Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

511–520 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#511

The real irony here is that a lot of ycombinator founders and the people reading HN were exactly the ones making this possible and now start to wonder why the snake eats its own tail.

The missing funding is something like 2 million dollars. Any US company could make this issue go away in an instant.

Its not a money problem, its a understanding problem.

Shouldn't the most powerful country has something like this? Being even in the forefront of it?

The USA was doing cyberprotection against Russia and cyberattacks across the world.

Now suddenly it doesn't need it anymore?

Like just did Russia go away (or has russia won and sits now in the white house)?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#512

I'm trying to steelman but I really can't think of a non- nefarious justification for this

Reduce government spending; since it's not actually a government organization (as far as I can tell, I never looked into it before), other organizations can fund it. How much goes into this organization a year anyway? I'm seeing a Mitre corporation that does lots of other stuff too that has a revenue of 2.2 billion a year. Multi-trillion-dollar companies benefit from and contribute to this system, surely they can spa…

MITRE is a non-profit, it receives about $1.5B from the federal government, and another almost $2B from Virginia.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#513

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

The European, GDPR compliant subnet of the Internet Computer could suit your needs. The app would be decentralized out of the box and it can't be shut down by a single entity like a traditional cloud provider or nation state. Hosting 100GB costs about 500$ per year [0]. This is not a traditional hosting provider, it's a decentralized cloud. Reach out on the forum [1] or to me if this sounds like a good fit to you (I…

Or just use a normal host where hosting 100GB costs about $60.00 per year.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#514

Earlier quoted context omitted.

> I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? This was not a carefully-weighed decision based on a cost-benefit analysis. This was a political order, consistent with the administration's policy of "cut everything, recklessly, indiscriminately."

> cut everything, recklessly, indiscriminately Mostly discriminately, tbh.

[flagged]

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#515
post #76

Earlier quoted context omitted.

The scores were never going to be that accurate across people's environments (IDK how much other places relied on them, places I worked never did that much) and issues with the scores don't seem to be a good justification to torch the whole CVE system anyway.

Why isn't it a good justification? I think the question everyone in this thread should ask is: why is it the government's job to do this, especially given the prior widespread view that they're doing a bad job? Is the software industry so immiserated by poverty that it cannot organize its own distribution of security bulletins? Clearly not: GitHub already runs its own vuln tracking scheme that's better integrated wit…

> why is it the government's job to do this?

Because the private sector can't see past their profit motive to the national defense motive.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#516

Earlier quoted context omitted.

>They've been aware of the risk of relying on the US for software security for years, but AFAIK there have been no efforts to do anything about it. Indeed. Just as Germany knew their economy is vulnerable to Russian gas and did nothing about it, even after the 2014 invasion of Crimea. Just as the west knew moving their entire manufacturing sector to one country would make them vulnerable, but choose to ignore it beca…

Germany had with under the best deal for gas possible with Russia, I don’t understand the sentiment calling it a vulnerability. There is still a working pipeline available and Russia stated clearly if would continue delivering gas, if Germany wants to.

NordStream 1 had been stopped from Russian side for nearly 4 months before this, with constantly shifting goal post excuses.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#517
post #400

Earlier quoted context omitted.

A lot was lost in the midterms and Supreme Court appointments. Hopefully these 4 years energize people to vote. I know protesting and direct action and so on are also important, but the gradient is not negative for voting for every office you can vote for in every election.

I fear the situation either ends badly or in a bloodshed. They aren't respecting the courts, so assuming they will accept defeat in elections is naive.

Maybe that's the only way that people can learn.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#518

Earlier quoted context omitted.

One of the benefits a working democracy conveys to its citizens is that they largely don't have to care about politics. They can trust that government action is relatively consistent over time, that laws will be enforced fairly enough, that their property will be protected to a reasonable degree, that the currency will be reasonably stable, that the roads will be maintained, that some public transport will be availab…

Interestingly, I believe that the reality is exactly the opposite: on the political regimes' spectrum of democratic -> authoritarian -> totalitarian only the middle one doesn't require people's participation. Both democracy and totalitarism need to be actively maintained by significant part of the population, otherwise they converge to the "natural" state of things - authoritarian order. None of the stuff you listed…

Yeah, I should have phrased this better. When I said that

>citizens (...) largely don't have to care about politics

I didn't mean that it wasn't harmful if they didn't care; I meant that there was no clear, immediate incentive.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#519

Earlier quoted context omitted.

>They've been aware of the risk of relying on the US for software security for years, but AFAIK there have been no efforts to do anything about it. Indeed. Just as Germany knew their economy is vulnerable to Russian gas and did nothing about it, even after the 2014 invasion of Crimea. Just as the west knew moving their entire manufacturing sector to one country would make them vulnerable, but choose to ignore it beca…

> I never EVER saw politicians act proactively for the good of the nation or the people, This is almost certainly because those cases don't make the news.

Yup.

Politicians react to the public when it stands up. Otherwise it will follow other agenda's.

That is why it is critical to have an informed public. When journalism has to compete with corporate owned Fake News and Entertainment, journalism dies, and democracy will follow. Then, add the spy business of Big Tech in the mix, with algorithmic silo's. The people don't even realize they are locked up in a jar, where they live on a diet of cultural engineering.

Now, pause a moment and think about what happens when you add AI-models to the mix. Your daughter, your neighbor will be totally brain-wrecked.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#520
post #331
post #295

Earlier quoted context omitted.

This would be hilarious. That would be a good thumb in the eye to the current administration who complained long and loud about how Obama let ICANN leave US possession. Just imagine the campaign commercials in 2026, >The POTUS transferred our cyber defenses to the EU Ouch

Well, that's kind of the point? The current administration doesn't care about cyber defense, any less than it cares about protecting the environment, protecting consumers, having top-notch universities and research, foreign aid etc. etc. Actually, it takes pride in not caring about all of these things.

> The current administration doesn't care about cyber defense, any less than it cares about protecting the environment

On the contrary, I would argue that they deeply care about the environment. The REAL point of all those tit-for-tat tariffs with China including with small mail/packages are to drastically cut cargo/shipping emissions. The threatening of annexation of Canada? That was really to get ~70% reduction in air passenger traffic BECAUSE they care about the environment. Same with creating a few high profile border horror story incidents against nationals from allied countries. The real point of it? Reduce transoceanic air passenger loads and save the environment. /s

Post reply on HN