I'm trying to steelman but I really can't think of a non- nefarious justification for this
[flagged]
CVE program faces swift end after DHS fails to renew contract [updated]
11–20 of 1001 posts
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#12I'm trying to steelman but I really can't think of a non- nefarious justification for this
Now if you want that (even just funding) to be a thing ... you have to go through Trump & Co and pay your bribe to get it back up.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#13I'm trying to steelman but I really can't think of a non- nefarious justification for this
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#14If you work on OSS software on CVE management, then you already know that NVD funding reductions have been ongoing for more than a year. April 2024, https://nvd.nist.gov/general/news/nvd-program-transition-ann... NIST maintains the National Vulnerability Database (NVD).. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing backlog of vulnerabilities.. based on.. an increase in software…
The funding appears to have been cut off today, and both of these comments seem to talk about continuing work and how important it is.
Do you mean to say that some form of threat to the NVD has been around for over a year now? Just want to be sure I'm parsing correctly!
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#15Re: CVE program faces swift end after DHS fails to renew contract [updated]
#16Earlier quoted context omitted.
Yet so far no volunteer has emerged and people who do run CNA are pretty busy with it.
I think sneak would volunteer to do it since it is pretty simple according to them.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#17Re: CVE program faces swift end after DHS fails to renew contract [updated]
#18I'm trying to steelman but I really can't think of a non- nefarious justification for this
Why? This administration is not acting in good faith, you don't have to act as if they are. People and institutions doing that is part of how we got here in the first place.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#19If you work on OSS software on CVE management, then you already know that NVD funding reductions have been ongoing for more than a year. April 2024, https://nvd.nist.gov/general/news/nvd-program-transition-ann... NIST maintains the National Vulnerability Database (NVD).. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing backlog of vulnerabilities.. based on.. an increase in software…
What has been ongoing for more than a year? The funding appears to have been cut off today, and both of these comments seem to talk about continuing work and how important it is. Do you mean to say that some form of threat to the NVD has been around for over a year now? Just want to be sure I'm parsing correctly!
May 2024, https://therecord.media/nist-database-backlog-growing-vulnch...
> Moving forward, cybersecurity companies will have to “fill the void” .. NVD said in April [2024] that it is “working to establish a consortium to address challenges in the NVD program and develop improved tools and methods.” .. CISA acknowledged the concerns and outrage of the security community and said it is starting an enrichment effort called “Vulnrichment," which will add much of the information described by Garrity to CVEs.
The second VulnCon event took place last week and no silver bullet has appeared, https://ygreky.com/2025/04/vulncon-2025-impressions/
Vulnerability enrichment was mentioned in many talks. However, most organizations seem to handle it internally. There doesn’t appear to be momentum toward a shared or open source solution – at least not yet.Re: CVE program faces swift end after DHS fails to renew contract [updated]
#20I'm trying to steelman but I really can't think of a non- nefarious justification for this
> I'm trying to steelman Why? This administration is not acting in good faith, you don't have to act as if they are. People and institutions doing that is part of how we got here in the first place.
As you say, that's exactly what got us here. But the alternatives are very unclear, and seem deeply unpleasant.