Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

821–830 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#821

Earlier quoted context omitted.

One of the benefits a working democracy conveys to its citizens is that they largely don't have to care about politics. They can trust that government action is relatively consistent over time, that laws will be enforced fairly enough, that their property will be protected to a reasonable degree, that the currency will be reasonably stable, that the roads will be maintained, that some public transport will be availab…

>One of the benefits a working democracy conveys to its citizens is that they largely don't have to care about politics The citizens elect the government so how can you not care about poltiics?

Well, a bit. A part of liberal democracy is that elections don't matter that much. The losers can trust that they aren't going to be arrested, have their property confiscated etc. The established system like the courts, constitutions separation of powers and other anti-majoritarian things will prevent most extreme measures. And in at least some political systems, it is expect that no matter what some minimally competent people will win and govern not that differently from what the election loser was going to do.

And remember voting is not mandatory and a lot of people don't vote. Those people are ultimately letting others decide, and a lot of them are hoping the voters are going to pick well, or at least decently.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#822
post #739

Earlier quoted context omitted.

My guess is that they’ll be phased out next year. The long-term goal seems to be transitioning the CVE program into something more like an industry-led consortium. (If you did not notice they operate zero budgeting approach: cut everything and if something is very important reverse it. But you cut first and then ask questions.) It’s worth noting that MITRE is a DoD contractor (with minor contracts from other agencies…

... and that industry led consortium will have a board all paid princely sums, and an executive leadership team that is conflicted to the hilt and paid kingly sums, and they will charge exorbitant rents in order to keep the lighthouse lit. There's flaws with every approach, but I much prefer the approach where this sort of thing is treated as a public good, rather than as yet another soon-to-be walled garden.

I keep thinking of that time Wisconsin's state government privatized a bunch of IT stuff in the interest of "government efficiency", and the cost taxpayers paid for those specific functions increased by several hundred percent while quality of service went down.

At that same time, though, I worked for a contractor that I do believe saved states money compared to doing things in-house. The work we did really required specialists. But no one state had enough of the work to keep one busy all year. So sharing a pool of people to do the work among many states meant there was room for both saving the states money and allowing some profit for the company.

The idea that you can just blanket assume that private industry is inherently more efficient than public works really needs to die. There doesn't seem to be any more evidence to support it than there is to support the idea that it's inherently less efficient. Life just isn't that simple. It's all case by case.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#823
post #369

Earlier quoted context omitted.

No, we’re in a middle of a coup. Palantir or some other odious company will get paid 100x more to do something.

People will not submit vulns as happily to such business. Most of vulns will go unaddressed because company like palantir will most likely want only really good vulns like 0-click RCE.

Putin, Xi, and Un say thank you.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#824

The contract with MITRE has been extended. https://www.forbes.com/sites/kateoflahertyuk/2025/04/16/cve-... My guess indefinitely. DOGE might be a bunch of idiots, but in the entire DOD, there are non-idiots.

But the article says, quote: > It’s unclear what led to DHS’s decision to end the contract after 25 years and then suddenly it gets extended. What does it have to do with DOGE?

MITRE has been hit with DOGE-branded cuts[0] earlier this month. CISA has been impacted[1]. It seems reasonable to assume they were involved in this.

0 - https://virginiabusiness.com/nova-govcon-firm-mitre-to-lay-o...

1 - https://techcrunch.com/2025/03/11/doge-axes-cisa-red-team-st...

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#825

To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.

People trying to ignore politics are like fish trying to ignore water.

> People trying to ignore politics are like fish trying to ignore water.

Like fish, most people do ignore it until it turns foul.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#826

This makes me wonder what other stuff most people don't know exists but is important to our society has quietly disappeared in the last few weeks. We know about this one because we know it's important. What are the things we don't know about?

The cheerleaders don't care. Americans' relative certainty and quality of life is backstopped by institutions they either barely understand or have never heard of. Let them touch the stove, I guess.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#827

Earlier quoted context omitted.

[flagged]

Afaik there's never been a DEI initiative (or similar, I'm not American) that I've ever heard of to hire more gay people specifically. Most of us would hate to be hired for our sexuality rather than our skills. There's nothing "woke" about it and screaming woke woke woke isn't going to change the fact that we exist and you don't like it. I'd tell you what I really think of you but it would invoke Dang.

You misinterpreted that comment, which was sarcastically pointing out a study which was purportedly cut simply because it had the word part “homo” in it.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#828

Earlier quoted context omitted.

It's called providing leadership. Worth the money. China will happily fill the void.

I hate this whole disaster but why can't Europe step in for stuff like this?

Because they have their own programs for this already.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#829
post #820
post #739

Earlier quoted context omitted.

My guess is that they’ll be phased out next year. The long-term goal seems to be transitioning the CVE program into something more like an industry-led consortium. (If you did not notice they operate zero budgeting approach: cut everything and if something is very important reverse it. But you cut first and then ask questions.) It’s worth noting that MITRE is a DoD contractor (with minor contracts from other agencies…

> The long-term goal seems to be... Where do you get that from? I've seen no sign of long-term goals, much less any mechanisms being put in place for follow-through on those goals. It seems like people keep making the mistake of believing there's a detailed plan, while all evidence tells us there isn't. I guess it's the normal human tendency to see order in the chaos.

Project 2025 lays out a clear vision for the privatization and decentralization of federal functions. It’s not subtle—it explicitly calls for it.

Separate from whether we support this or not:

Trump is doing—or promising to do—exactly what he said he would. We can disagree with the policies, but it’s not accurate to say he or his team are directionless or incompetent. They have a coherent (if controversial) agenda.

So rather than dismissing them as clueless or idiots, it’s more productive to debate this:

- Why is outsourcing CVE program to private consortia a bad idea?

- Could a model exist where a private consortium is supported by federal grants, but maintains accountability and public interest safeguards?

Post reply on HN