Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

441–450 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#441

To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.

People trying to ignore politics are like fish trying to ignore water.

It’s really a question of time and place. There are many foundational topics in life, such as politics, religion, and philosophy. But it’s not always helpful or appropriate to discuss them in a particular setting.

That said, HN already has an extremely wide range of subject matter, so I wouldn’t say politics should be out of place here. It can, though, become a divisive distraction that disrupts other conversations, so I can appreciate that some limits are needed.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#442
post #249
post #52

Earlier quoted context omitted.

and then a random 9.8 critical comes that affects some software you have in a way that makes it a 0 in your environment but it doesn't matter cause the cve tanks your organizational Security Score (tm) by 10 arbitrary points and management is wondering when you'll secure the company again because the Security Score is their only tangible deliverable to measure success

Spot on. Vulnerability scanners that make up an organizational Security Score (TM) tend to operate at the wrong level of abstraction, flagging some library somewhere that never runs and has nothing to do with your production flow or architecture, or some test keys with zero security impact. Go explain that to management, because obviously the security tools are right and you are wrong. This sad state of affairs is un…

This is my research field. Do you have any input you can think of at the top of your head?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#443
post #223

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

Maybe something to bring up to one of these e.V.'s if it ends up being difficult to get started: Codeberg.org, nlnet.nl, ccc.de

Codeberg might be a nice cooperation partner for hosting the git repositories. Gonna write them!

I'm also visiting the local CCC chapters here this week, maybe it makes sense to have a separate e.V. where the CCC chapters are beneficiaries?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#444

Earlier quoted context omitted.

Everything was always political. Laws, the economy, conflcit. How is any person not affected by these? The government is responsible for all or a large part of how a country functions. People who say "I'm not political" are deflecting to avoid conflict

One of the benefits a working democracy conveys to its citizens is that they largely don't have to care about politics. They can trust that government action is relatively consistent over time, that laws will be enforced fairly enough, that their property will be protected to a reasonable degree, that the currency will be reasonably stable, that the roads will be maintained, that some public transport will be availab…

Interestingly, I believe that the reality is exactly the opposite: on the political regimes' spectrum of democratic -> authoritarian -> totalitarian only the middle one doesn't require people's participation. Both democracy and totalitarism need to be actively maintained by significant part of the population, otherwise they converge to the "natural" state of things - authoritarian order. None of the stuff you listed (fair laws, property rights, etc.) occur naturally once it has been set up at some point in past. That's why they talk about "checks and balances" all the time, and they are impossible without active participation.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#445

Earlier quoted context omitted.

Honest question: Does this not already exist? - https://vulnerability.circl.lu/ - https://osv.dev/ - https://vuldb.com/ And a few others?

OSV is made by Google/Alphabet and therefore also prone to Trump intervention (see Gulf of Mexico executive order). The circl.lu might be actually a potential cooperation partner. (Vuldb is down right now)

you've slept just 3 hours? Go back to bed..

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#446

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

There are already many security trackers, why writing a new one? The issue is paying people to handle the advisories.

I agree with you there. Before CISA got sacked / taken down, they were working together with the BSI and other CERT agencies on a vulnerability exchange format.

This might be the optimum time to implement CSAF and to lead by example when it comes to vulnerability disclosures.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#447

Earlier quoted context omitted.

Not talking about politics is itself a political position (in favor of status quo).

Depends. We’re a small, very international startup and have a super strict “no politics” policy. Politics and work are not a good combination when you’re employing people from all over the world. But I would not consider it a political statement to adopt this policy.

How do you define politics? For example, are employees allowed to be LGBTQ? Are they allowed to mention their relationships to colleagues?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#448

Earlier quoted context omitted.

When this is discussed, what's being meant is that everday party politics are spilling out and overwhelming a project's or industry's individual, internal politics, which are often a completely disconnected meta. Appealing to "well everything is connected" I'm not sure is useful. It's interesting from a semantics perspective the first few times you come across it maybe, then swaps around into being plain frustrating,…

> I think are doing a pretty big favor to their mental health, and It your mental health is harmed while defending your political views it's possible your views are the issue. For example if my view was that "domestic animals shouldn't be abused and penalties increased for such crimes" I wouldn't have mental health issues discussing this.

The vast majority of people will get stressed talking to people they think are evil or against their values. Someone breaking down in tears because another person says they "don't give a fuck about the bloody Gazans" is not behaving particularly unusually.

The views don't matter as much as how strongly they are held.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#449
post #387

To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.

HN and founders will say "no politics here" on the regulated internet, drinking regulated water, eating regulated food, breathing regulated air.

Apart from the few maniacs On Here who seek out the unregulated intentionally. Raw milk (all those tasty diseases). "Research chemicals" (don't hear so much about that lately, but there were whole microdosing fads).

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#450

To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.

> The ancient Greek understanding of an “idiot” referred to someone who was a private citizen or a person who did not actively participate in public life or politics.
Post reply on HN