Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

491–500 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#491
post #356

Earlier quoted context omitted.

> Not only that, but being owned by the EU gives the ability for MITRE employees to have the option to immigrate to the EU to protect against any retaliation. According to which rule would "owning by the EU" result in an option to immigrate? Immigration is handled on a per country basis. I don't see how the EU provide such an option.

https://eur-lex.europa.eu/eli/dir/2009/50/oj The EU has agreed upon programs in order to bring in, through an immigration policy, high skilled persons from non-member states. More importantly, working within the member nations, as to which member nation would want MITRE to be located within their borders, is not something that is a hard sell given that it has economic advantages for whichever state(s) onboard MITRE.

That still leaves decisions on who to admit to states. As far as I can see its main effect is to allow people admitted to one country as highly skilled to travel to (not live in) other countries?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#492
post #379

Earlier quoted context omitted.

Everything is political now by design. It's meant to reach into every facet of society and community and restructure it.

That's because we got reliant on the funds from government. Maybe it's time to break the dependency.

> That's because we got reliant on the funds from government

Not we, some people got reliant on the funds from government. It is always at the cost of someone else. The tax the rich and bourgeoisie mentality is what led to Mao Zedong and Stalin, but no-one wants to learn about history anymore.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#493
post #472

Earlier quoted context omitted.

This should be work for the ENISA: https://www.enisa.europa.eu/ https://www.enisa.europa.eu/topics/vulnerability-disclosure They have a tender going on tracking best practices: https://www.enisa.europa.eu/procurement/vulnerability-disclo... So they will take 12 months to select for the tender...18 months pondering on the report...and in 3 years they make a tender out for a solution...

oh but you forgot the mandatory time before they even start considering the tender. looking at average speed of bureaucracy in EU it will take roughly a year to set date for a meeting that will set the date for actual meeting which will decide if this will go forward or not.... (if you think i'm joking - i'm basing this on proposed EU initiative for nuclear power which started with setting a date of meeting to setup…

100% - I wonder if this is partly by design.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#494
post #25

Mr. President, Do you want China to get the reports instead, or do you want the NSA to have a lead time where the vuln's are useful tools?

If you /s/China/Russia/, when asking Trump, it’s no longer a rhetorical question.

For those reading, a fair few of my recent posts were downvoted after this comment, and it was initially flagged.

If I violated some rule so be it, and I could care less about internet points, but it certainly feels like suppression of individuals based on individual posts which is a behaviour that could end up being the death of hn.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#495
post #445

Earlier quoted context omitted.

OSV is made by Google/Alphabet and therefore also prone to Trump intervention (see Gulf of Mexico executive order). The circl.lu might be actually a potential cooperation partner. (Vuldb is down right now)

you've slept just 3 hours? Go back to bed..

hmm? it's already daytime in Europe where he's located

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#496
post #75

Earlier quoted context omitted.

Destroy, destroy, destroy. Promise to rebuild but don't. Take it all.

So much for the wunderkinds in DOGE.

They were able to eliminate all open CVE's while cutting costs at the same time. Amazing!

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#497

To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.

Apolitical person: Ugh politics is so dumb

Same person: Why is the world organized in such a dumb way?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#498
post #481

Earlier quoted context omitted.

Honest question: Does this not already exist? - https://vulnerability.circl.lu/ - https://osv.dev/ - https://vuldb.com/ And a few others?

https://www.enisa.europa.eu/news/another-step-forward-toward...

Other authorities: https://www.cve.org/programorganization/cnas

The CVE program is really important. This Administration is truly the example of the D.O.G.E. - Department Of Gaffes and Errors

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#499

The real irony here is that a lot of ycombinator founders and the people reading HN were exactly the ones making this possible and now start to wonder why the snake eats its own tail.

Or they wanted this, because this could be part of the privatization of many government functions. They, or at least some of them, could see this as controlling this function for money. It's a regular stream too, the valuable subscription model and customers who really need the service (and if they don't, just add a new law in the name of IT security forcing firms to sign up).
Post reply on HN