Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

601–610 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#601
post #400

Earlier quoted context omitted.

I fear the situation either ends badly or in a bloodshed. They aren't respecting the courts, so assuming they will accept defeat in elections is naive.

Maybe that's the only way that people can learn.

People can learn once the world puts most of its money into education.

The unfortunate part is that education is often also part of propaganda and spinning history for said propaganda. These days I wish education had a bigger emphasis on history and history should be looked at from different angles, like how the same thing is being taught from different angles.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#602

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

The European, GDPR compliant subnet of the Internet Computer could suit your needs. The app would be decentralized out of the box and it can't be shut down by a single entity like a traditional cloud provider or nation state. Hosting 100GB costs about 500$ per year [0]. This is not a traditional hosting provider, it's a decentralized cloud. Reach out on the forum [1] or to me if this sounds like a good fit to you (I…

Seems way overkill & unnecessary. Wouldn't the e.V. (foundation) especially with FOSS backend/frontend already ensure continued operation? Also if it's about redudancy/resilience it seems like good ol' torrent/ipfs or even a dedicated dht (if you really want to have fast updated content) would be much more efficient.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#603

Earlier quoted context omitted.

>>They thought they voted for something different Like what exactly? I mean the guy ran on cutting the budget by 2 trillion. In his last term he gave tax breaks yo the rich. Where did they think the cuts were coming from? He ran very hard on raising tarrifs. Which demonstrably raise prices (thats literally their goal.) But now people claim "I didn't vote for this." In truth they voted for him because he was the Repub…

> Where did they think the cuts were coming from? When someone hands you a pencil, you don't wonder what variety of tree the wood came from, or what paint chemistry was used for the coating. It's a pencil. You might have broad opinions on whether the one in your hand is comfortable to use, and sharp - but you leave the details to the pencil makers. About 70% of the population engage with politics the same way: Leave…

This pencil was proudly advertised as being comprised of the remains of all that was decent in humanity. The fact that it wrote in blood was gleefully touted and cheered.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#604

Earlier quoted context omitted.

Germany had with under the best deal for gas possible with Russia, I don’t understand the sentiment calling it a vulnerability. There is still a working pipeline available and Russia stated clearly if would continue delivering gas, if Germany wants to.

>I don’t understand the sentiment calling it a vulnerability - You're Germany. - You join NATO for protection from Russia, an actor with a long history of military aggression[1] - Your export economy is based on manufacturing. - The energy driving your manufacturing sector is ~60% cheap gas from Russia, your military aggressive partner. - Russia invades Georgia in 2008 and Ukraine in 2014 to no ones surprise - Leader…

[dead]

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#605

Earlier quoted context omitted.

To play devil's advocate - it's horrible when gaming, programming, business or even porn forums get overrun by politics. It's not that the political topics are unimportant but all my feeds just end up looking the same as each other and the same as a newspaper app. I hate election nights because of this.

"porn forums" is a thing?

They’re so much a thing that they came back the other way and overran politics itself in the North Carolina governor’s race last year

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#606
post #476

> A coalition of CVE Board members launched a new CVE Foundation "to ensure the long-term viability, stability, and independence of the Common Vulnerabilities and Exposures (CVE) Program." > https://www.thecvefoundation.org https://mastodon.social/@serghei/114346660986059236

This kind of a consortium needs to explicitly avoid being captured by both the product vendors (who could be incentivised to manipulate the CVE issuance process to support their own remediation timescales), and by security companies (who could be incentivised to obtain a competitive advantage via preferential access to the CVE database). It isn't impossible for a commercially-funded organisation to avoid this kind of…

Then there were two: https://gcve.eu

Plus the proposed "Foundation for Standards and Metrology (FSM)" to build on NIST, https://democrats-science.house.gov/bills/the-expanding-part...

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#607

I'm surprised that it was USA's responsibility to fund this in the first place. Why weren't other countries providing funds?

Because USA was a superpower that can afford it easily. Taking the leadership in everything is quite cheap price to pay when the other end of the bargain is everyone else has to follow you. Now of course USA is ceasing (voluntarily, by stripping down every international soft power effector in government) to be a superpower, to the great glee of dictators all around the world. The "we can't afford being great" is a di…

The nazis don't think that though, uh I mean conservatives. After they've burned down everything, they expect still to be a superpower somehow. Do they think they can just start a war with everyone who doesn't play ball? It's hard to comprehend what their rational is, if there is one.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#608
post #239

Earlier quoted context omitted.

It’s Way Better than what we had before: software vendors making even arbitrarier decisions about how to classify them. There are far too many bad actors for us to operate as an industry with no yardstick.

I disagree that it is Way Better than before. A judgement call is worth more than a team wasting effort chasing irrelevant pseudo-vulnerabilities being reported as vulnerabilities. A broken yardstick is worse than no yardstick.

But that's an issue organizations bring upon themselves, by defining semi-arbitrary KPIs that are used without proper interpretation. It's not directly caused by CVEs or assigned scores. It's like blaming git that it count lines in diffs, because your company created a KPI that measures developer's based on LOC changes.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#609
post #481

Earlier quoted context omitted.

Honest question: Does this not already exist? - https://vulnerability.circl.lu/ - https://osv.dev/ - https://vuldb.com/ And a few others?

https://www.enisa.europa.eu/news/another-step-forward-toward...

This is (without any irony) the first useful thing I see from ENISA.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#610

If there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in th…

Why EU? Canada may be another friendly option

Canada’s been described as the Ukraine of North America.

Let’s not site global critical infrastructure within 150km of US land borders for a generation, please.

Post reply on HN