Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

971–980 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#972

Earlier quoted context omitted.

>I hope it goes remembered. It won't be. Willful ignorance is a cornerstone of the movement. You can't lie about what you don't know. You can't have a bad take if you don't know. Upton Sinclaire said in the 1930's: "It is difficult to get a man to understand something, when his salary depends on his not understanding it." Now add to "salary" "identity", "relationships", "sense of belonging to the group". This is why…

I mostly agree, although I really disagree with 'speaking truth to power' — I feel like the outsized reverence for this is exactly what got us into this mess. For YEARS, there's been a culture of celebrating opposition for opposition's sake, a performative stance of always positioning oneself against the perceived holders of power, rather than critically evaluating the actual accuracy or value of what's being said. D…

I agree that "speaking truth to power" can, and has been, abused. Treated as an end unto itself it becomes mere contrarianism, and loses the "truth" part of the phrase. I mean it in its original sense: speaking up when it is dangerous for you to speak, particularly when you have evidence of misdeeds by the powerful (the lack of evidence is another pervasive issue with most online speech - mere allegation against those you don't like is enough, it seems, for most people). When the government can disappear its critics and optionally suppress news of the disappearance, then critics deserve praise and honor.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#973

Earlier quoted context omitted.

MITRE is absolutely not an FFRDC. It's a regular old 501(c)(3) which happens to manage FFRDCs.

Yes, you are correct, I should have typed "runs". But the point is that MITRE runs the U.S. National Cybersecurity FFRDC that maintains the CVE system, and FFRDCs are deliberately structured to minimize potential conflicts of interest (GP comment) and are definitely distinct from private industry (parent comment).

[deleted]

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#974

Earlier quoted context omitted.

Because they have their own programs for this already.

I guess that’s why I don’t get all the knee-jerk “China will step in” comments. Even if they did people wouldn’t have the same trust levels as they did with the former USA. I’d trust a European version a lot more. China will be able to fill some voids but ideologically they’re not fit to fill them all.

What I meant to say was that China will happily seize the opportunity to try to fill the void (whether it succeeds or not is a separate matter).

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#975

Earlier quoted context omitted.

Afaik there's never been a DEI initiative (or similar, I'm not American) that I've ever heard of to hire more gay people specifically. Most of us would hate to be hired for our sexuality rather than our skills. There's nothing "woke" about it and screaming woke woke woke isn't going to change the fact that we exist and you don't like it. I'd tell you what I really think of you but it would invoke Dang.

You misinterpreted that comment, which was sarcastically pointing out a study which was purportedly cut simply because it had the word part “homo” in it.

This is correct.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#976

Earlier quoted context omitted.

[flagged]

can you image that? people will just go on the internet and lie ? https://en.wikipedia.org/wiki/Eric_Shinseki

Oversight, okay. Point stands that Hegseth is a decorated solider, before and more importantly than previous news show host.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#977

Earlier quoted context omitted.

You aren’t worried about the conflict of interest with a government run system, given the desire of governments to be able to intercept all communication?

No, particularly because CVE has no communications functionality.

My worry would be that a government might want to hide a particular vulnerability it has found that enables it to break into a system.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#978
post #312

Earlier quoted context omitted.

Have you seen proof that this is what has been happening? Your explanation is much more convoluted than "DHS cut funding, like the administration has said it is going to do".

These explanations are not mutually exclusive.

I think they are a little, but you didn't answer my question?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#979

Earlier quoted context omitted.

A lot was lost in the midterms and Supreme Court appointments. Hopefully these 4 years energize people to vote. I know protesting and direct action and so on are also important, but the gradient is not negative for voting for every office you can vote for in every election.

> Hopefully these 4 years energize people to vote. This euphemism has to end. I think you mean: "Hopefully these 4 years energize people to vote Democrat". Why not just say it plainly instead of using supposedly non-partisan language? This neutral phrasing seems to be an appeal to a "silent majority" that agrees with you and disagrees with Republican leadership. What if that silent majority doesn't exist?

> This neutral phrasing seems to be an appeal to a "silent majority" that agrees with you and disagrees with Republican leadership. What if that silent majority doesn't exist?

Then we are on course to lose our spot on top of the world, and I should probably plan to get laid off. Idk, I get what you mean, but not agreeing with Democrats (I don't really agree with them much) and wanting a stable country with a good economy are way different things. I can hold my nose and vote for someone who doesn't actively try to tank the economy, the same way many conservatives (especially religious ones), held their nose and voted for Trump

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#980
post #602

Earlier quoted context omitted.

Seems way overkill & unnecessary. Wouldn't the e.V. (foundation) especially with FOSS backend/frontend already ensure continued operation? Also if it's about redudancy/resilience it seems like good ol' torrent/ipfs or even a dedicated dht (if you really want to have fast updated content) would be much more efficient.

>FOSS backend/frontend That phrase does not address where and how to host data and run software, and while I think an e.V. would be a great idea, it also does doesn't address it. So these concerns seem orthogonal to my input. The IC Protocol is indeed about redundancy and resilience, but also about sovereignty and security, and it does not just host data (like torrents) but also runs software in a verifiable way (in…

> runs software in a verifiable way (in particular, for every message you get from a dapp on the ICP, you get a certificate that proves that the majority of nodes in the subnet agree on the result).

There is no need for this though, by it's very nature CVE services are "authorities", that distribute fairly simple data. Also if it costs 500$ to keep it online it's not really giving you much more resilience than regular multi-node hosting and significantly less than torrenting which is effectively free for many volunteers.

Post reply on HN