Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

701–710 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#701
post #476

> A coalition of CVE Board members launched a new CVE Foundation "to ensure the long-term viability, stability, and independence of the Common Vulnerabilities and Exposures (CVE) Program." > https://www.thecvefoundation.org https://mastodon.social/@serghei/114346660986059236

This smells like a quick attempt to enable phishing for vulnerabilities, and not a legit way to make progress. The comment is from a person that runs a security startup and the site is a google site that people can report to google as a scam. (Edit: downvote as you like it— perhaps my language was too harsh to help make the point clear. It is interesting how easy non-sec people fall for names and quotes and authority.. building trust does not come overnight, in fact it is never fully there, and infosec experts would not fall for such supply chain redirections with questionable future. Hopefully we will not have to test this idea soon, though some level of reliability and long-term automation would be welcome. We need technical, generally agreed upon systems, not a “foundation”).

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#703
post #672

Earlier quoted context omitted.

The problem with discussing politics is that it gives you the kicks. Its very easy to get into a feedback loop and take things quite far off civility. I am also guilty of it, many times. IMHO there needs to be a mechanism for breaking the loop and then we can have civil online political discussions. Unfortunately most places just ban it or ban those who got into the loop, either way its ugly. IRL when discussing poli…

No thank you. I am absolutely uninterested in civil discussions with people who literally want to kill me and deport my good friends to guantanamo bay cuba. When you accept nazism you throw the concept of civil discourse out the window.

Case in point: you have decided that those who disagree with you want to kill you, deport your friend, and are otherwise nazis. While a minority do, that isn't the majority.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#704
post #51

I wish this hadn't happened. I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do t…

No one analyzed it most likely. It’s possible on of the college students working for Doge doesn’t understand security because they are a child with no real world experience that Elon brought in to slash costs.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#705

Earlier quoted context omitted.

I can't believe what a bunch of bollocks this administration is. I couldn't believe it the first time, and this time I thought "Well at least I'm ready, it will be a lot like last time" and it's so much worse

A lot was lost in the midterms and Supreme Court appointments. Hopefully these 4 years energize people to vote. I know protesting and direct action and so on are also important, but the gradient is not negative for voting for every office you can vote for in every election.

> Hopefully these 4 years energize people to vote.

This euphemism has to end. I think you mean: "Hopefully these 4 years energize people to vote Democrat".

Why not just say it plainly instead of using supposedly non-partisan language? This neutral phrasing seems to be an appeal to a "silent majority" that agrees with you and disagrees with Republican leadership. What if that silent majority doesn't exist?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#707

Earlier quoted context omitted.

No thank you. I am absolutely uninterested in civil discussions with people who literally want to kill me and deport my good friends to guantanamo bay cuba. When you accept nazism you throw the concept of civil discourse out the window.

Case in point: you have decided that those who disagree with you want to kill you, deport your friend, and are otherwise nazis. While a minority do, that isn't the majority.

I am (un)lucky enough to live in an area where I don't have to decide this. People are willing to say it out loud.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#708

FWIW, I've never understood why this sort of thing wasn't just directly handled by the NSA --- aren't they the group which should be tasked with cybersecurity? I always suspected that "Department of Homeland Security" would lead to Banana-republic-like shenanigans --- could we defund them?

"National Security" doesn't mean you personally. It's the government only. There's a conflict of interest that immediately arises if a part of the DoD (who owns cyberwarafe, which uses vulns) maintains a public vuln database.

(Edited to be less salty, sorry)

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#710

To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.

The problem is not political topics, it is how people discuss them.

That's a massive issue. Every topic is so polarized that it's as if it's evil vs. good.

But I think people are waking up, because things they took as non-political god given right is being made political and taken away.

Post reply on HN