Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

801–810 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#801

The contract with MITRE has been extended. https://www.forbes.com/sites/kateoflahertyuk/2025/04/16/cve-... My guess indefinitely. DOGE might be a bunch of idiots, but in the entire DOD, there are non-idiots.

[flagged]

Better for who exactly? Malware authors?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#802
post #48

Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?

Yes it earnestly needed new direction and leadership.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#803

I'm trying to steelman but I really can't think of a non- nefarious justification for this

I think it’s ignorance and arrogance. The US seems to be on a path to lose technological and science leadership. The current leadership doesn’t seem to understand things that aren’t flashy. I wonder when they’ll dial back on food safety. I am sure RFK knows some vitamins that protect against salmonella

According to the radio this morning, they're currently working to close all the FDA branches that do food safety testing, so, good guess?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#804

The contract with MITRE has been extended. https://www.forbes.com/sites/kateoflahertyuk/2025/04/16/cve-... My guess indefinitely. DOGE might be a bunch of idiots, but in the entire DOD, there are non-idiots.

[flagged]

Actually idiots could still end up make improvements. Won’t stop them from being idiots. But what the commenter is saying is the ones who recklessly cut programs trashing away all the effort that went into the program are idiots. They are trying to make a thriving government have a reputation for failure and unreliability.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#805

Earlier quoted context omitted.

Not talking about politics is itself a political position (in favor of status quo).

No it’s not. It’s a position that comes from experience of knowing that it’s a complete waste of time because nobody’s mind is being changed. Further, there are entire segments of political groups who just want to assume your beliefs like a political straw man so they can denigrate you. It’s an unhealthy waste of time and that doesn’t truly hit you until you invest the time in talking to an otherwise rational person,…

You don't need to completely change someone's positions for it to be worthwhile. This is a thread about something that has directly to do with HN's usual tech topics, and it would be hard to not talk at least a bit about the political aspects.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#806

The contract with MITRE has been extended. https://www.forbes.com/sites/kateoflahertyuk/2025/04/16/cve-... My guess indefinitely. DOGE might be a bunch of idiots, but in the entire DOD, there are non-idiots.

It doesn't appear to have posted to FPDS yet: https://www.fpds.gov/ezsearch/fpdsportal?q=PIID%3A%2270RCSJ2... The contract expired today, but had an option period through March of 2026. DHS just needed to exercise the option. Edit: Note the contract ended today April 16 - so performance would stop midnight tonight if the option wasn't exercised. Government contracts routinely go down to the wire like this, and often…

> Did CISA signal to MITRE that they weren't going to exercise the option?

An internal letter sent to CVE board members was making the rounds yesterday warning the current contract ("contracting pathway") would expire. The letter was authenticated by Brian Krebs[0]. Once Krebs authenticated the letter, people more or less assumed CISA was pulling funding, at least based on the infosec social media posts I saw.

CISA officials responded to multiple media inquiries (including the OP) with a statement that more directly said the contract would expire:

  Although CISA’s contract with the MITRE Corporation will lapse after April 16, we are urgently working to mitigate impact and to maintain CVE services on which global stakeholders rely.[1]
0 - https://krebsonsecurity.com/2025/04/funding-expires-for-key-...

1 - https://www.csoonline.com/article/3963190/cve-program-faces-...

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#807
post #672

To the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.

The problem with discussing politics is that it gives you the kicks. Its very easy to get into a feedback loop and take things quite far off civility. I am also guilty of it, many times. IMHO there needs to be a mechanism for breaking the loop and then we can have civil online political discussions. Unfortunately most places just ban it or ban those who got into the loop, either way its ugly. IRL when discussing poli…

The loop is intentionally being closed and sped-up by enemies of the USA who want to exhaust the USA in every way possible.

After the infekktion of 2015, moderators of Right-leaning discussion boards started amping up their censorship. Left leaning and moderate discussion boards still tend to be more moderate, letting most discussions in and censoring less.

Most of the time, one side is trying to play an equal field, while the other shits all over it and just yells "Winning!"

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#809
post #739

Earlier quoted context omitted.

My guess is that they’ll be phased out next year. The long-term goal seems to be transitioning the CVE program into something more like an industry-led consortium. (If you did not notice they operate zero budgeting approach: cut everything and if something is very important reverse it. But you cut first and then ask questions.) It’s worth noting that MITRE is a DoD contractor (with minor contracts from other agencies…

I’m a little hesitant to trust a CVE database operated by private industry on the grounds of conflict of interest for that reason, too.

I am quite hesitant to trust the DOD to keep track of software vulnerabilities. Some parts are developing and exploiting vulnerabilities. And given a fresh feed of what people find, and usually a delay from notification until publication, which may sometimes just be a bit longer of a delay, would allow the DOD to weaponize the vulnerability for their own use as well.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#810
post #373

It’s a reckless move to cut funding so abruptly, but taking a step back from the short-term chaos, it probably is an anomaly that this was government funded. All of private tech relies on it, and private tech is big enough to pay for it. I hope that the trillion dollar babies consider this an opportunity to pool together to form a foundation that funds this, and a bunch of other open source projects run by one random…

Considering the large number of government agencies that have sponsored the program, no, I don't think it was an anomaly: https://www.cve.org/About/History
Post reply on HN