Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

561–570 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#561

This makes me wonder what other stuff most people don't know exists but is important to our society has quietly disappeared in the last few weeks. We know about this one because we know it's important. What are the things we don't know about?

https://www.project2025.observer/ lists a few. Of course, those are only the agencies the Trump people know about and explicitly want to destroy, but it's a start.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#562

How much was this contract worth? If it was $5000/yr it's very different to if it's $5M/year for what amounts to little more than an instance of mediawiki.

$44M/year?

https://www.usaspending.gov/award/CONT_AWD_70RCSJ23FR0000015...

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#563

Earlier quoted context omitted.

When this is discussed, what's being meant is that everday party politics are spilling out and overwhelming a project's or industry's individual, internal politics, which are often a completely disconnected meta. Appealing to "well everything is connected" I'm not sure is useful. It's interesting from a semantics perspective the first few times you come across it maybe, then swaps around into being plain frustrating,…

> I think are doing a pretty big favor to their mental health, and It your mental health is harmed while defending your political views it's possible your views are the issue. For example if my view was that "domestic animals shouldn't be abused and penalties increased for such crimes" I wouldn't have mental health issues discussing this.

So if I now said some intentionally asinine garbage, e.g. about how dogs need to be disciplined, shown who the pack leader is, and sometimes that necessarily involves a beating, and how if you disagree you're woke, that wouldn't make you very understandably very distraught?

Because it would make me pretty distraught, and I don't think that it's because anything is wrong with the idea of not abusing animals.

Even doing this mental exercise for the sake of this conversation is already extremely frustrating for me. And I don't think this should surprise you, or is anything strange or unusual.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#564

I don't see why this should be publicly funded, so I don't really see an issue with this. The industry benefits from having a CVE database, so the industry should fund it.

So you trust industry now?

Same question would be for government funded agencies.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#565

I don't see why this should be publicly funded, so I don't really see an issue with this. The industry benefits from having a CVE database, so the industry should fund it.

The insane number of downvotes you’re getting for saying basic common sense stuff, it’s why we should push for stricter political rules here in HN. You didn’t say something wrong or controversial, just an opinion. Some ideologies love to pay things with other people’s wallets, and they’ll do whatever they can to pursue this.

Especially the L guy who downvoted this after 10 seconds. get a life

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#566
post #51

I wish this hadn't happened. I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do t…

> I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides?

The National Vulnerability Database has been unable to keep up with the flow of CVEs for over a year now:

- https://anchore.com/blog/national-vulnerability-database-opa...

- https://www.cyberreport.io/news/cve-backlog-update-the-nvd-s...

- https://www.ibm.com/think/insights/cve-backlog-update-nvd-st...

- and many, many, many others

It has been a complete disaster for months. At this point, perhaps the thinking is to radically change approaches?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#567
post #52

Earlier quoted context omitted.

and then a random 9.8 critical comes that affects some software you have in a way that makes it a 0 in your environment but it doesn't matter cause the cve tanks your organizational Security Score (tm) by 10 arbitrary points and management is wondering when you'll secure the company again because the Security Score is their only tangible deliverable to measure success

Yeah like when we bundled in a .js library for client side date processing that has a CVE affecting node.js servers with high score. Our auditors don’t care they tag the whole app as high risk. It doesn’t even run on the server!

Incompetent auditors don't detract from the classification system, though. If we removed every data point auditors misinterpret or don't care to understand, we may as well remove all metrics.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#569

Earlier quoted context omitted.

When this is discussed, what's being meant is that everday party politics are spilling out and overwhelming a project's or industry's individual, internal politics, which are often a completely disconnected meta. Appealing to "well everything is connected" I'm not sure is useful. It's interesting from a semantics perspective the first few times you come across it maybe, then swaps around into being plain frustrating,…

Two things: "Party politics" is ill-defined, and so a "no politics" rule becomes an arbitrary hammer that bosses can use to smash employees. If I say "I'm going to get a COVID vaccine this afternoon" is that discussing party politics? In the UK, where I live, the vaccine was provided by the government, so I'm implicitly discussing the actions of the government. That is under any reasonable definition a discussion of…

There's no way to define any modality of politics such that someone like you won't come around and start going off about how it's a leaky segmentation, and is actually just an excuse for censorship.

Every artificial segmentation of the real world is leaky. Just like the recognition that politics is everywhere, this too is not actually inquisitive. It's like arguing that stairsteps are chairs. They can be, but that doesn't make the word "chair" ill-defined.

> but this was not what happened in the poster child cases of implementing "no politics" rules

There is no such thing. These may be notable cases in your cohort, for me it's the first time I heard of these. And I've seen my fair share of these rules.

Post reply on HN