Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

461–470 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#461

Am I missing something or was this literally announced with less than 24 hours of warning that one of the critical components to the cyber security landscape was disappearing. What the fuck are you supposed to do about this. This is something that should have had multiple MONTHS of warning in order to allow those who depend on the CVE infrastructure to plan what to do next with their security posture.

CVE-zero: the attack is coming from inside the White House.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#462

Earlier quoted context omitted.

MITRE is a non-profit. All the EU has to do is reach out to MITRE and be willing to fund the project.

I think all the big companies that owe their ongoing business should band together and fund it. No way an organization like this should rely on just one sponsor.

I think that I'm in favour of pricing in externalities like this.

What cross-industry organisations exist that could coordinate?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#463
post #445

Earlier quoted context omitted.

you've slept just 3 hours? Go back to bed..

Maybe just a toilet break (see the bio): > Fun fact: All my comments have been written on the toilet. I don't use social media anywhere else.

https://xkcd.com/1369/

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#464
post #445

Earlier quoted context omitted.

you've slept just 3 hours? Go back to bed..

Maybe just a toilet break (see the bio): > Fun fact: All my comments have been written on the toilet. I don't use social media anywhere else.

Yep, toilet and now back to bed :D

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#465

The real irony here is that a lot of ycombinator founders and the people reading HN were exactly the ones making this possible and now start to wonder why the snake eats its own tail.

The missing funding is something like 2 million dollars. Any US company could make this issue go away in an instant.

We will see. I understand that money shouldn't be an issue but trust might be, no?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#466

Earlier quoted context omitted.

>They've been aware of the risk of relying on the US for software security for years, but AFAIK there have been no efforts to do anything about it. Indeed. Just as Germany knew their economy is vulnerable to Russian gas and did nothing about it, even after the 2014 invasion of Crimea. Just as the west knew moving their entire manufacturing sector to one country would make them vulnerable, but choose to ignore it beca…

> I never EVER saw politicians act proactively for the good of the nation or the people, This is almost certainly because those cases don't make the news.

They do where I live, but those are drops in the bucket compared to the industrial scale theft(wealth transfer) the central government operates.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#467

Earlier quoted context omitted.

>>They thought they voted for something different Like what exactly? I mean the guy ran on cutting the budget by 2 trillion. In his last term he gave tax breaks yo the rich. Where did they think the cuts were coming from? He ran very hard on raising tarrifs. Which demonstrably raise prices (thats literally their goal.) But now people claim "I didn't vote for this." In truth they voted for him because he was the Repub…

> In truth they voted for him because he was the Republican on offer and they're die-hard Republican. The Republican party has made no secret of its agenda for decades. This is actually simply not true. The Republican party before the Tea Party looked nothing at all like this. Trump won the presidency last year riding a wave of distinctly not-your-typical-Republican lower class voters. As he rose the old guard Republ…

I'm upvoting you because you make a coherent argument, and votes here should be for that, not whether I agree with you or not.

I would agree he's not George Bush, much less Ronald Reagan. Nevertheless those who voted for Bush and Reagan also voted for Trump.

This has been "decades" in the making in the sense that since Obama was elected (in 2008), Republicans have embraced racism at the heart of their populist message. That swing rightward was made palatable to center republicans with a woman democratic candidate in 2016 (one not terribly well liked in democratic circles) and a black woman candidate in 2024.

While racism, and misogyny gather a bunch of votes, long-term distrust of institutions is sown, and fostered. Republican policy becomes protecting white guys, and especially old, rich, white guys.

Reagan was popular and competent, and worked for the good of America. Today's president is nothing like him, but wins because a bunch of people "vote Republican".

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#468

Earlier quoted context omitted.

>They've been aware of the risk of relying on the US for software security for years, but AFAIK there have been no efforts to do anything about it. Indeed. Just as Germany knew their economy is vulnerable to Russian gas and did nothing about it, even after the 2014 invasion of Crimea. Just as the west knew moving their entire manufacturing sector to one country would make them vulnerable, but choose to ignore it beca…

Germany had with under the best deal for gas possible with Russia, I don’t understand the sentiment calling it a vulnerability. There is still a working pipeline available and Russia stated clearly if would continue delivering gas, if Germany wants to.

Except what Russia states and what Russia does are only aligned when it serves Russia. Russia stopped delivering gas through NordStream 1. After that, Germany took note of the danger and decided it would do better without that dependency.

https://www.aljazeera.com/economy/2022/9/2/russias-gazprom-k...

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#469

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

The main costs definitely not hosting and can be quite significant. MITRE had $2.37B revenue in 2023, most if it contributions. I don't know how much of it can be attributed to the CVE, but I assume it's not an insignificant part of it: https://projects.propublica.org/nonprofits/organizations/422...

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#470
post #373

It’s a reckless move to cut funding so abruptly, but taking a step back from the short-term chaos, it probably is an anomaly that this was government funded. All of private tech relies on it, and private tech is big enough to pay for it. I hope that the trillion dollar babies consider this an opportunity to pool together to form a foundation that funds this, and a bunch of other open source projects run by one random…

ah yes, let private entities pay for it. then when there is a vulnerability with one of those entities' software, they can pay a bit more to bury it!
Post reply on HN