Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

631–640 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#631

vibe coding could not have come at a worse moment.

I see this as the perfect moment to get into consulting - either development, or security. People were not sure what jobs AI will create: "GenAI babysitting" is one of them.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#632

Earlier quoted context omitted.

> cut everything, recklessly, indiscriminately Mostly discriminately, tbh.

[flagged]

I can't tell what argument you're making within the context of my post?

The OP said indiscriminately, which means they're cutting uniformly across the board. I responded with "mostly discriminately" which means they're more selectively cutting based on prejudice. You then linked me a data point where you show they cut funding because it has the word "homo" in it and tell me to "get a hold of myself".. but your link would directly support what I've said?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#633

Earlier quoted context omitted.

Everything was always political. Laws, the economy, conflcit. How is any person not affected by these? The government is responsible for all or a large part of how a country functions. People who say "I'm not political" are deflecting to avoid conflict

One of the benefits a working democracy conveys to its citizens is that they largely don't have to care about politics. They can trust that government action is relatively consistent over time, that laws will be enforced fairly enough, that their property will be protected to a reasonable degree, that the currency will be reasonably stable, that the roads will be maintained, that some public transport will be availab…

And yet the Republicans have campaigned on tearing down government for my entire life. And people treated me like a fool for believing them.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#634

FWIW, I've never understood why this sort of thing wasn't just directly handled by the NSA --- aren't they the group which should be tasked with cybersecurity? I always suspected that "Department of Homeland Security" would lead to Banana-republic-like shenanigans --- could we defund them?

I don’t think anyone trusts the NSA to run a program like this.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#635

Earlier quoted context omitted.

Basically when any software/library/whatever has a vulnerability, they have to communicate that out themselves, in some format. If I'm developing a product built on 20 libraries, it won't just be a matter of scanning CVEs for major vulnerabilities any more, so I'm more likely to miss one. "always update" doesn't always work, when to manage a product you realistically have to version pin.

They surprise is: they won't. This will weaken the West. This is dangerously stupid.

This is deliberate. I just want to figure out the avenues of communication and coordination between trump admin and moscow so we can pin them down better.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#636

Earlier quoted context omitted.

PyPy's logo is a snake eating its tail.

Cool thanks!

Sorry and thanks GP. ;o)

Your nerd card had been validated for today. Go forth, ethically.* :D

* Oops, I introduced 2 more programming languages, my bad.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#637

Earlier quoted context omitted.

I can't believe what a bunch of bollocks this administration is. I couldn't believe it the first time, and this time I thought "Well at least I'm ready, it will be a lot like last time" and it's so much worse

> it will be a lot like last time A lot of people seemed to have had this theory, despite all the evidence to the contrary.

[deleted]

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#638
post #483
post #403

The latest contract[1] (I hope this is the right one) for MITRE's involvement with CVE and CWE programs was USD$29.1m for the period 2024-04-17 to 2025-04-16 with optional extension of expenditure up to USD$57.8m and to an end date of 2026-04-16. Seemingly MITRE hasn't been advised yet whether the option to extend the contract from 2025-04-16 to 2026-04-16 will be executed. And there doesn't appear to be any other pu…

I can't figure out why the hue and cry wasn't raised until the very last minute. Did they not know a month ago that they were running out of time? Is it standard practice for the government not to say they're going to extend the contract until the day beforehand or something?

I was at VulnCon last week, and an NIST representative said that there were no plans to cut CVE funding.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#639

Earlier quoted context omitted.

>>They thought they voted for something different Like what exactly? I mean the guy ran on cutting the budget by 2 trillion. In his last term he gave tax breaks yo the rich. Where did they think the cuts were coming from? He ran very hard on raising tarrifs. Which demonstrably raise prices (thats literally their goal.) But now people claim "I didn't vote for this." In truth they voted for him because he was the Repub…

> Where did they think the cuts were coming from? When someone hands you a pencil, you don't wonder what variety of tree the wood came from, or what paint chemistry was used for the coating. It's a pencil. You might have broad opinions on whether the one in your hand is comfortable to use, and sharp - but you leave the details to the pencil makers. About 70% of the population engage with politics the same way: Leave…

You are a pencil company director. A CEO candidate promised to cut expenses by 30% by eliminating waste. People who do this stuff for a living countered wood and graphite exceed 70% of your expenses. The CEO candidate proposed to increase graphite spending. Do you wonder what the CEO would do if hired?

> Do they expect to be disappointed?

Aurornis said their relatives were shocked.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#640

Earlier quoted context omitted.

> But maybe this is an opportunity to do CVE better. Okay, how? This sounds like looking for lemonade in a genocide.

> This sounds like looking for lemonade in a genocide. It really doesn't. This level of catastrophising has no point. It would be nice if CVE continued to exist, but it wasn't close to perfect, and perhaps it can continue in another form. There's no particular reason the US taxpayer has to sponsor global security threat tracking any more than any other taxpayer or customer.

This is also a myopic argument against funding standards bodies that support the internet.

The point of having a global, shared database is a single, authoritative (more-or-less), semi-vetted repository that can hold vendor accountable externally without digital amnesia or downplaying issues, and global unique identifiers. If that takes an international nonprofit funded by bits of the free world who are okay with investing in commonwealth infrastructure, so be it. Those who don't understand what they're destroying so casually are ignorant, and possibly evil if they do understand.

Post reply on HN