Earlier quoted context omitted.
>They've been aware of the risk of relying on the US for software security for years, but AFAIK there have been no efforts to do anything about it. Indeed. Just as Germany knew their economy is vulnerable to Russian gas and did nothing about it, even after the 2014 invasion of Crimea. Just as the west knew moving their entire manufacturing sector to one country would make them vulnerable, but choose to ignore it beca…
Germany had with under the best deal for gas possible with Russia, I don’t understand the sentiment calling it a vulnerability. There is still a working pipeline available and Russia stated clearly if would continue delivering gas, if Germany wants to.
CVE program faces swift end after DHS fails to renew contract [updated]
471–480 of 1001 posts
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#472If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…
The EU should just buy MITRE. Move it to the EU and make it a EU based project.
https://www.enisa.europa.eu/topics/vulnerability-disclosure
They have a tender going on tracking best practices: https://www.enisa.europa.eu/procurement/vulnerability-disclo...
So they will take 12 months to select for the tender...18 months pondering on the report...and in 3 years they make a tender out for a solution...
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#473Earlier quoted context omitted.
Depends. We’re a small, very international startup and have a super strict “no politics” policy. Politics and work are not a good combination when you’re employing people from all over the world. But I would not consider it a political statement to adopt this policy.
Your statements are incoherent. Politics is decision making and power relationships within groups of people. It is 100% a political statement to adopt this policy as it exercises power over a group. You cannot function as a group without politics. "Where do y'all want to go for lunch" is also politics, as it involves group decision making and power relationships (Do you go to the vegetarian place? Do you avoid the sp…
I wish people were at least honest about "no politics" to mean "lets avoid to unsafe, potentially divisive issues relative to our geographic location, and take the basic tenets of neoliberal, capitalistic society to be assumed". And yeah, that is a more than reasonable policy. Its a difficult policy in international spaces, because its very hard to not trespass that line when political contexts differ so strongly across the globe
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#474Earlier quoted context omitted.
The EU should just buy MITRE. Move it to the EU and make it a EU based project.
I don't think the EU has any interest in this. They've been aware of the risk of relying on the US for software security for years, but AFAIK there have been no efforts to do anything about it. Maybe the current situation will kick some butts into gear ... Off topic: your username is very appropriate given the situation.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#475To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.
HN and founders will say "no politics here" on the regulated internet, drinking regulated water, eating regulated food, breathing regulated air.
If so, is there a signup page?
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#476Re: CVE program faces swift end after DHS fails to renew contract [updated]
#477Earlier quoted context omitted.
One of the benefits a working democracy conveys to its citizens is that they largely don't have to care about politics. They can trust that government action is relatively consistent over time, that laws will be enforced fairly enough, that their property will be protected to a reasonable degree, that the currency will be reasonably stable, that the roads will be maintained, that some public transport will be availab…
>One of the benefits a working democracy conveys to its citizens is that they largely don't have to care about politics The citizens elect the government so how can you not care about poltiics?
I don't think there's a direct correlation between the ability to vote and caring about politics. People usually care about politics when it affects them negatively. I would guess that most people in most democratic systems don't have strong negative experiences with their governments and, thus, are not incentivized to care about politics.
Note that I'm not making an argument that they should not care. I think they should, but the very system that allows participation probably also decreases the incentive for most people to participate.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#478If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#479If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…
Canada may be another friendly option
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#480Earlier quoted context omitted.
>They've been aware of the risk of relying on the US for software security for years, but AFAIK there have been no efforts to do anything about it. Indeed. Just as Germany knew their economy is vulnerable to Russian gas and did nothing about it, even after the 2014 invasion of Crimea. Just as the west knew moving their entire manufacturing sector to one country would make them vulnerable, but choose to ignore it beca…
Germany had with under the best deal for gas possible with Russia, I don’t understand the sentiment calling it a vulnerability. There is still a working pipeline available and Russia stated clearly if would continue delivering gas, if Germany wants to.
You conveniently leave out that minor detail that it was RUSSIA who stopped the gas.
Germany tried hard to keep it going, even making a sanction-exemption or a Siemens turbine repaired in Canada, which according to Russia was needed. Only that when they were to receive it nothing happened, gas stopped anyway.