Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

501–510 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#501

Earlier quoted context omitted.

Depends. We’re a small, very international startup and have a super strict “no politics” policy. Politics and work are not a good combination when you’re employing people from all over the world. But I would not consider it a political statement to adopt this policy.

First, “no politics” is not a political statement to me, more of an implicitly adopted political position. Personally, if I have a personal political position and my colleague has an opposite one, I don’t see why we can’t talk about it. If you have a workplace rule about no politics during working hours, you better have this rule for all non-work discussions at work, or I personally would feel uncomfortable. — If pol…

Are you from the US? In the last 15 years it has become impossible for two people to reasonably disagree over political positions because of how much vitriol is thrown around on the attention markets—even if both individuals themselves are rather tame. When having an otherwise normal political opinion makes you a racist bigot or a beta cuck because the opposition is so determined to get their way at any cost, no, you can’t just talk politics at work and have a cohesive team. Someone will feel oppressed.

Work is about making money. Politics is a distraction unless there’s an issue that directly affects the business. Then it’s fair game. Like this one. Many teams of individuals will have to figure out how to navigate this situation so discussing it in context is apropos and can be done objectively.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#502
post #472

Earlier quoted context omitted.

This should be work for the ENISA: https://www.enisa.europa.eu/ https://www.enisa.europa.eu/topics/vulnerability-disclosure They have a tender going on tracking best practices: https://www.enisa.europa.eu/procurement/vulnerability-disclo... So they will take 12 months to select for the tender...18 months pondering on the report...and in 3 years they make a tender out for a solution...

oh but you forgot the mandatory time before they even start considering the tender. looking at average speed of bureaucracy in EU it will take roughly a year to set date for a meeting that will set the date for actual meeting which will decide if this will go forward or not.... (if you think i'm joking - i'm basing this on proposed EU initiative for nuclear power which started with setting a date of meeting to setup…

Sir Humphrey ran that meeting if I recall correctly

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#503
post #7

Earlier quoted context omitted.

[flagged]

Thanks for volunteering to manage the "300-600 CVEs each month"! The world needs more volunteers like you.

I imagine most of those CVEs not being anything meaningful and just script kiddies trying to put something on their portfolio

all the meaningful ones will show up on HN

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#504

Earlier quoted context omitted.

If you made this careful analysis, you'd hear "CRISSAKE WE NEED THIS DONT TOUCH IT" for almost everything (and it likely would be right for a significant portion but not everything). That's why the current approach seems to be to axe everything, listen to how much screaming there is, then reinstate only the projects where the screaming is really loud.

So the dumbest way to do anything. Got it.

Please read Isaacson biography of Musk.

The "Musk algorithm" is described in detail, and can be summed up as a "reverse Chesterton's fence"

"If you are not forced to reinstitute 10% of the rules you slashed, you have not slashed enough".

What happens while the 10% are slashed is left as an exercise to the voter.

Hopefully, the cve db will be deemed part of the 10%.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#505

Earlier quoted context omitted.

People trying to ignore politics are like fish trying to ignore water.

Not talking about politics is itself a political position (in favor of status quo).

No it’s not. It’s having discipline to not pollute unrelated conversations with your politics. I am very against the status quo but I don’t complain about it to a bunch of anonymous usernames on a forum focused on technology.

You can believe something without proselytizing.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#506
post #373

It’s a reckless move to cut funding so abruptly, but taking a step back from the short-term chaos, it probably is an anomaly that this was government funded. All of private tech relies on it, and private tech is big enough to pay for it. I hope that the trillion dollar babies consider this an opportunity to pool together to form a foundation that funds this, and a bunch of other open source projects run by one random…

> it probably is an anomaly that this was government funded. All of private tech relies on it, and private tech is big enough to pay for it.

I mean doesn't big tech and the people they give salary money to pay taxes? Ground transportation companies rely on public roads and but we fund it because having the infrastructure is an economic multiplier.

I'm not arguing in favor of funding the CVE program, I just don't think that's a good reason.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#507

Trump stupidity hurts the country and world. But maybe this is an opportunity to do CVE better.

> But maybe this is an opportunity to do CVE better. Okay, how? This sounds like looking for lemonade in a genocide.

> This sounds like looking for lemonade in a genocide.

It really doesn't. This level of catastrophising has no point. It would be nice if CVE continued to exist, but it wasn't close to perfect, and perhaps it can continue in another form. There's no particular reason the US taxpayer has to sponsor global security threat tracking any more than any other taxpayer or customer.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#508

Earlier quoted context omitted.

Everything was always political. Laws, the economy, conflcit. How is any person not affected by these? The government is responsible for all or a large part of how a country functions. People who say "I'm not political" are deflecting to avoid conflict

> People who say "I'm not political" are deflecting to avoid conflict A great truth. Even isolating yourself from society like a hermit is still a political decision: you are rejecting society as it is, and prefer to live in your own solo society. That's politics.

I don’t think that’s totally accurate. If I live as a hermit but perform my civic duties like voting and paying any taxes, I don’t see how choosing to live in solitude is anything more than a lifestyle choice.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#509

Earlier quoted context omitted.

Not talking about politics is itself a political position (in favor of status quo).

No it’s not. It’s having discipline to not pollute unrelated conversations with your politics. I am very against the status quo but I don’t complain about it to a bunch of anonymous usernames on a forum focused on technology. You can believe something without proselytizing.

Things are often inherently political.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#510

To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.

To play devil's advocate - it's horrible when gaming, programming, business or even porn forums get overrun by politics. It's not that the political topics are unimportant but all my feeds just end up looking the same as each other and the same as a newspaper app. I hate election nights because of this.

[flagged]
Post reply on HN