former knows the latter donates half his commission money to organizations that help kill babies?
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#435Earlier quoted context omitted.
important to note: the US's food safety is already really bad. salmonella isn't a thing you have to worry about in first world countries. can't wait to see what plague demon spawns out of a food industry running amok after the FDA gets gutted.
At least American chicken is chlorinated: https://www.npr.org/sections/shots-health-news/2025/04/15/nx...
"The vast majority of chicken processed in the United States is not chilled in chlorine and hasn't been for quite a few years," says Dianna Bourassa, an applied poultry microbiologist at Auburn University, "So that's not the issue."
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#436Earlier quoted context omitted.
>They've been aware of the risk of relying on the US for software security for years, but AFAIK there have been no efforts to do anything about it. Indeed. Just as Germany knew their economy is vulnerable to Russian gas and did nothing about it, even after the 2014 invasion of Crimea. Just as the west knew moving their entire manufacturing sector to one country would make them vulnerable, but choose to ignore it beca…
Germany had with under the best deal for gas possible with Russia, I don’t understand the sentiment calling it a vulnerability. There is still a working pipeline available and Russia stated clearly if would continue delivering gas, if Germany wants to.
- You're Germany.
- You join NATO for protection from Russia, an actor with a long history of military aggression[1]
- Your export economy is based on manufacturing.
- The energy driving your manufacturing sector is ~60% cheap gas from Russia, your military aggressive partner.
- Russia invades Georgia in 2008 and Ukraine in 2014 to no ones surprise
- Leaders of USA and Eastern Europe warn you of Russia's influence on your economy
- You ignore all this and build another gas pipeline from Russia
- You are surprised Russia invades Ukraine(again) and gas sanctions cripple your manufacturing economy
MFW German leaders and HN commenters see no vulnerability in this.Someone please stop the planet, I wish to get off, my sanity can't handle this level of stupidity anymore.
[1] https://natoassociation.ca/a-timeline-of-russian-aggression/
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#437The real irony here is that a lot of ycombinator founders and the people reading HN were exactly the ones making this possible and now start to wonder why the snake eats its own tail.
exactly; I hope ycombinator and its proponents can enjoy living in the ancap fantasy land where you have to pay to be alerted for a climate change fueled mega hurricane (also caused by this exact same reckless, unregulated greed) because NOAA was disbanded. Billionaires shouldn't exist, but neither should millionaires.
For-profit private journaling is working really well for academia!
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#438If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…
Try to talk to the people from the Sovereign Tech Fund, they have a history of sponsoring security relevant projects in the EU.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#439The real irony here is that a lot of ycombinator founders and the people reading HN were exactly the ones making this possible and now start to wonder why the snake eats its own tail.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#440Earlier quoted context omitted.
Depends. We’re a small, very international startup and have a super strict “no politics” policy. Politics and work are not a good combination when you’re employing people from all over the world. But I would not consider it a political statement to adopt this policy.
Your statements are incoherent. Politics is decision making and power relationships within groups of people. It is 100% a political statement to adopt this policy as it exercises power over a group. You cannot function as a group without politics. "Where do y'all want to go for lunch" is also politics, as it involves group decision making and power relationships (Do you go to the vegetarian place? Do you avoid the sp…