Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

961–970 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#961
post #891

Earlier quoted context omitted.

[flagged]

> Malicious idiots surrounded by sheepish intelligent people. Prefixing people with "sheepish intelligent" is bound to oversimplify this. Many of the non-DOGE employees who directly see wrongdoing are likely making calculated decisions on what to do. It depends on many factors, including the law and whistleblower protections. Many of them are responding in various ways that they hope will have an impact. Some resign…

The current administration is shipping people out of American territory to a hellhole in El Salvador without trial. It'd like to do that more often.

Whistleblower protections don't mean much if the brute squad snatches you off the street and throws you on a plane regardless of what the law says.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#962
post #492
post #379

Earlier quoted context omitted.

That's because we got reliant on the funds from government. Maybe it's time to break the dependency.

> That's because we got reliant on the funds from government Not we, some people got reliant on the funds from government. It is always at the cost of someone else. The tax the rich and bourgeoisie mentality is what led to Mao Zedong and Stalin, but no-one wants to learn about history anymore.

Stalin and Mao were both cults of personality being driven by a young, disaffected population who were so sick and tired of the status quo that they were willing to murder and burn and kill and destroy and didn't really care about what came after.

That should sound very familiar right about now.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#963
post #959

Earlier quoted context omitted.

> how did you decide that such a database has no serious utility to the governments and private institutions worldwide I did not. I said that the signal noise ratio has to be improved. I explicitly used the word "revamp". I know, hyperbole low reading comprehension. > So perhaps what's needed to improve their quality is to increase their funding, not cut it further. Sure, if that is the blocker, funding them more is…

> Good. CVEs were the poster boy of goodharts law for the longest time. I guess this must have been by somebody else who thinks it's OK to shutdown CVE db because it isn't good enough for them. > I know, hyperbole low reading comprehension Try starting with the list in my first reply. Reading comprehension comes later. > Sure, if that is the blocker, funding them more is fine by me. Perhaps you should have started wi…

> I guess this must have been by somebody else who thinks it's OK to shutdown CVE db because it isn't good enough for them.

Yes, shutting it down is completely fine by me, letting some other database take its place. It has a chance to be better.

> Perhaps you should have started with that first before belittling their work. This is exactly what I have been saying all along.

I very much intentionally criticised their work - I think the CVE system (the way it runs today) is garbage. You proposed a solution to this situation involving increased funding. I am fine with that solution. Just like I am fine with the solution "nuking it and starting afresh".

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#964

Earlier quoted context omitted.

That’s a pretty big leap. Ending a 25-year contract and laying off ~600 employees are two very different scales of impact. While DOGE-related cuts might have influenced some decisions, assuming they directly caused DHS to initially let the CVE contract lapse seems like a stretch. Just because two things happen near each other doesn’t mean one caused the other - this feels more like another chance to take a swing at D…

Yes, imagining that the quasi-government organization that is solely tasked with cutting spending might have cut spending at an agency where they are currently cutting spending is a “huge leap.” What was I thinking?

What you’re doing is jumping from “DOGE made cuts” to “DOGE killed a 25-year contract” with zero evidence beyond coincidence. That’s not analysis - that’s just reaching. If this were a clean budget cut, the contract wouldn’t have been renewed at the last minute. That kind of flip-flop screams internal disarray or political games, not a calculated DOGE move. You’re not connecting dots, but drawing them in with a crayon and calling it a map.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#965
post #625
post #424

Earlier quoted context omitted.

This quote is essentially unworkable. Everything you say, or choose not to say, inevitably advances some political perspective over another. What we should really aim for is thoughtful, civilized, and maybe even aesthetically pleasing discourse. That’s what educated people strive for. Trying to “avoid politics” is like collecting seashells while a tsunami is rolling in.

It's scary how widely this varies between different communities. On Reddit, /r/politics is mostly people acting like they're auditioning for the writers' room on one of those late-night talk shows, whereas /r/ukpolitics and /r/australianpolitics are almost exclusively people making insightful, analytic comments.

Oh really? I will check all of them, thanks for the hints!

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#967
post #143

I don't see why this should be publicly funded, so I don't really see an issue with this. The industry benefits from having a CVE database, so the industry should fund it.

There are going to be all kinds of messed up incentives if this is funded from industry.

Like there aren't any messed up incentives with it funded by the government? Um, Vault 7? Snowden? PRISM? Did you literally just forget the past two decades of domestic spying and the NSA withholding critical vulnerabilities they were currently using?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#968

Why is the government responsible for CVEs again?

It's not. The CVE board members include representatives from CrowdStrike, Microsoft, Github Security, LP3, F5, Panasonic, NIST.

Everyone crying about "Oh no! This government institution is going away! Private companies would never do this! They would use it for financial gain!"

Um.... It's already run entirely by private entities via government money. It's the literal definition of a "Public Private Partnership." You know, that way the US government get away with doing a lot of shady stuff via non-government contracts who are totally not state actors /s.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#969

Earlier quoted context omitted.

I hate this whole disaster but why can't Europe step in for stuff like this?

Because they have their own programs for this already.

I guess that’s why I don’t get all the knee-jerk “China will step in” comments. Even if they did people wouldn’t have the same trust levels as they did with the former USA.

I’d trust a European version a lot more.

China will be able to fill some voids but ideologically they’re not fit to fill them all.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#970
post #837
post #350

only one country pays but all benefit from it. It should be funded by all who benefit like UN.

I thought most people in the US wanted the UN to have less control over this stuff? Remember the talk about moving control of the Internet to the ITU (International Telecommunication Union)?

The EU, the EU and all bodies that remove a nations sovereignty should be removed entirely. Brexit was good, but the UK government made it meaningless. The UN chokes and strongholds it member states.

The CVE program is already a public-private partnership, which is BAD. CVE's board has people from Microsoft, Github, CrowdStrike, etc. Public-private partnerships are how the US government gets away with things a State should not be able to do: via private contractors. The US government has also run programs like Vault 7. The NSA has a vested interest in vulnerabilities not being made public until the US can fully exploit them Internationally.

The merger of state and corporate interests seems to be everyone's favorite overused word of the decade.

Post reply on HN