Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

571–580 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#571
post #481

Earlier quoted context omitted.

Honest question: Does this not already exist? - https://vulnerability.circl.lu/ - https://osv.dev/ - https://vuldb.com/ And a few others?

https://www.enisa.europa.eu/news/another-step-forward-toward...

> https://euvd.enisa.europa.eu/

They already did it. Great!

Maybe we can ask them how to contribute to their software, as it seems to be proprietary at the moment?

edit: lol, their manifest.json is still the React boilerplate: https://euvd.enisa.europa.eu/manifest.json

Their database seems to also only contain fairly recent CVEs (up until 2019? some CVEs are missing...) and not before that

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#572
post #449

Earlier quoted context omitted.

Apart from the few maniacs On Here who seek out the unregulated intentionally. Raw milk (all those tasty diseases). "Research chemicals" (don't hear so much about that lately, but there were whole microdosing fads).

Raw milk is delicious, my ancestors have been drinking it for millennia.

And we enjoyed our milkborne tuberculosis, typhoid, scarlet fever, diphtheria, and septic sore throat thoroughly, too. The risks actually doubled the joys. Why does a supposedly enlightened society step all over my right to choose which eliminated diseases to bring back?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#573
post #445

Earlier quoted context omitted.

you've slept just 3 hours? Go back to bed..

Maybe just a toilet break (see the bio): > Fun fact: All my comments have been written on the toilet. I don't use social media anywhere else.

Taking TDD to a level it’s never been before

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#574

Long term its probably good to have a less US-centric world.

This is a chance for the EU to step up and take over. If the US government won't pay for the CVE program, the EU surely could. Many EU countries already run a program like this to server their own interests, and I believe the EU does as well.

If the US is willing to give up influence and control over the cybersecurity sector, we should accept that gift and use it to our advantage.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#575

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

Why EU? Canada may be another friendly option

[deleted]

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#576
post #403

The latest contract[1] (I hope this is the right one) for MITRE's involvement with CVE and CWE programs was USD$29.1m for the period 2024-04-17 to 2025-04-16 with optional extension of expenditure up to USD$57.8m and to an end date of 2026-04-16. Seemingly MITRE hasn't been advised yet whether the option to extend the contract from 2025-04-16 to 2026-04-16 will be executed. And there doesn't appear to be any other pu…

[dead]

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#577

I'm surprised that it was USA's responsibility to fund this in the first place. Why weren't other countries providing funds?

It's called providing leadership. Worth the money. China will happily fill the void.

I hate this whole disaster but why can't Europe step in for stuff like this?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#578

I'm surprised that it was USA's responsibility to fund this in the first place. Why weren't other countries providing funds?

It's a program the US government spun up to serve America's interests. Why would someone else pay for American interests?

Other countries have their own programs, some cooperating with the US, others separate. China has the CNNVD if you're interested in helping Chinese society safe. My government operates https://advisories.ncsc.nl/advisories to serve my country's interests.

Of course, the US is free to abandon their programme and rely on Chinese, Russian, and European vulnerability databases to keep their country safe. It does save them a couple of million after all!

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#579

The real irony here is that a lot of ycombinator founders and the people reading HN were exactly the ones making this possible and now start to wonder why the snake eats its own tail.

Or they wanted this, because this could be part of the privatization of many government functions. They, or at least some of them, could see this as controlling this function for money. It's a regular stream too, the valuable subscription model and customers who really need the service (and if they don't, just add a new law in the name of IT security forcing firms to sign up).

To me it looks too chaotic to be a planned privatization plan but who knows.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#580
post #449

Earlier quoted context omitted.

Apart from the few maniacs On Here who seek out the unregulated intentionally. Raw milk (all those tasty diseases). "Research chemicals" (don't hear so much about that lately, but there were whole microdosing fads).

Raw milk is delicious, my ancestors have been drinking it for millennia.

Isn't this literally survivorship bias? Those who died early wouldn't have had offspring.

1 - https://en.wikipedia.org/wiki/Survivorship_bias

Post reply on HN