I don't see why this should be publicly funded, so I don't really see an issue with this. The industry benefits from having a CVE database, so the industry should fund it.
CVE program faces swift end after DHS fails to renew contract [updated]
231–240 of 1001 posts
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#232Earlier quoted context omitted.
War with China and doing enough reprehensible acts to stoke protests to declare martial law to stay in power indefinitely.
I feel like we're only a few weeks away from someone "home grown" experiencing an "administrative error." The slide into madness continues.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#233The government is not particular (in the sense of particularism) and cannot be easily tuned to fix particular problems; rather, its best solutions come through institutional procedure and design, such as the tension between the FAA and the NTSB that, at a first glance, would seem like obviously needless duplication and waste.
It is a broad, blunt, wasteful instrument to solve broad, blunt problems in a way that may not be the best but that work far, far better than alternatives that have been tried.
That the effort to treat government like a personal budget has ended up destroying important things is a sad inevitability of such efforts. I hope it goes remembered.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#234Earlier quoted context omitted.
Yes, the next elections are all I have to look forward to really.
Given the current government has blown off an unanimous 9-0 supreme court decision, right now I can't feel too optimistic there will even be more elections.
For example, a lot of people have forgotten, but the phrase "fake news" originally came about in the wake of the 2016 election about all the (actually false) misinformation that was spread on social media in the run up to the election. Trump adeptly then co-opted the term, so any news he didn't like he could just call it "fake news", and who was to say any news he called fake was any less fake than what people were calling fake before?
My guess is the 2028 elections will be marked by fraud, and then when people protest or object, Trump and the Republicans will just say "Hey, you called all those Jan 6 protesters traitors and said the election was secure, how is now any different? Now you're all the traitors."
The only belief that gives me hope these days is "History will judge the complicit."
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#235If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…
Try to talk to the people from the Sovereign Tech Fund, they have a history of sponsoring security relevant projects in the EU.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#236Now the NSA can hoard more 0days and the general public suffers. Win win for this administration
It's more likely to boost the zero day black market. I don't know if I want to attribute this to idiocy (indiscriminate cost cutting), greed (contracts for their crony pals) or malice (hoarding and trading 0 days).
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#237Earlier quoted context omitted.
No, it's definitely DOGE doing all of this. Each one of these young fools need to be named and shamed. The level of damage they have done is unprecedented. They will, in their later years, hopefully look back at this time in their life with a great deal of shame and embarrassment.
I have the feeling that there will be no redemption arc for those ones and the repenting would be for show before a court of public opinion. I'm going to be to the point here, if you guys over there don't start to heavily push and organise, and I said it already, you're one Reichstag fire away from something very bad, and from my point of view, there is probably one kristallnacht pending in the mix. This is not a hyp…
The rest of the world is mostly against Trump.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#238Re: CVE program faces swift end after DHS fails to renew contract [updated]
#239Earlier quoted context omitted.
and then a random 9.8 critical comes that affects some software you have in a way that makes it a 0 in your environment but it doesn't matter cause the cve tanks your organizational Security Score (tm) by 10 arbitrary points and management is wondering when you'll secure the company again because the Security Score is their only tangible deliverable to measure success
It’s Way Better than what we had before: software vendors making even arbitrarier decisions about how to classify them. There are far too many bad actors for us to operate as an industry with no yardstick.