Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

541–550 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#541

To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.

To play devil's advocate - it's horrible when gaming, programming, business or even porn forums get overrun by politics. It's not that the political topics are unimportant but all my feeds just end up looking the same as each other and the same as a newspaper app. I hate election nights because of this.

"porn forums" is a thing?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#543

To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.

100% agree, staying out of politics has been a luxury not everyone has, it's totally unavoidable now.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#544

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

Looks like some people are already getting things moving: https://www.thecvefoundation.org/

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#545
post #536
post #476

> A coalition of CVE Board members launched a new CVE Foundation "to ensure the long-term viability, stability, and independence of the Common Vulnerabilities and Exposures (CVE) Program." > https://www.thecvefoundation.org https://mastodon.social/@serghei/114346660986059236

So if the govt stops paying them they'll continue to do the work for free?

More likely they will seek funding from companies and other organizations, as every other foundation/consortium of this kind does.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#546
post #388

Earlier quoted context omitted.

I don't think the EU has any interest in this. They've been aware of the risk of relying on the US for software security for years, but AFAIK there have been no efforts to do anything about it. Maybe the current situation will kick some butts into gear ... Off topic: your username is very appropriate given the situation.

>They've been aware of the risk of relying on the US for software security for years, but AFAIK there have been no efforts to do anything about it. Indeed. Just as Germany knew their economy is vulnerable to Russian gas and did nothing about it, even after the 2014 invasion of Crimea. Just as the west knew moving their entire manufacturing sector to one country would make them vulnerable, but choose to ignore it beca…

Perfect exmple of the "one-deep" conservative response.

PP is looking for a pattern, finding, and abstaining from questioning or contextualizing it:

Engaging only with the first or most obvious layer of an issue—never going deeper into context, nuance, or systemic causes.

The quickest counterexample that comes to mind is Elizabeth Warren's Consumer Financial Protection Bureau. It has returned billions to American citizens.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#547

Earlier quoted context omitted.

Germany had with under the best deal for gas possible with Russia, I don’t understand the sentiment calling it a vulnerability. There is still a working pipeline available and Russia stated clearly if would continue delivering gas, if Germany wants to.

Except what Russia states and what Russia does are only aligned when it serves Russia. Russia stopped delivering gas through NordStream 1. After that, Germany took note of the danger and decided it would do better without that dependency. https://www.aljazeera.com/economy/2022/9/2/russias-gazprom-k...

> Germany took note of the danger and decided it would do better without that dependency.

So they just swapped dependencies. And it's not that the new dependency will have no strings attached.

Diversifying while keeping russian energy in the loop, as part of a risk-management strategy, would make more sense. Completely cutting off russian energy just gives more bargaining power to their new energy provider.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#548

Earlier quoted context omitted.

Germany had with under the best deal for gas possible with Russia, I don’t understand the sentiment calling it a vulnerability. There is still a working pipeline available and Russia stated clearly if would continue delivering gas, if Germany wants to.

>I don’t understand the sentiment calling it a vulnerability - You're Germany. - You join NATO for protection from Russia, an actor with a long history of military aggression[1] - Your export economy is based on manufacturing. - The energy driving your manufacturing sector is ~60% cheap gas from Russia, your military aggressive partner. - Russia invades Georgia in 2008 and Ukraine in 2014 to no ones surprise - Leader…

Follow the money...

"German journalist dubbed the ‘Putin connoisseur’ had secret book deal with Russian oligarch" - https://www.icij.org/investigations/cyprus-confidential/germ...

"Russia's best friends in Germany: AfD and BSW" - https://www.dw.com/en/russias-best-friends-in-germany-afd-an...

"12 Germans who got played by Putin" - https://www.politico.eu/article/blame-germany-russia-policy/

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#550
post #536
post #476

> A coalition of CVE Board members launched a new CVE Foundation "to ensure the long-term viability, stability, and independence of the Common Vulnerabilities and Exposures (CVE) Program." > https://www.thecvefoundation.org https://mastodon.social/@serghei/114346660986059236

So if the govt stops paying them they'll continue to do the work for free?

The way their letter is worded it seems that they have a rainy day fund constituted to ride out the stormy next few week and I'm fairly certain they'll come back with more details as to how they'll be acquiring funding from now on in the next few days. Maybe paid access to an API, maybe donations from large companies that use the system, maybe something else ::shrug:: Hopefully a project as important as this doesn't just dissapear completely because of government pressure.
Post reply on HN