Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

61–70 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#61
post #51

I wish this hadn't happened. I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do t…

> I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides?

This was not a carefully-weighed decision based on a cost-benefit analysis. This was a political order, consistent with the administration's policy of "cut everything, recklessly, indiscriminately."

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#62
post #52
post #48

Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?

and then a random 9.8 critical comes that affects some software you have in a way that makes it a 0 in your environment but it doesn't matter cause the cve tanks your organizational Security Score (tm) by 10 arbitrary points and management is wondering when you'll secure the company again because the Security Score is their only tangible deliverable to measure success

[deleted]

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#63
post #48

Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?

I don't know of anyone who doesn't quickly become exhausted after running a CVE scanner on their code.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#65

If you work on OSS software on CVE management, then you already know that NVD funding reductions have been ongoing for more than a year. April 2024, https://nvd.nist.gov/general/news/nvd-program-transition-ann... NIST maintains the National Vulnerability Database (NVD).. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing backlog of vulnerabilities.. based on.. an increase in software…

I did find this post to be non-helpful and confusing. It would be helpful to edit it (or write differently in the future) to clarify that the sudden defunding event occurring today is separate and not related to the previous funding cuts. If that's the case.

Is there no connection between 2025 funding cuts and previous ones? e.g. If a year of work after the previous cuts resulted in an open-data collaboration between NVD and commercial vendors to share a subset of CC0 vulnerability metadata, could that industry collective now argue for government to share (with companies) the burden of funding an open, decentralized program for CVE tracking? Commercial vendors could still offer additional metadata and analytics, over and above the public baseline.

Edit_1: found a proposed bill, April 2025, https://fedscoop.com/public-private-partnerships-bill-nist-h...

> A bipartisan bill that would establish a nonprofit foundation aimed at boosting private-sector partnerships at the National Institute of Standards and Technology was reintroduced in the House and the Senate.. the proposed foundation structure was described as replicating similar nonprofits that support public-private partnerships at other science agencies.. we encourage a strategy that leverages NIST’s leadership and expertise on standards development, voluntary frameworks, public-private sector collaboration, and international harmonization.. NIST’s funding has been in focus following a budget cut of roughly 12% to $1.46 billion in fiscal year 2024.

Edit_2: is there a shortage of database rows, or people to write a shell script? Why not pre-allocate N CVE IDs for every CNA, while a new plan is worked out? At least one random commercial vendor could foresee the shutdown early enough to reserve CVEs.

> Garrity posted on LinkedIn, “Given the current uncertainty surrounding which services at MITRE or within the CVE Program may be affected, VulnCheck has proactively reserved 1,000 CVEs for 2025,” adding that Vulncheck “will continue to provide CVE assignments to the community in the days and weeks ahead.”

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#67

I'm trying to steelman but I really can't think of a non- nefarious justification for this

We have a 2tn deficit. If Congress wants to fund this, they need to make it mandatory spending and raise taxes.

This is an absolute pittance compared to the total budget. And considering the current administration wants a $4T tax cut they are not interested in trimming the deficit at all.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#69
post #52
post #48

Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?

and then a random 9.8 critical comes that affects some software you have in a way that makes it a 0 in your environment but it doesn't matter cause the cve tanks your organizational Security Score (tm) by 10 arbitrary points and management is wondering when you'll secure the company again because the Security Score is their only tangible deliverable to measure success

Yeah like when we bundled in a .js library for client side date processing that has a CVE affecting node.js servers with high score. Our auditors don’t care they tag the whole app as high risk. It doesn’t even run on the server!

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#70

Earlier quoted context omitted.

We have a 2tn deficit. If Congress wants to fund this, they need to make it mandatory spending and raise taxes.

Or cut from $877B in defense spending instead? https://usafacts.org/government-spending/

Listen, I hate the debt, but we have an income problem, not a spending problem. The military looks like a waste, but it does more than build bombs i.e research etc.

The issue we have is that republican every chance they get since the 1970s have cut taxes. And then blamed democrats for causing the deficits. We don't need smaller governments. We need a reasonable tax system that taxes people. It can be progressive like it was before we decided rich people just need it easier than poor people.

Yes, I will pay more taxes sign me up, especially if they can finally fix the roads and fund research. The problem is my taxes as a middle-class person go up and rich people get a tax cut. It's stupid. I like water provided by government utilities, I like planes that don't crash into stuff because there are air traffic controllers. These things used to work because we paid for them. When you buy cheap you get cheap.

Post reply on HN