Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

581–590 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#581
post #171

So who will maintain it then? Either the EU or China I suppose. They can easily fund it. Maybe the Dutch should go ahead.

Us Dutch have https://advisories.ncsc.nl/advisories although a lot of that is just analysing CVEs and their impact on society.

An EU solution would probably be much better. Would suck for Americans, though, they'd need to get up early to meet European office hours.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#582
post #51

I wish this hadn't happened. I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do t…

> I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? The National Vulnerability Database has been unable to keep up with the flow of CVEs for over a year now: - https://anchore.com/blog/national-vulnerability-database-opa... - https://www.cyberreport.io/news/cve-backlog-update-the-nvd-s... - https://www.ibm.com/think/insights/cve-backlog-update-nvd-st...…

You assume there's a plan. Interesting.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#583

Earlier quoted context omitted.

Perfect exmple of the "one-deep" conservative response. PP is looking for a pattern, finding, and abstaining from questioning or contextualizing it: Engaging only with the first or most obvious layer of an issue—never going deeper into context, nuance, or systemic causes. The quickest counterexample that comes to mind is Elizabeth Warren's Consumer Financial Protection Bureau. It has returned billions to American cit…

I'm gonna have to stop engaging with you here if you start a comment by accusing someone to be a conservative. If your first reaction is putting people into political/ideological camps in order to make their arguments weaker and easier to attack form a holier than though political/ideological angle, it's game over for me as I like to judge actions objectively based on the outcomes, not conservative vs democrat, left…

It is damningly simple, the root cause beneath far too many issues our advanced civilization faces: we have a global adult immaturity issue, species wide. The leaders that are crony capitalist and widely populist are in truth terribly immature public figures. Our incredibly short sighted (also an immature behavior) news and analyst media pretends to be adult while never really having any solutions that are not plain school yard bullying and tribe glorifying. And the public is only allowed outsider fringe opportunities to include their voice in these public non-debates. We do not produce adults anymore, we produce a civilization of Lindsay Lohans that think they are adult men and women.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#584
post #475
post #387

Earlier quoted context omitted.

HN and founders will say "no politics here" on the regulated internet, drinking regulated water, eating regulated food, breathing regulated air.

Will all of these things be free of micro plastics and other contaminants? If so, is there a signup page?

Wait these regulations haven't created total perfection? Better burn the whole thing down.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#585

Earlier quoted context omitted.

Did they promise to rebuild? If I'm giving them the benefit of the doubt (which I hate), it's a shotgun approach; cut things relentlessly and see what falls apart. Chaos engineering applied to a country and / or the world.

That’s exactly what it is, and they said as much repeatedly while campaigning. Voters, in their zealotry against the perceived status quo, failed to realize how much of what we have right now you don’t want to cut recklessly, as well as just how reckless the people that they were choosing to do that job were.

> in their zealotry against the perceived status quo,

Perceived, not actual, because spreading lies and misinformation is what makes the most money for the ad sellers that make up 90% of our industry.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#586
post #536

Earlier quoted context omitted.

So if the govt stops paying them they'll continue to do the work for free?

More likely they will seek funding from companies and other organizations, as every other foundation/consortium of this kind does.

[deleted]

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#587
post #536
post #476

> A coalition of CVE Board members launched a new CVE Foundation "to ensure the long-term viability, stability, and independence of the Common Vulnerabilities and Exposures (CVE) Program." > https://www.thecvefoundation.org https://mastodon.social/@serghei/114346660986059236

So if the govt stops paying them they'll continue to do the work for free?

They're converting to a nonprofit, so instead of federal funding they will need funding from big tech companies.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#588
post #481

Earlier quoted context omitted.

https://www.enisa.europa.eu/news/another-step-forward-toward...

> https://euvd.enisa.europa.eu/ They already did it. Great! Maybe we can ask them how to contribute to their software, as it seems to be proprietary at the moment? edit: lol, their manifest.json is still the React boilerplate: https://euvd.enisa.europa.eu/manifest.json Their database seems to also only contain fairly recent CVEs (up until 2019? some CVEs are missing...) and not before that

All major powers have at least one each, some few for different parts of bureaucracy. Most of them are probably minimum budget operations just rsync-ing US CVD but they exist.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#589
post #536
post #476

> A coalition of CVE Board members launched a new CVE Foundation "to ensure the long-term viability, stability, and independence of the Common Vulnerabilities and Exposures (CVE) Program." > https://www.thecvefoundation.org https://mastodon.social/@serghei/114346660986059236

So if the govt stops paying them they'll continue to do the work for free?

How else will they continue burning out open source maintainers with bullshit?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#590

I'm trying to steelman but I really can't think of a non- nefarious justification for this

It's a dying empire, really nothing else to say. The USA led world order is over, we've voted ourselves out of it, and now need to learn how to deal with that.
Post reply on HN