Live data from Hacker News

America's cyber defenses are being dismantled from the inside

theregister.com

171–180 of 218 posts

Re: America's cyber defenses are being dismantled from the inside

#171

Earlier quoted context omitted.

>So in what way does this help the American people? Shutting down Mitre and the CVE is against American interests, both public and private. That said, you can make an argument, one that revolves around cost (was the CVE DB worth $50M a year, especially given its backlog?). The other part of that argument rests on assuming there will be a private or semi-private replacement for the service, that there may be many of t…

> was the CVE DB worth $50M a year, especially given its backlog? This is more or less a common rhetorical argument made by republicans after cutting budgets. The agency (organization, etc) is ineffective now, so we should terminate it, rather than fund it so it may be more effective.

running the country like vulture private equiteers.

Re: America's cyber defenses are being dismantled from the inside

#172
post #64

Earlier quoted context omitted.

>So in what way does this help the American people? Shutting down Mitre and the CVE is against American interests, both public and private. That said, you can make an argument, one that revolves around cost (was the CVE DB worth $50M a year, especially given its backlog?). The other part of that argument rests on assuming there will be a private or semi-private replacement for the service, that there may be many of t…

NIST used to punch above its weight, everyone that I know who worked there has left over the last few months.

IIRC, expect (Unix automation tool) was developed at NIST by Don Libes, who also wrote the book about it.

I would call that punching about your own weight, if you consider the use and impact of expect:

https://en.m.wikipedia.org/wiki/Expect

https://core.tcl-lang.org/expect/home

Re: America's cyber defenses are being dismantled from the inside

#173

Earlier quoted context omitted.

If I were Putin I'd attack some very minor NATO state to check if NATO will really send soldiers to defend it. Example: is really somebody willing to die for Estonia? (Sorry HNers from Estonia, but you are just in the worst possible place of all of NATO.) If not, NATO will crumble into pieces. If yes, let's see who's sending soldiers and who won't, and how they will react to the first week of casualties. Keep going o…

But you are not Putin and he is not you. Attacking Ukraine wasn’t a gamble for him, it was a presumably easy win, like Georgia in 2008. Attack on NATO on Baltic shore isn’t an easy win, it’s a gamble. And what is this test for? America has already learned the lesson and is withdrawing from Russian periphery. Europe has no interest in power games, UK is in irreversible decline. NATO is not going to expand anymore in f…

The latest expansion of NATO was barely a year ago (with Sweden joining).

Russian authoritarianism may be secure, but the current regime's power is not (not to mention their leaders' paranoia).

Their ambition is the control of continental Europe. It might sound crazy, but if you listen to people like Dugin, it is very clear. And it's not that unrealistic in the longer run, considering everything you listed in your post.

The onslaught on Europe will continue - first (already happening) on its unity through the financing and propaganda support of the right-wing populist candidates who don't know (or simply don't care) better and then, once every (relatively) little country in Europe is on their own, on their sovereignty through military threat and/or invasion.

I will also leave this here as I think it is pertinent to the discussion:

https://www.researchgate.net/publication/313258664_Putin's_R...

Re: America's cyber defenses are being dismantled from the inside

#174
post #2

> It's the global catalog that helps everyone – security teams, software vendors, researchers, governments – organize and talk about vulnerabilities using the same reference system so why was only the US federal government funding it, especially if it wasn't expensive to maintain? this is the follow up question to every headline and won't be seen as controversial later, so why bother treating it as controversial to s…

Completely irrelevant. Deliberately or not you're repeating the Trump / DOGE talking point of government expense, focused on expenses that individually and in aggregate contribute practically nothing to the federal budget.

> Deliberately or not you're repeating the Trump / DOGE talking point of government expense

Its a run of the mill libertarian position

It doesn't matter which politician or administration does it from that perspective. Those two do happen to be a coalition with libertarian constituents that they courted for votes, so its more than happenstance that the positions and actions will sound the same.

Regardless, private funding isn't controversial. The US Federal government reaching parity with the same level of apathy of every other government organization in the world isn't controversial either.

Re: America's cyber defenses are being dismantled from the inside

#175
post #48

Earlier quoted context omitted.

> especially if it wasn’t expensive to maintain Okay, so we’ve established that the cost of the endeavor is low. > it’s the global catalog that helps everyone organize and talk about vulnerabilities I would argue that leading and controlling the organization that provides the world with the single most ubiquitous cybersecurity resource justifies what you characterized as a meager cost in reputational capital alone. >…

> I would argue that leading and controlling the organization that provides the world with the single most ubiquitous cybersecurity resource justifies what you characterized as a meager cost in reputational capital alone. Someone in the original HN thread about funding wrote a post explaining how poorly run CVE org was and it had been like that for years. It had a giant backlog, ignored criticism, and moved very slow…

> Someone in the original HN thread about funding wrote a post explaining how poorly run CVE org was and it had been like that for years.

Sure, but that doesn’t change anything, does it? Most people that use or have benefited from the CVE program are not even aware of these criticisms, and I’d be willing to bet that the majority of people who _are_ aware only became so in the past week.

> This is purely a reputational concern. Being on government networks doesn't make it instantly more trustworthy or safe.

I did not say the concern was the safety of the CVE program. The concern is influence over the world’s inbox for 0days and the tangible ways that can be used to a nation’s benefit. It is most certainly not just a reputational concern. If China had stepped in last week and took the reins there would be groups within both industry and government having mild freakouts this week.

Re: America's cyber defenses are being dismantled from the inside

#176

Earlier quoted context omitted.

>More than anything I'm curious how the money is being spent because without knowing that it's impossible to judge whether it's bloated or not. Exactly. And it's totally fair for anyone to question the cost. However, the current administration is destroying things with the precision of a Jackson Pollack painting and no such reflection is happening.

Question the cost how? By saying "is this alot?" Then performing no further investigation to confirm that or make a comparison basically leaving the question open which causes random to assume it's "alot"

I can say "Gee whiz $335M per F-22 seems a bit much!" without being an expert in jets, military equipment, or going into the details of its production. I know a bit more about software so I can safely say something similar about MITRE. The fact that I don't want to spend my time doing (frankly, rather useless since I'm not a journo or in government or influential at all) investigative journalism into the specifics doesn't invalidate my opinion. Random people will read random things into whatever random content they consume; deep in an HN comment thread this is of little concern.

Re: America's cyber defenses are being dismantled from the inside

#177
post #4
post #2

> It's the global catalog that helps everyone – security teams, software vendors, researchers, governments – organize and talk about vulnerabilities using the same reference system so why was only the US federal government funding it, especially if it wasn't expensive to maintain? this is the follow up question to every headline and won't be seen as controversial later, so why bother treating it as controversial to s…

For the same reason the US considers its self the "leader" of the world. You can't have it both ways, if you want to "lead", you've gotta pay for it.

then you might be pleased to know that I don't want to have it either way

let's fix our own cities and domestic infrastructure projects while pulling back the federal government, just like we are doing

Re: America's cyber defenses are being dismantled from the inside

#178
post #155
post #52

Earlier quoted context omitted.

> See, people look at the stalemate and often draw false conclusions. It's not that Russia was too weak militarily, it's that Ukraine put up one hell of a fight While Ukraine unquestionably put up a hell of a fight, the fact that the numerically superior army with the better and more numerical equipment, backed by the multiple times bigger and richer country failed is a failure. Especially when you consider that Ukra…

> Especially when you consider that Ukraine doesn't have a navy and barely had an air force and anti-air, yet Russia failed at establishing air or naval control, let alone dominance. Ukraine had dozens of airworthy fighter jets and well over a hundred air defense batteries at the start. Many of the latter were lost in the first weeks but Ukraine was fairly packed as far as smaller nations go. > Russia has no chance o…

> Name one thing in Polish military that Ukrainian military today doesn't have though?

Lack of combat experience.

But seriously, very good analysis!

Re: America's cyber defenses are being dismantled from the inside

#179

Earlier quoted context omitted.

>So in what way does this help the American people? Shutting down Mitre and the CVE is against American interests, both public and private. That said, you can make an argument, one that revolves around cost (was the CVE DB worth $50M a year, especially given its backlog?). The other part of that argument rests on assuming there will be a private or semi-private replacement for the service, that there may be many of t…

> was the CVE DB worth $50M a year, especially given its backlog? This is more or less a common rhetorical argument made by republicans after cutting budgets. The agency (organization, etc) is ineffective now, so we should terminate it, rather than fund it so it may be more effective.

It is not even argument that it is ineffective. Large backlog can mean it is ineffective or it can mean that there is more work to do then resources allow. There is no way to distinguish these two without further info.

Re: America's cyber defenses are being dismantled from the inside

#180
post #173

Earlier quoted context omitted.

But you are not Putin and he is not you. Attacking Ukraine wasn’t a gamble for him, it was a presumably easy win, like Georgia in 2008. Attack on NATO on Baltic shore isn’t an easy win, it’s a gamble. And what is this test for? America has already learned the lesson and is withdrawing from Russian periphery. Europe has no interest in power games, UK is in irreversible decline. NATO is not going to expand anymore in f…

The latest expansion of NATO was barely a year ago (with Sweden joining). Russian authoritarianism may be secure, but the current regime's power is not (not to mention their leaders' paranoia). Their ambition is the control of continental Europe. It might sound crazy, but if you listen to people like Dugin, it is very clear. And it's not that unrealistic in the longer run, considering everything you listed in your po…

>listen to people like Dugin, it is very clear

Don’t be afraid of scarecrows. He is a powerless freak far away from the decision makers, not Rasputin. Says a lot, but doesn’t really matter. It is much more interesting what people in security council say and who gets the contracts. There’s zero indication of expansion but a lot of messages about not messing with “legitimate interests”. They protect what they think is theirs.

The ambition of the control over continental Europe exists only in imagination of people with no understanding of Russian internal politics. They need absence of threat and parking lot for the money, so they will play the game of influence, but war? Nonsense.

Post reply on HN