Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

521–530 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#521
post #373

It’s a reckless move to cut funding so abruptly, but taking a step back from the short-term chaos, it probably is an anomaly that this was government funded. All of private tech relies on it, and private tech is big enough to pay for it. I hope that the trillion dollar babies consider this an opportunity to pool together to form a foundation that funds this, and a bunch of other open source projects run by one random…

> it probably is an anomaly that this was government funded. All of private tech relies on it, and private tech is big enough to pay for it. I mean doesn't big tech and the people they give salary money to pay taxes? Ground transportation companies rely on public roads and but we fund it because having the infrastructure is an economic multiplier. I'm not arguing in favor of funding the CVE program, I just don't thin…

Opinions vary on what the purpose of government is, but if you take the view that the government's priorities should be providing services that are impossible, inefficient, or unethical to provide privately, then I don't see the CVE program making the cut, when the tech industry is collectively flush with resources and has every incentive to form an industry consortium to take it over.

A modern Open Group, perhaps?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#523

Earlier quoted context omitted.

Germany had with under the best deal for gas possible with Russia, I don’t understand the sentiment calling it a vulnerability. There is still a working pipeline available and Russia stated clearly if would continue delivering gas, if Germany wants to.

> There is still a working pipeline available and Russia stated clearly if would continue delivering gas, if Germany wants to. You conveniently leave out that minor detail that it was RUSSIA who stopped the gas. Germany tried hard to keep it going, even making a sanction-exemption or a Siemens turbine repaired in Canada, which according to Russia was needed. Only that when they were to receive it nothing happened, ga…

Nordstream 1 which had if I recall correctly one working turbine left and went into inspection during which an oil spill was noticed and the restart of the service was postponed. Shortly after Nordstream 1 Pipeline A + B and Nordstream 2 Pipeline A was been blown up. It’s up to debate if the oil spill which was uncovered during the inspection which postponed the gas delivery was a political move. The turbine, which underlies sanctions, should have been still in transit during that time and even if delivered useless.

There is still Nordstream 2 Pipeline B intact available to deliver gas and it uses Russian made turbines compared to Nordstream 1.

The whole discussion is very special to say the least if you leave out that some adversary blow up the infrastructure.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#524

Earlier quoted context omitted.

Not talking about politics is itself a political position (in favor of status quo).

It's in favor of not having relationships break down in your community/company. Only a small percentage of people are able to handle fundamental disagreements calmly and without it bleeding over to other interactions. Will the SE and sales guy work as well together if the former knows the latter donates half his commission money to organizations that help kill babies?

Turning the question around, will the SE and sales guy work as well together if the former knows the latter donates half his commission money to FSF while the other is hard advocate for commercial software?

Politics are across all layers, including at technology decisions.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#526

Earlier quoted context omitted.

Not talking about politics is itself a political position (in favor of status quo).

No it’s not. It’s having discipline to not pollute unrelated conversations with your politics. I am very against the status quo but I don’t complain about it to a bunch of anonymous usernames on a forum focused on technology. You can believe something without proselytizing.

Technology and the consequences of using technology are inherently highly political.

New or improved technologies shape communities.

Ignoring that is a political statement as well.

Just see how online media has changed discourse, how Amazon changed retail business, how business analytics change the way businesses work, how always being connected changes relations, ...

When developing technologies one can be Wernher von Braun "(where the rockets land and whether they contain explosives is) not my department" or one can consider consequences.Both are a political position, with consequences.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#527

Earlier quoted context omitted.

"the government" aka "We the people". It is in all our interest. This is like asking why the government is responsible for roads.

> This is like asking why the government is responsible for roads. Thought experiment: If roads were built by private companies, could a Government justify the expense maintaining a database of all the potholes?

Pot holes do not enable fraud, ransom schemes, data breaches, denial of essential services to millions of people, and so on.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#528
post #249
post #52

Earlier quoted context omitted.

and then a random 9.8 critical comes that affects some software you have in a way that makes it a 0 in your environment but it doesn't matter cause the cve tanks your organizational Security Score (tm) by 10 arbitrary points and management is wondering when you'll secure the company again because the Security Score is their only tangible deliverable to measure success

Spot on. Vulnerability scanners that make up an organizational Security Score (TM) tend to operate at the wrong level of abstraction, flagging some library somewhere that never runs and has nothing to do with your production flow or architecture, or some test keys with zero security impact. Go explain that to management, because obviously the security tools are right and you are wrong. This sad state of affairs is un…

And it's not enough to explain it to management, you also need to explain it to your ISO auditors, your customers et cetera ad nauseam.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#529

Earlier quoted context omitted.

>They've been aware of the risk of relying on the US for software security for years, but AFAIK there have been no efforts to do anything about it. Indeed. Just as Germany knew their economy is vulnerable to Russian gas and did nothing about it, even after the 2014 invasion of Crimea. Just as the west knew moving their entire manufacturing sector to one country would make them vulnerable, but choose to ignore it beca…

> I never EVER saw politicians act proactively for the good of the nation or the people, This is almost certainly because those cases don't make the news.

It's certainly because they have a belief based in ideology, not fact.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#530

Earlier quoted context omitted.

It's in favor of not having relationships break down in your community/company. Only a small percentage of people are able to handle fundamental disagreements calmly and without it bleeding over to other interactions. Will the SE and sales guy work as well together if the former knows the latter donates half his commission money to organizations that help kill babies?

but letting > the SE and sales guy never find out about their shared passion is kind of cruel, too?

It's not uncommon for one side to come out with their position/interpretation/belief whether it's passion or not.

Maybe at a work function, team party, conference, etc.

Post reply on HN