If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…
Honest question: Does this not already exist? - https://vulnerability.circl.lu/ - https://osv.dev/ - https://vuldb.com/ And a few others?
CVE program faces swift end after DHS fails to renew contract [updated]
481–490 of 1001 posts
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#482Earlier quoted context omitted.
The EU should just buy MITRE. Move it to the EU and make it a EU based project.
This should be work for the ENISA: https://www.enisa.europa.eu/ https://www.enisa.europa.eu/topics/vulnerability-disclosure They have a tender going on tracking best practices: https://www.enisa.europa.eu/procurement/vulnerability-disclo... So they will take 12 months to select for the tender...18 months pondering on the report...and in 3 years they make a tender out for a solution...
looking at average speed of bureaucracy in EU it will take roughly a year to set date for a meeting that will set the date for actual meeting which will decide if this will go forward or not....
(if you think i'm joking - i'm basing this on proposed EU initiative for nuclear power which started with setting a date of meeting to setup a meeting to draft an agenda)
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#483The latest contract[1] (I hope this is the right one) for MITRE's involvement with CVE and CWE programs was USD$29.1m for the period 2024-04-17 to 2025-04-16 with optional extension of expenditure up to USD$57.8m and to an end date of 2026-04-16. Seemingly MITRE hasn't been advised yet whether the option to extend the contract from 2025-04-16 to 2026-04-16 will be executed. And there doesn't appear to be any other pu…
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#484Earlier quoted context omitted.
When this is discussed, what's being meant is that everday party politics are spilling out and overwhelming a project's or industry's individual, internal politics, which are often a completely disconnected meta. Appealing to "well everything is connected" I'm not sure is useful. It's interesting from a semantics perspective the first few times you come across it maybe, then swaps around into being plain frustrating,…
Two things: "Party politics" is ill-defined, and so a "no politics" rule becomes an arbitrary hammer that bosses can use to smash employees. If I say "I'm going to get a COVID vaccine this afternoon" is that discussing party politics? In the UK, where I live, the vaccine was provided by the government, so I'm implicitly discussing the actions of the government. That is under any reasonable definition a discussion of…
It is also illustrates the problem with discussing politics in an international forum. The KCL study of covid conspiracy theories (carried out during the pandemic) found that in the UK young people and those who identified as left wing were more likely to believe conspiracy theories. I am pretty sure this is significantly different from the US. Also matches things I have heard (e.g. my daughter met people at university who refused the vaccine because "we don't trust the Tories".
It is pretty common for Americans to assume that the Conservatives are equivalent to Republicans, and Labour are like the Democrats, which is very far from the truth. It has always been far from the truth but the reasons why change - e.g. in the 80s Thatcher and Reagan were not far apart, but that that time Labour were far to the left of the Democrats (actual socialists).
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#485To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.
It's not that the political topics are unimportant but all my feeds just end up looking the same as each other and the same as a newspaper app. I hate election nights because of this.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#486If it was $5000/yr it's very different to if it's $5M/year for what amounts to little more than an instance of mediawiki.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#487So who will maintain it then? Either the EU or China I suppose. They can easily fund it. Maybe the Dutch should go ahead.
ENISA in Europe has the mandate of building a EU vulnerability database for the NIS 2 directive anyway and it's coming soon... And CIRCL in Luxembourg are providing vulnerability-lookup which can also assign IDs but in a more decentralized way: https://www.vulnerability-lookup.org/documentation/ VulnerableCode can help with discovery etc. https://vulnerablecode.readthedocs.io/en/latest/introduction... So, parts of th…
Do we already have an ETA for the ENISA vulnerability database?
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#488Earlier quoted context omitted.
I find it a little incredible people are still talking about "four years". They tried to reject the election result and do a coup, and were rewarded for it by getting back into power. They are refusing to follow the law or the courts. They are sending people to gulags in foreign countries. All the checks and balances were destroyed last time. The party has been stripped of anyone who would fight the admin or reject t…
Organizing mass protests isn't something you do instead of organizing electoral opposition. Even in countries that haven't had fair elections for a while, people generally still organize opposition and talk about how they're going to vote. The best way to ensure your opponents retain power is to go around telling people it's too late and they've already won.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#489Earlier quoted context omitted.
As an active consumer of CVEs: yea there are major problems. No there's nothing better and no I don't have any better ideas. The scores are mostly useless, I would not care if they disappeared, I do not look at them. I don't really understand why people get so upset about garbage scores though. If a high CVSS score creates a bunch of work for you then your vuln mag process is broken IMO. (Or alternatively, you are in…
> you are in the business of compliance rather than security. So, most businesses. They all need their ISO/NIST/HIPAA/etc certs.
If you're working in compliance either
A) you're stuck in your compliance job, that sucks, CVSS scores aren't the reason why though.
B) you enjoy compliance.
C) you should change jobs.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#490It’s a reckless move to cut funding so abruptly, but taking a step back from the short-term chaos, it probably is an anomaly that this was government funded. All of private tech relies on it, and private tech is big enough to pay for it. I hope that the trillion dollar babies consider this an opportunity to pool together to form a foundation that funds this, and a bunch of other open source projects run by one random…