Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

611–620 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#611
post #387

To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.

HN and founders will say "no politics here" on the regulated internet, drinking regulated water, eating regulated food, breathing regulated air.

> regulated ...

not for long

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#612
post #409

To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.

I view the archive.org, Wikipedia, CVE program, and Linux Kernel to all have had discussions on HN about how to they should be funded. Is that kind of politics the kind that people wish that HN stayed out from?

No, but the "everything is political" people are not capable of making that distinction. Which is probably why everything seems political to them.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#613
post #483
post #403

The latest contract[1] (I hope this is the right one) for MITRE's involvement with CVE and CWE programs was USD$29.1m for the period 2024-04-17 to 2025-04-16 with optional extension of expenditure up to USD$57.8m and to an end date of 2026-04-16. Seemingly MITRE hasn't been advised yet whether the option to extend the contract from 2025-04-16 to 2026-04-16 will be executed. And there doesn't appear to be any other pu…

I can't figure out why the hue and cry wasn't raised until the very last minute. Did they not know a month ago that they were running out of time? Is it standard practice for the government not to say they're going to extend the contract until the day beforehand or something?

Right now, yes. You can pretty easily have a scenario where you’re talking to the agency you’re working with and they’re saying “we want to renew this, but we don’t know if they’ll give us the money in the end”.

So you’ll get a bunch of “hopefully this week” up until it expires.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#614

Earlier quoted context omitted.

No it’s not. It’s having discipline to not pollute unrelated conversations with your politics. I am very against the status quo but I don’t complain about it to a bunch of anonymous usernames on a forum focused on technology. You can believe something without proselytizing.

Technology and the consequences of using technology are inherently highly political. New or improved technologies shape communities. Ignoring that is a political statement as well. Just see how online media has changed discourse, how Amazon changed retail business, how business analytics change the way businesses work, how always being connected changes relations, ... When developing technologies one can be Wernher v…

>Technology and the consequences of using technology are inherently highly political.

So what stance does The Art of Computer Programming take on communism?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#615

Earlier quoted context omitted.

People trying to ignore politics are like fish trying to ignore water.

Not talking about politics is itself a political position (in favor of status quo).

Incorrect, not talking about politics does not signal any political affiliation.

I think the "everything is political" statement is technically correct but practically useless. In the workplace the discussion is mostly about allowing or disallowing politics that are irrelevant to the business.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#616

Earlier quoted context omitted.

It's a near certitude that Russia and China each have databases of exploitable software errors and prize zero days. It was to the advantage of the US and allies to coordinate and lead in tracking and fixing such errors. Multiple countries, companies, and individuals contributed finding and fixing bugs. The administrative task of keeping track was one part of a greater picture, a part that came with first to be advise…

> It was to the advantage of the US and allies to coordinate and lead in tracking and fixing such errors. From what I understand of the article, none of these allies were funding it. > Multiple countries, companies, and individuals contributed finding and fixing bugs. Clearly that itself isn't enough. Someone has to pay for maintaining this service. It appears that no one other than USA spent money in funding it.

Almost every other western country does fund their own databases, CVE was just significant because its the one central source of truth. its like a standard. Instead of having to coordinate with dozens of different registries every time you publish a vulnerability you just communicate with one instead.

Researchers also don't directly talk with MITRE they go through one of the intermediaries that assigns the number.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#617

Earlier quoted context omitted.

The missing funding is something like 2 million dollars. Any US company could make this issue go away in an instant.

Its not a money problem, its a understanding problem. Shouldn't the most powerful country has something like this? Being even in the forefront of it? The USA was doing cyberprotection against Russia and cyberattacks across the world. Now suddenly it doesn't need it anymore? Like just did Russia go away (or has russia won and sits now in the white house)?

You're right.

I don't understand why the EU wasn't funding it and isn't funding it now. I thought they're united against Russia?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#619

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

Some cnas may also submit. Is this something you are open to?
Post reply on HN