Earlier quoted context omitted.
Project 2025 lays out a clear vision for the privatization and decentralization of federal functions. It’s not subtle—it explicitly calls for it. Separate from whether we support this or not: Trump is doing—or promising to do—exactly what he said he would. We can disagree with the policies, but it’s not accurate to say he or his team are directionless or incompetent. They have a coherent (if controversial) agenda. So…
Trump said he was not going to follow the project 2025 plan. So you're making two immediately contradictory claims that Trump is doing what he said he would, and is following the project 2025 plan. That's not coherent. You're suggesting a privatization plan exists, and want to debate its merits, but I see no sign such a plan is being adopted. E.g. who is enacting the plan? When is the comment period? Who do we send o…
CVE program faces swift end after DHS fails to renew contract [updated]
901–910 of 1001 posts
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#902Earlier quoted context omitted.
A bit disingenuous; he also had a career as a soldier.
Of course! It's easy to forget he was a guard at one of America's most notorious concentration camps, Guantanamo Bay. It's foolish to think of him only as a Fox News personality.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#903Earlier quoted context omitted.
My guess is that they’ll be phased out next year. The long-term goal seems to be transitioning the CVE program into something more like an industry-led consortium. (If you did not notice they operate zero budgeting approach: cut everything and if something is very important reverse it. But you cut first and then ask questions.) It’s worth noting that MITRE is a DoD contractor (with minor contracts from other agencies…
I’m a little hesitant to trust a CVE database operated by private industry on the grounds of conflict of interest for that reason, too.
In peacetime, I think everyone is generally alright with something centralized like the CVE database.
But in what increasingly seems like the lead-up to wartime... I'm hesitant to trust a CVE database operated or funded unilaterally by a single government — or even multilaterally, if the governments are all ones that all would end up on the same side of a hot war.
(Why? Strategic censorship of reports while the DB's patron takes advantage of the exploit, for one. Such a database becoming a high-priority cyberwar target, for another. Strategic wasting of enemy cybersecurity resources with false announcements, for a third.)
IMHO, the ideal form for the organization managing CVE, is one analogous to IANA and its Regional Internet Registries (RIRs).
IANA slices up the keyspace of IPs to assign to RIRs, and arbitrates disputes — but both at such a high level that their work is effectively in a de-facto state of "done until something comes up". The RIRs do all the actual everyday work.
This means that in a hot war that different RIRs end up on opposing sides of, where at least some of the RIRs can no longer trust the ownership of IANA to act in their best interests, the RIRs can just ignore IANA for a while, and keep on doing their own thing (managing allocations from their previously-agreed parts of the IP keyspace), and everything will still work.
And RIRs that control parts of IP space contended over by opposed states? They can just be split up, under obvious rules (every current allocation goes to the sub-RIR associated with the state that controls the gov/mil/corp/org entity currently holding that allocation.)
That's not the case with the CVE database under its current ownership. There's no established way to namespace it, no obvious way to split it up and keep it all working.
And I think that this problem would be obvious to the DoD. Which is precisely why paying to host a single-source-of-truth CVE database loses its lustre when that same DoD is aware that such a split might soon have to happen.
---
† I dislike the term "4D chess", because it implies one chess master who's really good at predicting non-obvious outcomes — rather than an entire military-industrial-complex acting as "see something, say something" inputs to an intelligence apparatus that does a lot of hard work and simulation analyzing potential outcomes, to produce easily-digested suggestions and action items. There just needs to be one guy in the Pentagon / the military / wherever, who realized this and sent a (classified MILNET) email about it.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#904Earlier quoted context omitted.
I just don't see how it is universally so, frankly. As a general guideline sure but some discernment is necessary nothing is gained from steelmanning apartheid or the third reich or torture prisons or or you see my point I hope.
How can you argue effectively against something if you don't understand the strongest version of the argument _for_ it?
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#905Earlier quoted context omitted.
Or they wanted this, because this could be part of the privatization of many government functions. They, or at least some of them, could see this as controlling this function for money. It's a regular stream too, the valuable subscription model and customers who really need the service (and if they don't, just add a new law in the name of IT security forcing firms to sign up).
To me it looks too chaotic to be a planned privatization plan but who knows.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#906Re: CVE program faces swift end after DHS fails to renew contract [updated]
#907Earlier quoted context omitted.
For every example of privatization going wrong, there's least one example (if not two) of it going right. But serious question -- what is the difference these days anyways? Our entire government is effectively privatized anyways from the local level up to the federal. We rely on contractors for almost everything that matters. We just maintain this facade that they are not privatized.
Would love to see a list on both sides. It is easy to win an argument when you get to gesture at evidence without being specific. For your question, the difference is if a government spend succeeds, it should lead to more things that the people can do. If a private company succeeds, it largely funds just the company. And, ideally, it should be fine that both the government/nation gets benefits while rewarding success…
To add a wrench to both "sides" some of the most effective have been state/federal-owned /state/federal controlled corporations -- or generally, arrangements where you still maintain capitalistic economic incentives and drivers, but have government oversight and (effective) regulation. I think everyone would that is good, but sometimes it takes different forms.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#908Re: CVE program faces swift end after DHS fails to renew contract [updated]
#909There are quite a few threads on hackernews that were cautiously optimistic about doge with, frankly, pretty naive libertarian takes about how the government works. The government is not particular (in the sense of particularism) and cannot be easily tuned to fix particular problems; rather, its best solutions come through institutional procedure and design, such as the tension between the FAA and the NTSB that, at a…
>I hope it goes remembered. It won't be. Willful ignorance is a cornerstone of the movement. You can't lie about what you don't know. You can't have a bad take if you don't know. Upton Sinclaire said in the 1930's: "It is difficult to get a man to understand something, when his salary depends on his not understanding it." Now add to "salary" "identity", "relationships", "sense of belonging to the group". This is why…
Democrats are repeatedly pilloried simply because they govern while the Republicans cosplay as a permanent opposition, and therefore became 'the power' to speak against. Governing inherently involves trade-offs, compromises, and complex realities that never match ideological purity. Thus, an atmosphere developed where people who engaged in governance—and therefore took responsibility for difficult, real-world outcomes—became easy targets for criticism that was more interested in the aesthetics of "truth to power" than in providing accurate analyses or constructive solutions.
As a result, "speaking truth to power" became a performance, disconnected from accountability or genuine insight. The loudest critics weren’t necessarily those with the most accurate or useful truths, just those who most visibly positioned themselves as opposing power structures. This reinforced public cynicism and undermined nuanced understanding of governance and policy, further obscuring genuine critique and necessary reforms.