vibe coding could not have come at a worse moment.
CVE program faces swift end after DHS fails to renew contract [updated]
631–640 of 1001 posts
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#632Earlier quoted context omitted.
> cut everything, recklessly, indiscriminately Mostly discriminately, tbh.
[flagged]
The OP said indiscriminately, which means they're cutting uniformly across the board. I responded with "mostly discriminately" which means they're more selectively cutting based on prejudice. You then linked me a data point where you show they cut funding because it has the word "homo" in it and tell me to "get a hold of myself".. but your link would directly support what I've said?
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#633Earlier quoted context omitted.
Everything was always political. Laws, the economy, conflcit. How is any person not affected by these? The government is responsible for all or a large part of how a country functions. People who say "I'm not political" are deflecting to avoid conflict
One of the benefits a working democracy conveys to its citizens is that they largely don't have to care about politics. They can trust that government action is relatively consistent over time, that laws will be enforced fairly enough, that their property will be protected to a reasonable degree, that the currency will be reasonably stable, that the roads will be maintained, that some public transport will be availab…
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#634FWIW, I've never understood why this sort of thing wasn't just directly handled by the NSA --- aren't they the group which should be tasked with cybersecurity? I always suspected that "Department of Homeland Security" would lead to Banana-republic-like shenanigans --- could we defund them?
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#635Earlier quoted context omitted.
Basically when any software/library/whatever has a vulnerability, they have to communicate that out themselves, in some format. If I'm developing a product built on 20 libraries, it won't just be a matter of scanning CVEs for major vulnerabilities any more, so I'm more likely to miss one. "always update" doesn't always work, when to manage a product you realistically have to version pin.
They surprise is: they won't. This will weaken the West. This is dangerously stupid.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#636Re: CVE program faces swift end after DHS fails to renew contract [updated]
#637Earlier quoted context omitted.
I can't believe what a bunch of bollocks this administration is. I couldn't believe it the first time, and this time I thought "Well at least I'm ready, it will be a lot like last time" and it's so much worse
> it will be a lot like last time A lot of people seemed to have had this theory, despite all the evidence to the contrary.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#638The latest contract[1] (I hope this is the right one) for MITRE's involvement with CVE and CWE programs was USD$29.1m for the period 2024-04-17 to 2025-04-16 with optional extension of expenditure up to USD$57.8m and to an end date of 2026-04-16. Seemingly MITRE hasn't been advised yet whether the option to extend the contract from 2025-04-16 to 2026-04-16 will be executed. And there doesn't appear to be any other pu…
I can't figure out why the hue and cry wasn't raised until the very last minute. Did they not know a month ago that they were running out of time? Is it standard practice for the government not to say they're going to extend the contract until the day beforehand or something?
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#639Earlier quoted context omitted.
>>They thought they voted for something different Like what exactly? I mean the guy ran on cutting the budget by 2 trillion. In his last term he gave tax breaks yo the rich. Where did they think the cuts were coming from? He ran very hard on raising tarrifs. Which demonstrably raise prices (thats literally their goal.) But now people claim "I didn't vote for this." In truth they voted for him because he was the Repub…
> Where did they think the cuts were coming from? When someone hands you a pencil, you don't wonder what variety of tree the wood came from, or what paint chemistry was used for the coating. It's a pencil. You might have broad opinions on whether the one in your hand is comfortable to use, and sharp - but you leave the details to the pencil makers. About 70% of the population engage with politics the same way: Leave…
> Do they expect to be disappointed?
Aurornis said their relatives were shocked.
Re: CVE program faces swift end after DHS fails to renew contract [updated]
#640Earlier quoted context omitted.
> But maybe this is an opportunity to do CVE better. Okay, how? This sounds like looking for lemonade in a genocide.
> This sounds like looking for lemonade in a genocide. It really doesn't. This level of catastrophising has no point. It would be nice if CVE continued to exist, but it wasn't close to perfect, and perhaps it can continue in another form. There's no particular reason the US taxpayer has to sponsor global security threat tracking any more than any other taxpayer or customer.
The point of having a global, shared database is a single, authoritative (more-or-less), semi-vetted repository that can hold vendor accountable externally without digital amnesia or downplaying issues, and global unique identifiers. If that takes an international nonprofit funded by bits of the free world who are okay with investing in commonwealth infrastructure, so be it. Those who don't understand what they're destroying so casually are ignorant, and possibly evil if they do understand.