Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

421–430 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#421

Earlier quoted context omitted.

Everything was always political. Laws, the economy, conflcit. How is any person not affected by these? The government is responsible for all or a large part of how a country functions. People who say "I'm not political" are deflecting to avoid conflict

When this is discussed, what's being meant is that everday party politics are spilling out and overwhelming a project's or industry's individual, internal politics, which are often a completely disconnected meta. Appealing to "well everything is connected" I'm not sure is useful. It's interesting from a semantics perspective the first few times you come across it maybe, then swaps around into being plain frustrating,…

> I think are doing a pretty big favor to their mental health, and

It your mental health is harmed while defending your political views it's possible your views are the issue.

For example if my view was that "domestic animals shouldn't be abused and penalties increased for such crimes" I wouldn't have mental health issues discussing this.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#423
post #388

Earlier quoted context omitted.

I don't think the EU has any interest in this. They've been aware of the risk of relying on the US for software security for years, but AFAIK there have been no efforts to do anything about it. Maybe the current situation will kick some butts into gear ... Off topic: your username is very appropriate given the situation.

>They've been aware of the risk of relying on the US for software security for years, but AFAIK there have been no efforts to do anything about it. Indeed. Just as Germany knew their economy is vulnerable to Russian gas and did nothing about it, even after the 2014 invasion of Crimea. Just as the west knew moving their entire manufacturing sector to one country would make them vulnerable, but choose to ignore it beca…

> I never EVER saw politicians act proactively for the good of the nation or the people,

This is almost certainly because those cases don't make the news.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#424

To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.

This quote is essentially unworkable. Everything you say, or choose not to say, inevitably advances some political perspective over another.

What we should really aim for is thoughtful, civilized, and maybe even aesthetically pleasing discourse. That’s what educated people strive for.

Trying to “avoid politics” is like collecting seashells while a tsunami is rolling in.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#425

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

Honest question: Does this not already exist?

- https://vulnerability.circl.lu/

- https://osv.dev/

- https://vuldb.com/

And a few others?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#426

Earlier quoted context omitted.

This sort of thing is happening across the federal government. There is no rhyme or reason. DOGE has been given an unrealistic target for cuts and they're desperately cutting whatever they can get their hands on. If you look at the federal budget it's nearly impossible for DOGE to hit their stated goals without touching benefits like medicare and social security (which are off limits so far) so the only option is dee…

Remember, DOGE has nothing to do with money or "efficiency". It's a pure ideological dismantling of the Federal government aimed at eliminating oversight, regulations, assistance and entitlements as envisioned by ultra-conservatives for decades. This isn't speculation or hyperbole, it's specifically laid out in their published plans: By hobbling or outright eliminating federal agencies responsible for executing the l…

That plus privatising a lot of it. Kills two birds with one stone, eliminate regulation and fill your pockets with cash.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#427

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

Try to talk to the people from the Sovereign Tech Fund, they have a history of sponsoring security relevant projects in the EU.

> Sovereign Tech Fund

It's actually been upgraded to the Sovereign Tech Agency now

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#428

Earlier quoted context omitted.

term is real... but is more like criticizing misuse of word startup. to be even more accurate it is what I said and not anything else

Maybe you don't see how it's bikeshedding. Ah well, let me try to explain. It's because it's like if someone had forgotten to validate the user's role in an endpoint in a Django app, and someone said that they should have used Rails because it's easier to understand. In reality both are easy enough to understand to be able to do an authorization check, and the framework isn't the issue. So the person suggesting Rails…

We're getting into pedantic arguments, but bikeshedding is when multiple people argue to death about the easy stuff because it's easy, and don't argue at all about the actually hard stuff, because none of them know enough to argue about it. I don't know what your example is, but it's not bikeshedding.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#429

The real irony here is that a lot of ycombinator founders and the people reading HN were exactly the ones making this possible and now start to wonder why the snake eats its own tail.

exactly; I hope ycombinator and its proponents can enjoy living in the ancap fantasy land where you have to pay to be alerted for a climate change fueled mega hurricane (also caused by this exact same reckless, unregulated greed) because NOAA was disbanded. Billionaires shouldn't exist, but neither should millionaires.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#430

Earlier quoted context omitted.

Not talking about politics is itself a political position (in favor of status quo).

Depends. We’re a small, very international startup and have a super strict “no politics” policy. Politics and work are not a good combination when you’re employing people from all over the world. But I would not consider it a political statement to adopt this policy.

I think it exists two different general ideas of what politic mean.

For some (including me), politics are, following the oldest definition: 'how do I and fellow humans organize ourselves to live together' this often leads to a belief that everything is politics (for me it's true, but it's a belief, not a fact).

For other, I think that when they say politics, they think of geopolitics and partisanship, which is fair, because it's how politicians and political journalists themselves define politics. For this group, hopefully, not everything is politics.

So to me, this disagreement about wether or not all is political is often semantic rather than ideologic.

Post reply on HN