Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

471–480 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#471

Earlier quoted context omitted.

>They've been aware of the risk of relying on the US for software security for years, but AFAIK there have been no efforts to do anything about it. Indeed. Just as Germany knew their economy is vulnerable to Russian gas and did nothing about it, even after the 2014 invasion of Crimea. Just as the west knew moving their entire manufacturing sector to one country would make them vulnerable, but choose to ignore it beca…

Germany had with under the best deal for gas possible with Russia, I don’t understand the sentiment calling it a vulnerability. There is still a working pipeline available and Russia stated clearly if would continue delivering gas, if Germany wants to.

Except that Russia did not deliver (not any meaningful amount anyways), when the pipelines were still intact. And yes, they pretended to be willing, firing off a series of excuses sufficiently transparent to make it clear between the lines that it's a demonstration of power. Get your history straight: "Russia stated clearly if would continue" has between zero and negative value.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#472

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

The EU should just buy MITRE. Move it to the EU and make it a EU based project.

This should be work for the ENISA: https://www.enisa.europa.eu/

https://www.enisa.europa.eu/topics/vulnerability-disclosure

They have a tender going on tracking best practices: https://www.enisa.europa.eu/procurement/vulnerability-disclo...

So they will take 12 months to select for the tender...18 months pondering on the report...and in 3 years they make a tender out for a solution...

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#473

Earlier quoted context omitted.

Depends. We’re a small, very international startup and have a super strict “no politics” policy. Politics and work are not a good combination when you’re employing people from all over the world. But I would not consider it a political statement to adopt this policy.

Your statements are incoherent. Politics is decision making and power relationships within groups of people. It is 100% a political statement to adopt this policy as it exercises power over a group. You cannot function as a group without politics. "Where do y'all want to go for lunch" is also politics, as it involves group decision making and power relationships (Do you go to the vegetarian place? Do you avoid the sp…

The politics of saying "no politics" is that you are drawing some line that separates some political issues into "politics" and others into "not politics". Because to truly avoid all politics is impossible; even if you believe banal, purely intra-personal politics are not political so much of the basic organization of a business & capitalism are politics. "Should we allow remote work" for example is a deeply political question that ties deeply into discussions about the rights/value of neurodivergent & disabled people in the workplace. To say 'I don't believe in God' is a deeply political and dangerous statement in some parts of the world, but fairly banal where I live. To contrast, in Indonesia, it is technically _unconstitutional_ to not believe in a "one and almighty God"

I wish people were at least honest about "no politics" to mean "lets avoid to unsafe, potentially divisive issues relative to our geographic location, and take the basic tenets of neoliberal, capitalistic society to be assumed". And yeah, that is a more than reasonable policy. Its a difficult policy in international spaces, because its very hard to not trespass that line when political contexts differ so strongly across the globe

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#474
post #388

Earlier quoted context omitted.

The EU should just buy MITRE. Move it to the EU and make it a EU based project.

I don't think the EU has any interest in this. They've been aware of the risk of relying on the US for software security for years, but AFAIK there have been no efforts to do anything about it. Maybe the current situation will kick some butts into gear ... Off topic: your username is very appropriate given the situation.

https://www.enisa.europa.eu/topics/vulnerability-disclosure

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#475
post #387

To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.

HN and founders will say "no politics here" on the regulated internet, drinking regulated water, eating regulated food, breathing regulated air.

Will all of these things be free of micro plastics and other contaminants?

If so, is there a signup page?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#476
> A coalition of CVE Board members launched a new CVE Foundation "to ensure the long-term viability, stability, and independence of the Common Vulnerabilities and Exposures (CVE) Program."

> https://www.thecvefoundation.org

https://mastodon.social/@serghei/114346660986059236

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#477

Earlier quoted context omitted.

One of the benefits a working democracy conveys to its citizens is that they largely don't have to care about politics. They can trust that government action is relatively consistent over time, that laws will be enforced fairly enough, that their property will be protected to a reasonable degree, that the currency will be reasonably stable, that the roads will be maintained, that some public transport will be availab…

>One of the benefits a working democracy conveys to its citizens is that they largely don't have to care about politics The citizens elect the government so how can you not care about poltiics?

>The citizens elect the government so how can you not care about poltiics?

I don't think there's a direct correlation between the ability to vote and caring about politics. People usually care about politics when it affects them negatively. I would guess that most people in most democratic systems don't have strong negative experiences with their governments and, thus, are not incentivized to care about politics.

Note that I'm not making an argument that they should not care. I think they should, but the very system that allows participation probably also decreases the incentive for most people to participate.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#478

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

I would email someone like Patch My PC they seem good stewards of stuff open source from my vague looking and they are good people. They may just host a clone of it that's open.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#479

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

Why EU?

Canada may be another friendly option

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#480

Earlier quoted context omitted.

>They've been aware of the risk of relying on the US for software security for years, but AFAIK there have been no efforts to do anything about it. Indeed. Just as Germany knew their economy is vulnerable to Russian gas and did nothing about it, even after the 2014 invasion of Crimea. Just as the west knew moving their entire manufacturing sector to one country would make them vulnerable, but choose to ignore it beca…

Germany had with under the best deal for gas possible with Russia, I don’t understand the sentiment calling it a vulnerability. There is still a working pipeline available and Russia stated clearly if would continue delivering gas, if Germany wants to.

> There is still a working pipeline available and Russia stated clearly if would continue delivering gas, if Germany wants to.

You conveniently leave out that minor detail that it was RUSSIA who stopped the gas.

Germany tried hard to keep it going, even making a sanction-exemption or a Siemens turbine repaired in Canada, which according to Russia was needed. Only that when they were to receive it nothing happened, gas stopped anyway.

Post reply on HN