Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

621–630 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#621
post #590

I'm trying to steelman but I really can't think of a non- nefarious justification for this

It's a dying empire, really nothing else to say. The USA led world order is over, we've voted ourselves out of it, and now need to learn how to deal with that.

Wow! So who is leading the world order now (aka who is funding MITRE)?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#622

Earlier quoted context omitted.

Is there no connection between 2025 funding cuts and previous ones? e.g. If a year of work after the previous cuts resulted in an open-data collaboration between NVD and commercial vendors to share a subset of CC0 vulnerability metadata, could that industry collective now argue for government to share (with companies) the burden of funding an open, decentralized program for CVE tracking? Commercial vendors could stil…

I am now more confused and not less.

Apparently 2024 NVD funding cuts did motivate CVE contingency planning, https://www.thecvefoundation.org/

> A coalition of longtime, active CVE Board members have spent the past year developing a strategy to transition CVE to a dedicated, non-profit foundation. The new CVE Foundation will focus solely on continuing the mission of delivering high-quality vulnerability identification and maintaining the integrity and availability of CVE data for defenders worldwide. “CVE, as a cornerstone of the global cybersecurity ecosystem, is too important to be vulnerable itself,” said Kent Landfield, an officer of the Foundation.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#623
post #20

Earlier quoted context omitted.

> I'm trying to steelman Why? This administration is not acting in good faith, you don't have to act as if they are. People and institutions doing that is part of how we got here in the first place.

Force of habit. We don't have a framework for talking under these circumstances, so we apply our outdated ones. As you say, that's exactly what got us here. But the alternatives are very unclear, and seem deeply unpleasant.

People should suck it up and not do it again.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#624
FWIW, I've never understood why this sort of thing wasn't just directly handled by the NSA --- aren't they the group which should be tasked with cybersecurity?

I always suspected that "Department of Homeland Security" would lead to Banana-republic-like shenanigans --- could we defund them?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#625
post #424

To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.

This quote is essentially unworkable. Everything you say, or choose not to say, inevitably advances some political perspective over another. What we should really aim for is thoughtful, civilized, and maybe even aesthetically pleasing discourse. That’s what educated people strive for. Trying to “avoid politics” is like collecting seashells while a tsunami is rolling in.

It's scary how widely this varies between different communities. On Reddit, /r/politics is mostly people acting like they're auditioning for the writers' room on one of those late-night talk shows, whereas /r/ukpolitics and /r/australianpolitics are almost exclusively people making insightful, analytic comments.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#626

Earlier quoted context omitted.

They have the chance to step up now. Every Comercial company that is supposedly so reliant on this for their very existence has the opportunity today. They can fund it.

What commercial company is going to "fund" this? It's such a strange idea, disconnected from the real world. You may as well say "companies can start doing road maintenance, as they are so reliant on them for their very existence." And perhaps if there had been more than a days notice, some consortium could be pulled together, but who's going to pay? Why would private companies do this, how do they profit? CVE progra…

>but who's going to pay?

The EU. They can have all the massive advantages that funding MITRE will give them. Why won't they step up to the plate? It's killing the EU and they have absolutely no idea how anything works. It's why they're a dying empire.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#629

Earlier quoted context omitted.

Soon to be powned, by their own extreme short sightedness. Duh.

Maybe "they" want to do the pwning with less coordinated resistance. Doing away with CVEs would help with that objective.

No, they are not skilled enough to hack anything. These are just a bunch of average junior engineers with hubris.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#630
post #51

I wish this hadn't happened. I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do t…

> I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? This was not a carefully-weighed decision based on a cost-benefit analysis. This was a political order, consistent with the administration's policy of "cut everything, recklessly, indiscriminately."

There are many problems going on right now, but in terms of cuts this is one of the most problematic: everything is secret, with no oversight or deliberation. It's indistinguishable from corrupt malice because it's not done with open thoughtfulness.
Post reply on HN