Live data from Hacker News

CVE program faces swift end after DHS fails to renew contract [updated]

csoonline.com

871–880 of 1001 posts

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#871

Earlier quoted context omitted.

Yeah, most businesses need window cleaners too. If you're a window cleaner and you complain about all the birds shitting on windows, I dunno what to tell ya. If you're working in compliance either A) you're stuck in your compliance job, that sucks, CVSS scores aren't the reason why though. B) you enjoy compliance. C) you should change jobs.

Often it is a second order impact. This creates a bunch of work for the compliance people, but then the compliance people end up competing a bunch of work for everyone else. If you count anyone who might have to follow compliance as working in compliance, then I purpose that there isn't enough non-compliance jobs to go around.

Hmm I dunnno I think

a) If you are having to do busywork for compliance reasons, you are either disempowered to push back on bullshit work (case A above, unfortunate, but your job was gonna suck anyway), or it's not really a second order effect, you work in compliance in a meaningful way.

b) Compliance bullshit seems to expand into the space available to it. Nobody thinks CVSS scores are meaningful, the fact that they feed into compliance processes is not the CVSS scores' fault it's the compliance machine just globbing onto random bullshit as its expansion continues. If you took away CVSS scores it feels like it would just glob onto something else instead.

Anyway, in the end I think we aren't disagreeing about that much. I think they're silly, if someone wanted to get rid of them I wouldn't try to defend them at all. I just wouldn'e be the person to push for that.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#872

Believe me when I say that DOGE is filled with smart people (I know a few of them). Just because they're scattershot cutting doesn't mean they're stupid.

I guess I'm naive, but given the current situation, wouldn't a smart person resign from DOGE? If I were smart and highly employable, like these guys, I would not want to be associated with all the indiscriminate firings of DOGE.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#874
post #838

Earlier quoted context omitted.

There wasn't any evidence, that's the problem. It was all opinion. Trump said a lot of stuff before this election, but he said a lot of stuff before his first one too. When people disagreed on what he might do, it was all guesses. There was no evidence to base anything on. Would his second term be restrained by people around him like in his first? That would be an evidence-based extrapolation. Would tariffs be all ta…

[flagged]

Well your theory would seem to be directly contradicted by the fact that he's been musing about figuring out ways to have a third term.

> Hindsight 20/20? Oh, I saw all of this, and I knew all of this would happen.

Great. So I assume you made massively leveraged bets to short the stock market and are now rich?

Or maybe you didn't, because talk is cheap, and you didn't actually know anything. Because nobody knew anything.

> Stupid Americans.

Please take this kind of talk elsewhere. Trump didn't even win 50% of the vote. But regardless, insulting entire nationalities is never called for.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#875
post #865
post #829

Earlier quoted context omitted.

Project 2025 lays out a clear vision for the privatization and decentralization of federal functions. It’s not subtle—it explicitly calls for it. Separate from whether we support this or not: Trump is doing—or promising to do—exactly what he said he would. We can disagree with the policies, but it’s not accurate to say he or his team are directionless or incompetent. They have a coherent (if controversial) agenda. So…

Trump said he was not going to follow the project 2025 plan. So you're making two immediately contradictory claims that Trump is doing what he said he would, and is following the project 2025 plan. That's not coherent. You're suggesting a privatization plan exists, and want to debate its merits, but I see no sign such a plan is being adopted. E.g. who is enacting the plan? When is the comment period? Who do we send o…

> Trump said he was not going to follow the project 2025 plan.

He didn’t convincingly reject it, though, and his distancing was only convincing to people who were looking for an excuse to ignore it with the way he pretended not to know the people behind it when 31 of the 38 authors were members of his first administration, his campaign was in close contact throughout, and he certainly didn’t put much effort into rejecting specific policy proposals.

I think this is a case where different audiences got different messages. The hardcore base knew he was lying since it had all of their red meat issues, informed Democrats knew he was lying because actions speak louder than vague denials (e.g. if you don’t agree with someone’s policies, you wouldn’t let them have a role in your campaign and you’d be able to say what you’d do differently), but he gave the media and casual voters just enough to make it harder for Biden/Harris to land attacks which we now know were fully accurate.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#877

Earlier quoted context omitted.

You're right. I don't understand why the EU wasn't funding it and isn't funding it now. I thought they're united against Russia?

because they already do? https://euvd.enisa.europa.eu/ please, stop spreading your weird anti-europe views

Great. Then there's no loss here. What's the big deal?

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#878
post #51

I wish this hadn't happened. I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do t…

> I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? Come on, are you living under a rock right now? There are massive indiscriminate funding cuts to anything that Elon/Doge deems to be "fraud", and they explicitly do not care about the collateral damage. This is not about the DHS or "compartmentalization". This is just a politician running amok and havin…

Also there has been funding cuts to all agencies where Musk is currently under investigation. NHTSA is getting cut so they can't get in the way of Tesla.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#879

Earlier quoted context omitted.

I’m a little hesitant to trust a CVE database operated by private industry on the grounds of conflict of interest for that reason, too.

I am quite hesitant to trust the DOD to keep track of software vulnerabilities. Some parts are developing and exploiting vulnerabilities. And given a fresh feed of what people find, and usually a delay from notification until publication, which may sometimes just be a bit longer of a delay, would allow the DOD to weaponize the vulnerability for their own use as well.

This contract is funded by CISA, which is an agency within the Department of Homeland Security, not DoD. As far as I'm aware, there are no components of DHS with Title 10 or Title 50 authorities to conduct cyber operations, unless you count the Coast Guard but they normally operate under Title 14. So there really should be no conflicts of interest as no one in the DHS is authorized to exploit vulnerabilities as part of cyber operations.

Re: CVE program faces swift end after DHS fails to renew contract [updated]

#880
post #48

Weren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?

Classic "oh its broken so throw it all away".

It's the way it is because there isn't a good alternative. They cannot possibly know every environment that we operate in.

To this day we still have large corporations down playing their issues, and it was way worse 20 years ago.

Post reply on HN