Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

841–850 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#842
post #664

[flagged]

Oh! It will be even more fun when the entire infotech and infosec industry starts seething soon. Then the rest of the world will just make alternative arrangements and move on, leaving the US behind because they can't be trusted anymore. HN's reaction is just a small taste of things to come.

[flagged]

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#843
post #349

Earlier quoted context omitted.

No, "the industry" is all of us alive in the 21st century who depend on software to make material decisions and to be resilient to attacks and tampering. We were all funding it, and now surely we will see some big tech company now assume responsibility from the federal government (please god don't let it be Oracle...)

so "all" should pay, not only US taxpayers.

That would be an improvement. Perhaps the UN should fund it.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#844

The contract with MITRE has been extended. https://www.forbes.com/sites/kateoflahertyuk/2025/04/16/cve-... My guess indefinitely. DOGE might be a bunch of idiots, but in the entire DOD, there are non-idiots.

[flagged]

You've put your faith in the wrong people.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#845
post #829
post #820

Earlier quoted context omitted.

> The long-term goal seems to be... Where do you get that from? I've seen no sign of long-term goals, much less any mechanisms being put in place for follow-through on those goals. It seems like people keep making the mistake of believing there's a detailed plan, while all evidence tells us there isn't. I guess it's the normal human tendency to see order in the chaos.

Project 2025 lays out a clear vision for the privatization and decentralization of federal functions. It’s not subtle—it explicitly calls for it. Separate from whether we support this or not: Trump is doing—or promising to do—exactly what he said he would. We can disagree with the policies, but it’s not accurate to say he or his team are directionless or incompetent. They have a coherent (if controversial) agenda. So…

Actually Trump repeatedly said he didn't know about project 2025. He's so scattered in his campaigning that it's possible to pretty much justify any action as "what he said he would do." But saying executing project 2025 is exactly what he SAID he would do defies all reality. It may be what intelligent observers expected him to do but it is not what he said.

Edit: good lord people I’m not defending Trump I’m saying he lies about everything including that he lied and said he wasn’t going to do project 2025. Read the post I’m responding to!

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#846

I'm trying to steelman but I really can't think of a non- nefarious justification for this

I'll admit this is a bugbear of mine, but I think this is the reason "steelmanning" is counterproductive.

Steelmanning is a neologism that serves no purpose other than in-group signaling. There was already a perfectly acceptable term for the same concept, one with more nuance and a rich history: Charitability.

The major difference is that charitability is about treating your interlocutor with respect. Steelmanning is about using one's own intellect to make your interlocutor's argument better than them. Because charitability is based on a concept of mutual respect, if somebody clearly doesn't respect you one iota, then why would you be charitable? Steelmanning tries to divorce the person from the argument, and is ironically both arrogant and naive.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#847
post #254

Earlier quoted context omitted.

As if laws have any meaning to this administration, and anyone expecting this will only last four years instead of turning into one of those countries so much admired by the captain at the helm, is fooling themselves. When the citizens realise this, the structures to clamp down any revolution will be in place.

TBF trade-marking a term like "CVE" is the most ridiculous fucking thing and just reeks of modern American copyright law type stuff.

It's only superficially ridiculous.

"CVE" is trademarked and emphasized (e.g. included in the shorthand notations, e.g. CVE-2014-0160), explicitly to prevent other groups from using "CVE" in a way that causes confusion in the marketplace. And yes, this is the same reason trademarks exist for commercial purposes.

But imagine if Microsoft could issue CVEs against Apple ... or OpenAI against Anthropic, etc.

The label "CVE" has to have a known authority to be useful. And the only way to ensure that is to trademark it. See also: "Linux™".

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#848

Earlier quoted context omitted.

I’m a little hesitant to trust a CVE database operated by private industry on the grounds of conflict of interest for that reason, too.

I am quite hesitant to trust the DOD to keep track of software vulnerabilities. Some parts are developing and exploiting vulnerabilities. And given a fresh feed of what people find, and usually a delay from notification until publication, which may sometimes just be a bit longer of a delay, would allow the DOD to weaponize the vulnerability for their own use as well.

CVE Numbering Authorities (CNA) have lots of control over those.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#849

Earlier quoted context omitted.

No thank you. I am absolutely uninterested in civil discussions with people who literally want to control everything I say and put my good friends into reeducation camps. When you accept communism you throw the concept of civil discourse out the window.

I understand you're trying to "both sides" an argument. What have you found that has achieved for you in the past? Do you change people's opinions with this?

I have found that no amount of online discussion has ever changed anyone's mind on larger issues. We're all pissing in the wind here.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#850
post #829

Earlier quoted context omitted.

Project 2025 lays out a clear vision for the privatization and decentralization of federal functions. It’s not subtle—it explicitly calls for it. Separate from whether we support this or not: Trump is doing—or promising to do—exactly what he said he would. We can disagree with the policies, but it’s not accurate to say he or his team are directionless or incompetent. They have a coherent (if controversial) agenda. So…

Actually Trump repeatedly said he didn't know about project 2025. He's so scattered in his campaigning that it's possible to pretty much justify any action as "what he said he would do." But saying executing project 2025 is exactly what he SAID he would do defies all reality. It may be what intelligent observers expected him to do but it is not what he said. Edit: good lord people I’m not defending Trump I’m saying h…

> Actually Trump repeatedly said he didn't know about project 2025

  * He said he'd end the war in a day.
  * He said he had a better health care plan.
  * He said he'd drop the price of eggs.
  * ...
  * He said lots of things that were not true.
Post reply on HN