CVE program faces swift end after DHS fails to renew contract [updated]
751–760 of 1001 posts
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#752Earlier quoted context omitted.
No thank you. I am absolutely uninterested in civil discussions with people who literally want to control everything I say and put my good friends into reeducation camps. When you accept communism you throw the concept of civil discourse out the window.
Insane talk. Where is that communist political force seeking to open gulags? The Democrats? Hahahahah Trump has a gulag in El Salvador, right now , that he uses to send his political opponents to. And you people are still making up fantasies to play the victim. Absolutely disgusting.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#753Disclaimer: This is not business advice and should be read using Cartman’s voice.
Step 1: Announce publicly that you are not renewing your contract.
Step 2: If the market has viable alternatives or the service you are negotiating isn’t that hard to replicate, other actors will manifest to fill in the gaps, especially if your business is attractive. (E.g., The top comment is building an alternative; other comments point to alternative services.)
Step 3: Congratulations, you now have leverage for a significant discount with your previous provider because they face the real prospect of losing your business entirely to a competitor. If the competitor is private, you can even double dip by investing in their company before attributing them the contract.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#754Earlier quoted context omitted.
> you are in the business of compliance rather than security. So, most businesses. They all need their ISO/NIST/HIPAA/etc certs.
Yeah, most businesses need window cleaners too. If you're a window cleaner and you complain about all the birds shitting on windows, I dunno what to tell ya. If you're working in compliance either A) you're stuck in your compliance job, that sucks, CVSS scores aren't the reason why though. B) you enjoy compliance. C) you should change jobs.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#755The contract with MITRE has been extended. https://www.forbes.com/sites/kateoflahertyuk/2025/04/16/cve-... My guess indefinitely. DOGE might be a bunch of idiots, but in the entire DOD, there are non-idiots.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#756Earlier quoted context omitted.
Why isn't it a good justification? I think the question everyone in this thread should ask is: why is it the government's job to do this, especially given the prior widespread view that they're doing a bad job? Is the software industry so immiserated by poverty that it cannot organize its own distribution of security bulletins? Clearly not: GitHub already runs its own vuln tracking scheme that's better integrated wit…
> why is it the government's job to do this This is like, exactly the sort of thing that the public sector should be doing. There's no profit incentive for this to happen in the private sector. I don't disagree with your overall sentiment re: unsustainable debt. But the answer must be reform and taking hard looks at the military budget, not just randomly cutting programs that you disagree with politically. More like…
Note that many of these entries start with GHSA not CVE.
Agree that the military budget should face large cuts too, unless I guess a major war breaks out.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#757Earlier quoted context omitted.
[flagged]
I think it's a stretch to suggest _all_ are, I'm not sure I could believe that a game like Super Hexagon is political. Would it be political to paint the tree in your backyard, or to draw a picture of your cat?
You could say that this is having political implications rather than carrying a political message, but the politics are still lurking in there all the same.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#758Earlier quoted context omitted.
The European, GDPR compliant subnet of the Internet Computer could suit your needs. The app would be decentralized out of the box and it can't be shut down by a single entity like a traditional cloud provider or nation state. Hosting 100GB costs about 500$ per year [0]. This is not a traditional hosting provider, it's a decentralized cloud. Reach out on the forum [1] or to me if this sounds like a good fit to you (I…
Seems way overkill & unnecessary. Wouldn't the e.V. (foundation) especially with FOSS backend/frontend already ensure continued operation? Also if it's about redudancy/resilience it seems like good ol' torrent/ipfs or even a dedicated dht (if you really want to have fast updated content) would be much more efficient.
That phrase does not address where and how to host data and run software, and while I think an e.V. would be a great idea, it also does doesn't address it. So these concerns seem orthogonal to my input.
The IC Protocol is indeed about redundancy and resilience, but also about sovereignty and security, and it does not just host data (like torrents) but also runs software in a verifiable way (in particular, for every message you get from a dapp on the ICP, you get a certificate that proves that the majority of nodes in the subnet agree on the result).
In a nutshell, it's a platform that gives you many guarantees (security, redundancy, sovereignty) out of the box - as opposed to classical solutions which have to be composed of many different building blocks that need to be orchestrated to work together.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#759Earlier quoted context omitted.
Not talking about politics is itself a political position (in favor of status quo).
No it’s not. It’s a position that comes from experience of knowing that it’s a complete waste of time because nobody’s mind is being changed. Further, there are entire segments of political groups who just want to assume your beliefs like a political straw man so they can denigrate you. It’s an unhealthy waste of time and that doesn’t truly hit you until you invest the time in talking to an otherwise rational person,…
I think the issue is that when people debate someone, they want to "win" by having the other side accept defeat. You are right, that rarely happens, especially in politics.
However, as someone who has participated in countless formal debates, I'll share a secret: your goal in a debate isn't to convince the person you're debating. It's to convince the audience. And that happens quite frequently, even if it's not immediately visible to the debate participants.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#760Earlier quoted context omitted.
I view the archive.org, Wikipedia, CVE program, and Linux Kernel to all have had discussions on HN about how to they should be funded. Is that kind of politics the kind that people wish that HN stayed out from?
No, but the "everything is political" people are not capable of making that distinction. Which is probably why everything seems political to them.
What is the distinction?