33 ms·
CVE program faces swift end after DHS fails to renew contract [updated]
- deleted 1y ago[deleted]
- hulitu 1y ago> CVE program faces swift end after DHS fails to renew contract So CVE is a child of US 3 letter agencies ? Good to know.
- bytematic 1y agoWhat are the implications of this? No more centralized store of vulnerability information?
- neuronexmachina 1y agoAccording to Brian Krebs: https://infosec.exchange/@briankrebs/114343835430587973 https://infosec.exchange/@briankrebs/114343835430587973 > Hearing a bit more on this. Apparently it's up to the CVE board to decide what to do, but for now no new CVEs will be added after tomorrow. the CVE website will still be up.
- Incipient 1y agoBasically when any software/library/whatever has a vulnerability, they have to communicate that out themselves, in some format. If I'm developing a product built on 20 libraries, it won't just be a matter of scanning CVEs for major vulnerabilities any more, so I'm more likely to miss one. "always update" doesn't always work, when to manage a product you realistically have to version pin.
- cantrecallmypwd 1y agoThey surprise is: they won't. This will weaken the West. This is dangerously stupid.
- delulucrew 1y ago[dead]
- OhioMan2943 1y agoThis is deliberate. I just want to figure out the avenues of communication and coordination between trump admin and moscow so we can pin them down better.
- worthless-trash 1y agoSo, while arguably true, there wont be a single source of truth of new cve's. It doesn't however mean there wont be. I would imagine the only SANE option would be some kind of git repository where CNA's can collaborate. Probably run some code across to make the website that people can easily access. It's going to be a mess.
- joshuanapoli 1y agoIs MITRE's CVE program redundant with NIST's National Vulnerability Database? I'm having a hard time telling how the two are related, or if NVD is simply performing the same service as MITRE.
- Rebelgecko 1y agoI'm trying to steelman but I really can't think of a non- nefarious justification for this
- sneak 1y ago[flagged]
- viraptor 1y agoYet so far no volunteer has emerged and people who do run CNA are pretty busy with it.
- _zer0 1y agoI think sneak would volunteer to do it since it is pretty simple according to them.
- mlinhares 1y agoAny work people don't understand must be easy and replaceable by chatgpt. Just look at how easy people here think farming is.
- johnnyjeans 1y agoGrok becoming an artificial nepobaby running the entire CVE program with zero oversight sounds so fucking funny I don't even care, PLEASE god make this real holy shit I can't breathe at the thought
- stevekemp 1y agoThere were some, short-lived, projects/groups trying to run their own processes. DWF is one that I recall, though it is dead again: https://lwn.net/Articles/851849/ https://lwn.net/Articles/851849/
- Rebelgecko 1y ago
- transpute 1y agoIf you work on OSS software on CVE management, then you already know that NVD funding reductions have been ongoing for more than a year. April 2024, https://nvd.nist.gov/general/news/nvd-program-transition-announcement https://nvd.nist.gov/general/news/nvd-program-transition-ann... NIST maintains the National Vulnerability Database (NVD).. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing backlog of vulnerabilities.. based on.. an increase in software and, therefore, vulnerabilities, as well as a change in interagency support.. We are also looking into longer-term solutions to this challenge, including the establishment of a consortium of industry, government, and other stakeholder organizations that can collaborate on research to improve the NVD. Sep 2024, Yocto Project, "An open letter to the CVE Project and CNAs", https://github.com/yoctoproject/cve-cna-open-letter/blob/main/cve-cna-open-letter.txt https://github.com/yoctoproject/cve-cna-open-letter/blob/mai... > Security and vulnerability handling in software is of ever increasing importance. Recent events have adversely affected many project's ability to identify and ensure these issues are addressed in a timely manner. This is extremely worrying.. Until recently many of us were relying not on the CVE project's data but on the NVD data that added that information. Five years ago (2019), I helped to organize a presentation by the CERT Director from Carnegie Mellon, who covered the CVE backlog and lack of resources, e.g. many reported vulnerabilities never even receive a CVE number. It has since averaged < 100 views per year, even as the queue increased and funding decreased, https://www.youtube.com/watch?v=WmC65VrnBPI https://www.youtube.com/watch?v=WmC65VrnBPI
- kulahan 1y agoWhat has been ongoing for more than a year? The funding appears to have been cut off today, and both of these comments seem to talk about continuing work and how important it is. Do you mean to say that some form of threat to the NVD has been around for over a year now? Just want to be sure I'm parsing correctly!
- transpute 1y agoYes, NVD funding cuts and a growing CVE backlog began in late 2023. May 2024, https://therecord.media/nist-database-backlog-growing-vulncheck https://therecord.media/nist-database-backlog-growing-vulnch... > Moving forward, cybersecurity companies will have to “fill the void” .. NVD said in April [2024] that it is “working to establish a consortium to address challenges in the NVD program and develop improved tools and methods.” .. CISA acknowledged the concerns and outrage of the security community and said it is starting an enrichment effort called “Vulnrichment," which will add much of the information described by Garrity to CVEs. The second VulnCon event took place last week and no silver bullet has appeared, https://ygreky.com/2025/04/vulncon-2025-impressions/ https://ygreky.com/2025/04/vulncon-2025-impressions/ Vulnerability enrichment was mentioned in many talks. However, most organizations seem to handle it internally. There doesn’t appear to be momentum toward a shared or open source solution – at least not yet.
- bradac56 1y agodupe of a dupe https://news.ycombinator.com/item?id=43700258 https://news.ycombinator.com/item?id=43700258
- dang 1y agoI'm not sure, but the current article looks to have somewhat more information in it, so I've merged that thread hither instead.
- 9283409232 1y agoReminds me of Trump's first term where he said if we stopped testing for Covid, we'd stop catching new cases and case numbers would go down. If you stop testing for vulnerabilities then vulnerabilities go down. Easy stuff.
- dboreham 1y ago[flagged]
- goku12 1y agoThat's exactly what they're saying about the HHS cuts and the measles outbreak.
- flanked-evergl 1y agoWhat I don't get is why people make things up and then get angry at the thing they made up. Is there not enough real things to be angry at?
- mjevans 1y agoMr. President, Do you want China to get the reports instead, or do you want the NSA to have a lead time where the vuln's are useful tools?
- hsbauauvhabzb 1y agoIf you /s/China/Russia/, when asking Trump, it’s no longer a rhetorical question.
- hsbauauvhabzb 1y agoFor those reading, a fair few of my recent posts were downvoted after this comment, and it was initially flagged. If I violated some rule so be it, and I could care less about internet points, but it certainly feels like suppression of individuals based on individual posts which is a behaviour that could end up being the death of hn.
- mjevans 1y agoIt seems phrasing it in the form of a joke was too much. I was trying to convey (with levity/humor) WHY it should continue to be funded as well as the argument that should be made to the one currently in control of the spineless US Congress. Yes, fixing the vulnerabilities is important. However what the government probably does gain from it is an inside advantage in the lead time for vulnerabilities to protect against, as well as to exploit on adversaries.
- delfinom 1y ago[flagged]
- thepaulmcbride 1y ago[flagged]
- stego-tech 1y agoMan, I just can’t even muster the snark I usually have for these sorts of boneheaded decisions. This sucks, plain and simple.
- aprilthird2021 1y agoI can't believe what a bunch of bollocks this administration is. I couldn't believe it the first time, and this time I thought "Well at least I'm ready, it will be a lot like last time" and it's so much worse
- 01HNNWZ0MV43FF 1y agoA lot was lost in the midterms and Supreme Court appointments. Hopefully these 4 years energize people to vote. I know protesting and direct action and so on are also important, but the gradient is not negative for voting for every office you can vote for in every election.
- aprilthird2021 1y agoYes, the next elections are all I have to look forward to really.
- jjav 1y agoGiven the current government has blown off an unanimous 9-0 supreme court decision, right now I can't feel too optimistic there will even be more elections.
- hn_throwaway_99 1y agoI think there will be more elections, but I think they will be fraudulent, because I think Trump has shown he is adept at turning things around and then trying to pretend that what he's doing is analogous to what the other side has done. For example, a lot of people have forgotten, but the phrase "fake news" originally came about in the wake of the 2016 election about all the (actually false) misinformation that was spread on social media in the run up to the election. Trump adeptly then co-opted the term, so any news he didn't like he could just call it "fake news", and who was to say any news he called fake was any less fake than what people were calling fake before? My guess is the 2028 elections will be marked by fraud, and then when people protest or object, Trump and the Republicans will just say "Hey, you called all those Jan 6 protesters traitors and said the election was secure, how is now any different? Now you're all the traitors." The only belief that gives me hope these days is "History will judge the complicit."
- hansvm 1y agoWeren't there major problems with the current CVE implementation, especially with the waves of script kiddies and AI tools spamming the database and the fact that projects who take security seriously have little to no say in the "score" that gets assigned?
- czk 1y agoand then a random 9.8 critical comes that affects some software you have in a way that makes it a 0 in your environment but it doesn't matter cause the cve tanks your organizational Security Score (tm) by 10 arbitrary points and management is wondering when you'll secure the company again because the Security Score is their only tangible deliverable to measure success
- deleted 1y ago[deleted]
- idiotsecant 1y agoI feel that. So tired of management being completely uninterested in actual, actionable security holes but getting wildly spun up because they saw a notice with a big scary number that has absolutely no relevance in our architecture.
- deleted 1y ago[deleted]
- icameron 1y agoYeah like when we bundled in a .js library for client side date processing that has a CVE affecting node.js servers with high score. Our auditors don’t care they tag the whole app as high risk. It doesn’t even run on the server!
- czk 1y agothe auditors that sign off on your security to meet your clients requirements usually know way less about your security posture than your clients do its all just surface-level box-checking. most companies required to get 'penetration tests' just get an overpriced Nessus scan sold as a pentest and that meets their reqs.
- curtisszmania 1y ago[dead]
- ggm 1y agoI wish this hadn't happened. I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? I ask this, because I don't think anyone in the subject matter specialist space would have made a strong case "kill it, we don't need this" and I am sure if asked would have made a strong case "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior finance would do their own research (tm) and mis-understand what they saw in how other people work with CVE, and who funds it.
- hackyhacky 1y ago> I wonder what level of compartmentalisation inside DHS means they didn't see this as having sufficient downsides? This was not a carefully-weighed decision based on a cost-benefit analysis. This was a political order, consistent with the administration's policy of "cut everything, recklessly, indiscriminately."
- tmpz22 1y agoDestroy, destroy, destroy. Promise to rebuild but don't. Take it all.
- cantrecallmypwd 1y agoVampire capitalism. They want civilization to break down so they can offer a solution for profit. The enemies of all people and life on the planet are a tiny group of oligarchs and their supplicants.
- 01HNNWZ0MV43FF 1y agoNot unlike the manga Berserk
- CamperBob2 1y agoThis isn't capitalism, any more than arson, burglary, or extortion is capitalism. Get some new material.
- yawnxyz 1y agoI guess their new business model is to sell zero days to the highest bidder
- alephnerd 1y agoThe private sector zero day market collapsed last year with Zerodium - corporate bug bounties, nation states in-housing offensive security operations, and the democratization of knowhow destroyed the Zero Day market.
- nkassis 1y agoMy tinfoil hat says they want to privatize this through one of the administrations friends. A disastrous decision here.
- 9283409232 1y agoPalantir is about to get a contract.
- goku12 1y agoI thought that the point of the CVE database is to improve security, not wreck it?
- jacobsenscott 1y agos/is/was/
- aprilthird2021 1y agoOr worse, NSO Group
- epistasis 1y agoWhy would they spend money to replace it? The idea is to weaken and destroy the US and its institutions. Giving Palantir money might mean that security improves, and that goes against their goals. They have already demanded that Russia stop being treated as a cybersecurity threat in other areas of the government, this is a way to ensure that systems are vulnerable to attack.
- throitallaway 1y agoExactly. The Trump admin is well on its way tanking the USD with tariffs and getting every country (including the penguins) mad at us. The rationalization given by the admin for tariffs (trade imbalance) make zero sense, and they haven't offered anything else.
- phatfish 1y ago
- markhahn 1y agoTrump stupidity hurts the country and world. But maybe this is an opportunity to do CVE better.
- cantrecallmypwd 1y ago> But maybe this is an opportunity to do CVE better. Okay, how? This sounds like looking for lemonade in a genocide.
- robertlagrant 1y ago> This sounds like looking for lemonade in a genocide. It really doesn't. This level of catastrophising has no point. It would be nice if CVE continued to exist, but it wasn't close to perfect, and perhaps it can continue in another form. There's no particular reason the US taxpayer has to sponsor global security threat tracking any more than any other taxpayer or customer.
- cantrecallmypwd 1y agoThis is also a myopic argument against funding standards bodies that support the internet. The point of having a global, shared database is a single, authoritative (more-or-less), semi-vetted repository that can hold vendor accountable externally without digital amnesia or downplaying issues, and global unique identifiers. If that takes an international nonprofit funded by bits of the free world who are okay with investing in commonwealth infrastructure, so be it. Those who don't understand what they're destroying so casually are ignorant, and possibly evil if they do understand.
- robertlagrant 1y ago> This is also a myopic argument against funding standards bodies that support the internet. No, it's the opposite. Things like this shouldn't be in the hands of a single government. They should be independent and funded by many parties. The part of your message that isn't catastrophisation is agreeing with exactly what I'm saying.
- bathtub365 1y agoNow the NSA can hoard more 0days and the general public suffers. Win win for this administration
- goku12 1y agoIt's more likely to boost the zero day black market. I don't know if I want to attribute this to idiocy (indiscriminate cost cutting), greed (contracts for their crony pals) or malice (hoarding and trading 0 days).
- gryfft 1y ago¿Por qué no los tres?
- goku12 1y agoI don't know Spanish. So I used an online translator. I can see how greed and malice can go together. But idiocy? I don't know.
- gryfft 1y agoThe trick is that there's more than one person involved in making these things happen. In this way, greed, malice, and idiocy can work hand in hand. Such is entropy.
- rurban 1y agoSo who will maintain it then? Either the EU or China I suppose. They can easily fund it. Maybe the Dutch should go ahead.
- lars_francke 1y agoENISA in Europe has the mandate of building a EU vulnerability database for the NIS 2 directive anyway and it's coming soon... And CIRCL in Luxembourg are providing vulnerability-lookup which can also assign IDs but in a more decentralized way: https://www.vulnerability-lookup.org/documentation/ https://www.vulnerability-lookup.org/documentation/ VulnerableCode can help with discovery etc. https://vulnerablecode.readthedocs.io/en/latest/introduction.html#what-can-i-do-with-vulnerablecode https://vulnerablecode.readthedocs.io/en/latest/introduction... So, parts of this are already in place and I assume this will be a big boost towards a new vulnerability ecosystem.
- esnard 1y agoThis sounds like good news, thanks! Do we already have an ETA for the ENISA vulnerability database?
- jeroenhd 1y agoUs Dutch have https://advisories.ncsc.nl/advisories https://advisories.ncsc.nl/advisories although a lot of that is just analysing CVEs and their impact on society. An EU solution would probably be much better. Would suck for Americans, though, they'd need to get up early to meet European office hours.
- outside1234 1y agoThese four years are going to be the death of all of us.
- cantrecallmypwd 1y agoWar with China and doing enough reprehensible acts to stoke protests to declare martial law to stay in power indefinitely.
- throitallaway 1y agoI feel like we're only a few weeks away from someone "home grown" experiencing an "administrative error." The slide into madness continues.
- gryfft 1y agoMore like only a few days away, honestly.
- wiseowise 1y agoWait until they start a war against Albania.
- throwaway984393 1y ago[dead]
- Latty 1y agoI find it a little incredible people are still talking about "four years". They tried to reject the election result and do a coup, and were rewarded for it by getting back into power. They are refusing to follow the law or the courts. They are sending people to gulags in foreign countries. All the checks and balances were destroyed last time. The party has been stripped of anyone who would fight the admin or reject this illegality. They have set up a power grab over elections. There will not be free and fair elections in four years unless they are simply too incompetent to rig it, the rubicon was crossed long ago. Without mass protest that makes it impossible for them to hold power, American democracy is dead. They have tried to do it, they say they want to do it, they have the ability to do it, they are actively doing it, and no one is stopping them. How are people still acting like in four years they are going to neatly hand over power to be prosecuted for their crimes?
- Galanwe 1y ago[flagged]
- atomicbeanie 1y agoThe white house prefers chaos. This will certainly be a step in that direction.
- yieldcrv 1y agoif only there were 188 other countries and an entire private sector in each one that could fund this thing they are also affected by
- xyst 1y agoSome companies are already clueless when it comes to CVE management. Probably won’t see the effects immediately but give it a few more years for new generation of vulns to be created/found and we will be back to early 2000s level security. Open season on American corporations for domestic and foreign hackers. If program isn’t brought back then CVE database likely to be fragmented amongst the “private” CVE databases. Sec Corp A has 700 well documented CVEs but Sec Corp B has 702 CVEs in their database since NIST funding pulled. What do corps do? Maybe some of them with massive budgets setup contracts with both to get “full spectrum coverage”. Maybe other non-technical companies that think of IT as strictly a cost will go with the cheapest or forego it all together. Who knows maybe we get ~~~free labor~~~ open source community to pick up the slack? This country with the orange man administration is quickly going to shit. Not in a “I dislike {opposing party} way” either. In a “I dislike authoritarian regimes” way.
- mmooss 1y ago> In a stunning development Who is still stunned by these things? They want you to be stunned; they want you to tell everyone else that you're stunned to spread feelings of terror and powerlessness. If you actually are stunned, you are stunningly ignorant. If you are not and still saying it, perhaps to emphasize your unhappiness, you are a 'useful idiot'. Either way, if you are saying it, you are a useful idiot. You should have known decades ago: The GOP impeached a President for lying about sex; they fabricated intelligence to invade another country (killing thousands of Americans and 100,000+ Iraqis) - and that was all before 2004. They've voted almost unanimously, multiple times, to bankrupt the country (by refusing to authorize debt for existing obligations). Nobody (i.e., the Dems failed to) stopped them or made them pay a price, so why wouldn't they keep doing those things. (Edit: And if you object because the analysis criticizes one side and therefore you reject it as partisan, that's a big part of the reason nothing was done.) This time they published Project 2025, telling you what they were going to do.
- mcintyre1994 1y agoProject 2025 literally calls for dismantling the DHS. Seems pretty unsurprising that the CVE database wouldn’t be in the list of things they’d care to maintain in that process.
- wnevets 1y ago[flagged]
- arghandugh 1y agoThis industry relentlessly lionized Trump and Musk, elevating them to positions of power and handing them the power to destroy at will. This is your moment! Enjoy it!
- Gigachad 1y agoIt’s astounding that the users here watched all the horrendous things going on and ignored them. But now the CVE numbers are gone it’s shocking and too far.
- flanked-evergl 1y agoPlease, this place has permeated with Trump rage since before he took office. The only way you could think he was ignored is to not have read any comments.
- throitallaway 1y agoCome again? This is Hacker News, a heavily moderated forum with a narrow focus. We don't discuss Israel or El Salvador here (unless it's tech related.)
- gortok 1y agoI would hope the folks that frequent HN would not be so insular as to only read what happens on HN and not read any other news source. If you’ve somehow missed Trump’s systematic dismantling of academic freedom or his disappearing of folks he doesn’t like, then we have a far bigger problem than the limits of what is discussed on HN.
- throitallaway 1y agoOrthogonal comment, and that was not inferred at all.
- pseudalopex 1y ago> It’s astounding that the users here watched all the horrendous things going on and ignored them. Many most voted and most commented submissions were the other things.
- Ferret7446 1y agoI don't see why this should be publicly funded, so I don't really see an issue with this. The industry benefits from having a CVE database, so the industry should fund it.
- klysm 1y agoThere are going to be all kinds of messed up incentives if this is funded from industry.
- throitallaway 1y agoTrue, although Google's Project Zero seems to be run pretty well.
- worthless-trash 1y agoDifferent goals, not cve related.
- Ferret7446 1y agoLike what?
- airhangerf15 1y agoLike there aren't any messed up incentives with it funded by the government? Um, Vault 7? Snowden? PRISM? Did you literally just forget the past two decades of domestic spying and the NSA withholding critical vulnerabilities they were currently using?
- klysm 1y agoAnd how does that relate to this exactly?
- guhidalg 1y agoNo, "the industry" is all of us alive in the 21st century who depend on software to make material decisions and to be resilient to attacks and tampering. We were all funding it, and now surely we will see some big tech company now assume responsibility from the federal government (please god don't let it be Oracle...)
- nurettin 1y ago[flagged]
- the_doctah 1y agoWhy is the government responsible for CVEs again?
- throitallaway 1y agoEvery now and then the government decides to fund things. Public schools, roads, police, firemen, GPS, NOAA, cybersecurity, government cheese, etc.
- sschueller 1y ago"the government" aka "We the people". It is in all our interest. This is like asking why the government is responsible for roads.
- dingaling 1y ago> This is like asking why the government is responsible for roads. Thought experiment: If roads were built by private companies, could a Government justify the expense maintaining a database of all the potholes?
- Xelynega 1y agoYes, as it would be a public good to everyone to be able to know where the potholes(that aren't profitable to fix for these private companies apparently) are so they can avoid them. They might take a step back and realize that it would be more cost-effective to just own the roads, in which case your thought experiment ends where we are, because where we are was a place reasoned to(to an extent).
- pseudalopex 1y agoPot holes do not enable fraud, ransom schemes, data breaches, denial of essential services to millions of people, and so on.
- goku12 1y agoDoesn't the government use those software (private and open source) to handle private information of citizens and other sensitive information? And what about their contractors? That alone justifies maintaining such a database.
- wichitawch 1y agoI'm surprised that it was USA's responsibility to fund this in the first place. Why weren't other countries providing funds?
- defrost 1y agoIt's a near certitude that Russia and China each have databases of exploitable software errors and prize zero days. It was to the advantage of the US and allies to coordinate and lead in tracking and fixing such errors. Multiple countries, companies, and individuals contributed finding and fixing bugs. The administrative task of keeping track was one part of a greater picture, a part that came with first to be advised and other perks. It's not that the US had a responsibility to take on the lead admin task, more that in past times the US saw an advantage to being at the centre of global action. This is just another part of increasing US isolationism.
- wichitawch 1y ago> It was to the advantage of the US and allies to coordinate and lead in tracking and fixing such errors. From what I understand of the article, none of these allies were funding it. > Multiple countries, companies, and individuals contributed finding and fixing bugs. Clearly that itself isn't enough. Someone has to pay for maintaining this service. It appears that no one other than USA spent money in funding it.
- hiddencost 1y ago[flagged]
- digitalPhonix 1y agoFunnily this was on the front page recently: https://seths.blog/2025/04/how-to-win-an-argument-with-a-toddler/ https://seths.blog/2025/04/how-to-win-an-argument-with-a-tod... Don't bother; they're a brand new user trying to cause trouble
- cbondurant 1y agoAm I missing something or was this literally announced with less than 24 hours of warning that one of the critical components to the cyber security landscape was disappearing. What the fuck are you supposed to do about this. This is something that should have had multiple MONTHS of warning in order to allow those who depend on the CVE infrastructure to plan what to do next with their security posture.
- cookiengineer 1y agoIf there are any Europeans here, I'd love to make my vulnerability database that's accumulated from all linux security trackers and the CVE/NVD open source if I can manage to find some folks who'd help with maintenance. Currently hosting costs are unclear, but it should be doable if we offer API access for like 5 bucks / month for private and 100 / month for corporate or similar. Already did a backup of the NVD in the last couple hours, currently backing up the security trackers and OVAL feeds. Gonna need some sleep now, it's morning again. My project criteria: - hosting within the EU - must have a copyleft license (AGPL) - must have open source backend and frontend - dataset size is around 90-148 GB (compressed vs uncompressed) - ideally an e.V. for managing funds and costs, so it can survive me - already built my vulnerability scraper in Go, would contribute it under AGPL - already built all schema parsers, would contribute them also under AGPL - backend and frontend needs to be built - would make it prerendered, so that cves can be static HTML files that can be hosted on a CDN - needs submission/PoC/advisory web forms and database/workflow for it - data is accumulated into a JSON format (sources are mixed non standard formats for each security tracker. Enterprise distros use odata or oval for the most parts) If you are interested, write me on linkedin.com/in/cookiengineer or here.
- weinzierl 1y agoTry to talk to the people from the Sovereign Tech Fund, they have a history of sponsoring security relevant projects in the EU.
- jauco 1y agoAnd maybe the sidn fund?
- decide1000 1y agoNlnet for opensource
- Sander_Marechal 1y agoYes, maybe reach out to Michiel Leenaars from the NLNet foundation. But IIRC NLNet mostly funds shorter development tracks, not ongoing upkeep/maintenance.
- delusional 1y agoMeh. It's not like I was going to ask the facist autocracy about my software vulnerabilities.
- nelox 1y agoJust what is needed with an adversary during and asymmetrical trade war.
- insane_dreamer 1y agoCVE was anti-American woke. No, more seriously, just like with shutting down NOAA services, it seems the goal is to: 1. cut services (we saved taxpayer money!!) 2. at some point later: oh, we actually need those services 3. pay <insert your favorite vendor here, preferably one connected to Musk> to provide the service (see! we don't need to pay gov employees!!) (fine print: the vendor costs 2-3x the original cost). But by then no one is looking at the spending numbers anymore. Slick moves.
- SirHumphrey 1y agoAnd here lies the problem. Even from a libertarian perspective DOGE is counterproductive because maintaining a system is much more cost effective than starting it anew. Especially when you cut something recklessly, figure out in month that you need back that capability right now and have very little leverage to negotiate with private providers. When you look at the last cutting effort in the Clinton administration the difference in jarring. Combine that with the fact that with a few exceptions DOGE has been cutting the most cost effective programs (i can’t think of a better bang for buck science program than NOAA) it’s saved very little vs the amount of pain it has caused.
- darkwater 1y agoHeeeeey but he runs Tesla like this and it's an hyper-valued company!!!1! He cannot be wrong, he is a genius!!
- JackYoustra 1y agoThere are quite a few threads on hackernews that were cautiously optimistic about doge with, frankly, pretty naive libertarian takes about how the government works. The government is not particular (in the sense of particularism) and cannot be easily tuned to fix particular problems; rather, its best solutions come through institutional procedure and design, such as the tension between the FAA and the NTSB that, at a first glance, would seem like obviously needless duplication and waste. It is a broad, blunt, wasteful instrument to solve broad, blunt problems in a way that may not be the best but that work far, far better than alternatives that have been tried. That the effort to treat government like a personal budget has ended up destroying important things is a sad inevitability of such efforts. I hope it goes remembered.
- simpaticoder 1y ago>I hope it goes remembered. It won't be. Willful ignorance is a cornerstone of the movement. You can't lie about what you don't know. You can't have a bad take if you don't know. Upton Sinclaire said in the 1930's: "It is difficult to get a man to understand something, when his salary depends on his not understanding it." Now add to "salary" "identity", "relationships", "sense of belonging to the group". This is why critical, independent thinking, speaking truth to power, must be separately honored and encouraged by a healthy culture, because these attributes are by default mercilessly punished. (Physical courage and heroism are honored by a healthy culture for similar reasons.)
- JackYoustra 1y agoI mostly agree, although I really disagree with 'speaking truth to power' — I feel like the outsized reverence for this is exactly what got us into this mess. For YEARS, there's been a culture of celebrating opposition for opposition's sake, a performative stance of always positioning oneself against the perceived holders of power, rather than critically evaluating the actual accuracy or value of what's being said. Democrats are repeatedly pilloried simply because they govern while the Republicans cosplay as a permanent opposition, and therefore became 'the power' to speak against. Governing inherently involves trade-offs, compromises, and complex realities that never match ideological purity. Thus, an atmosphere developed where people who engaged in governance—and therefore took responsibility for difficult, real-world outcomes—became easy targets for criticism that was more interested in the aesthetics of "truth to power" than in providing accurate analyses or constructive solutions. As a result, "speaking truth to power" became a performance, disconnected from accountability or genuine insight. The loudest critics weren’t necessarily those with the most accurate or useful truths, just those who most visibly positioned themselves as opposing power structures. This reinforced public cynicism and undermined nuanced understanding of governance and policy, further obscuring genuine critique and necessary reforms.
- 1970-01-01 1y agoRoot cause: Layer 8 failure https://www.computerhope.com/jargon/l/layer8.htm https://www.computerhope.com/jargon/l/layer8.htm
- apexalpha 1y agoWhy is this sponsored by such an American gov entity? I guess it's one of those things you never think about until it goes wrong. The world would do well to move this kind of stuff out of the US quickly, just like ICANN and stuff.
- kbumsik 1y agoBecause gov infra also relies on CVE?
- porridgeraisin 1y agoGood. CVEs were the poster boy of goodharts law for the longest time. Most security vulnerabilities behind CVEs are utterly meaningless.
- goku12 1y agoAh! Another one to add to the following list: - What disease did the CDC ever prevent? - What improvement did the NHTSA ever bring to full self driving? - What improvement in airline safety did the FAA bring? - What good did FEMA do in any disasters? I don't want to quip about how their achievements are invisible because they prevented the disasters that would have brought the spotlight on them, even when they were too underfunded to properly do their jobs. But I sure would like to see the people making these smart comments to give it a try and see how that goes. Then again, I have no complaints - at this rate, we'll get that chance soon.
- porridgeraisin 1y agoLikening CVE database maintainers to natural disaster response teams and an entire country's medical board is quite the achievement in hyperbole, congratulations. Anyway, my opinion is that CVEs have a very low signal-noise ratio and vulnerability databases in general should be revamped to try and fix that problem. The current system - I don't claim to know the root cause - is simply horrible. It could be the management, the entry requirements, some loophole perhaps, etc,. I also don't claim that this is the motive behind this move, I am just hoping it gets revamped anyway as a side effect (There's another article on HN floating around that says someone else has picked up the baton - good luck to them). I also don't care for your country's politics which you seem to be eluding to in your final paragraph.
- goku12 1y agoHyperbole according to whom? Clearly, this forum full of tech professionals seem to disagree with you. And I listed those arguments to show how hollow your own argumentation is - not to draw a parallel. But even with that straw-man, how did you decide that such a database has no serious utility to the governments and private institutions worldwide? And what's even worse is how some people belittle others' work without getting even the basic facts right. You neglected the fact that they were underfunded to begin with. So perhaps what's needed to improve their quality is to increase their funding, not cut it further. That's a trick used by some sleazy politicians to justify de-funding and privatizing useful endeavors like these. I find such excuses to be quite dishonest to begin with.
- 4ndrewl 1y agoTo the "I wish HN would stay out of politics" crew. You can stay out of politics, but politics will always come and find you.
- pif 1y agoThere's politics and there are facts. Trump voters are stupid. This is a fact. Right or left leaning, that's politics.
- OhioMan2943 1y agoEverything is political now by design. It's meant to reach into every facet of society and community and restructure it.
- Braxton1980 1y agoEverything was always political. Laws, the economy, conflcit. How is any person not affected by these? The government is responsible for all or a large part of how a country functions. People who say "I'm not political" are deflecting to avoid conflict
- OhioMan2943 1y agoI mean I think The Republican Incumbent was chosen specifically as a tool because he is so extreme, pervasive and demoralising and creeps into everything. Definitely by Russia, maybe also by our "friend" in the ME. Although it's not that reported on they are on friendly terms. Disaffection lends itself easily to creating a Russia-style society. This all feels pretty Dugin-esque, and his proposition (return to values, reject interest/hope in politics because it is always flawed anyway, bind together under the state) fits perfectly, and is finding prominence at the perfect time. Just my opinion, but to me this seems far more akin to Dugin than whatever Curtis Yavin is pushing
- ndr42 1y agoWhat is "ME" referring to?
- nodesocket 1y agoI’m betting CVE will get sponsored by a security company or Cloudflare.
- gm3dmo 1y agoAnyone feel confident that the companies who benefit massively from MITRE are even now planning to step in and provide significant funding?
- gabesullice 1y agoAs a newly minted cynic, this seems like a cynical play to save someone's budget. Step 1: Post discreetly to a forum with minimal information and an absurdly short deadline Step 2: Phone your friend, the former board member, to make your case on LinkedIn Step 3: Ring up a friendly journalist and give them a tip Step 4: Reference the insuing chaos as justification for keeping your project funded Note that the article carefully avoids pinning the blame on DOGE or the Whitehouse while heavily implying it. MITRE is technically a private entity, albeit a non-profit. And the very last paragraph of the article states: > A CISA spokesperson told CSO, “CISA is the primary sponsor for the Common Vulnerabilities and Exposure (CVE) program… Although CISA’s contract with the MITRE Corporation will lapse after April 16, we are urgently working to mitigate impact and to maintain CVE services on which global stakeholders rely.” To be clear, the point isn't to say that the CVE program isn't valuable, nor is it to say that it's good for a shenanigan like this to be necessary. The point is that, unless you're directly involved in this subject (not impacted—involved), it's probably best to maintain a "wait and see" attitude rather than succumb to catastrophizing this news.
- girvo 1y agoHave you seen proof that this is what has been happening? Your explanation is much more convoluted than "DHS cut funding, like the administration has said it is going to do".
- gabesullice 1y agoThese explanations are not mutually exclusive.
- girvo 1y agoI think they are a little, but you didn't answer my question?
- gabesullice 1y agoI think my post aged quite well, considering the resolution happened a few hours later, no? Your post was implicitly invoking Occam's razor and so the premise of the question was about deciding which explanation to believe. I rejected that premise because it wasn't necessary to decide between the two explanations—they weren't mutually exclusive. The only proof I had was that I've seen enough of these events resolve themselves very similarly to the way this one was resolved—which is why I was recommending a "wait and see" approach. Call it wisdom or "lived experience".
- jl6 1y agoSo is this going to instantly break a bunch of tools like Trivy?
- wengo314 1y agovibe coding could not have come at a worse moment.
- sgt 1y agoJust tell the AI: "Make this code secure" /s
- redleader55 1y agoI see this as the perfect moment to get into consulting - either development, or security. People were not sure what jobs AI will create: "GenAI babysitting" is one of them.
- skirge 1y agoonly one country pays but all benefit from it. It should be funded by all who benefit like UN.
- goku12 1y agoI'm sure that a hundred other countries will step up to fund it. But have you given any thought about why the US was so willing to sponsor it alone in the past?
- jowea 1y agoI thought most people in the US wanted the UN to have less control over this stuff? Remember the talk about moving control of the Internet to the ITU (International Telecommunication Union)?
- airhangerf15 1y agoThe EU, the EU and all bodies that remove a nations sovereignty should be removed entirely. Brexit was good, but the UK government made it meaningless. The UN chokes and strongholds it member states. The CVE program is already a public-private partnership, which is BAD. CVE's board has people from Microsoft, Github, CrowdStrike, etc. Public-private partnerships are how the US government gets away with things a State should not be able to do: via private contractors. The US government has also run programs like Vault 7. The NSA has a vested interest in vulnerabilities not being made public until the US can fully exploit them Internationally. The merger of state and corporate interests seems to be everyone's favorite overused word of the decade.
- hubabuba44 1y agoThe real irony here is that a lot of ycombinator founders and the people reading HN were exactly the ones making this possible and now start to wonder why the snake eats its own tail.
- cantrecallmypwd 1y agoSorry, I made the mistake of installing PyPy.
- hubabuba44 1y agoI assume that this comment should go somewhere else or I'm not able to decipher the message ;)
- jampekka 1y agoPyPy's logo is a snake eating its tail.
- hubabuba44 1y agoCool thanks!
- cantrecallmypwd 1y agoSorry and thanks GP. ;o) Your nerd card had been validated for today. Go forth, ethically.* :D * Oops, I introduced 2 more programming languages, my bad.
- this15testingg 1y agoexactly; I hope ycombinator and its proponents can enjoy living in the ancap fantasy land where you have to pay to be alerted for a climate change fueled mega hurricane (also caused by this exact same reckless, unregulated greed) because NOAA was disbanded. Billionaires shouldn't exist, but neither should millionaires.
- rcarmo 1y agoNow would be a great time for a major tech company to support them (or, even better, a consortium).
- basemi 1y agoFor now, historical CVE records will be available at GitHub: https://github.com/CVEProject https://github.com/CVEProject
- doodlecricket 1y ago[dead]
- InsideOutSanta 1y agoThis makes me wonder what other stuff most people don't know exists but is important to our society has quietly disappeared in the last few weeks. We know about this one because we know it's important. What are the things we don't know about?
- jeroenhd 1y agohttps://www.project2025.observer/ https://www.project2025.observer/ lists a few. Of course, those are only the agencies the Trump people know about and explicitly want to destroy, but it's a start.
- knowaveragejoe 1y agoThe cheerleaders don't care. Americans' relative certainty and quality of life is backstopped by institutions they either barely understand or have never heard of. Let them touch the stove, I guess.
- jl6 1y agoIt’s a reckless move to cut funding so abruptly, but taking a step back from the short-term chaos, it probably is an anomaly that this was government funded. All of private tech relies on it, and private tech is big enough to pay for it. I hope that the trillion dollar babies consider this an opportunity to pool together to form a foundation that funds this, and a bunch of other open source projects run by one random person in Nebraska.
- kbumsik 1y ago> it probably is an anomaly that this was government funded Companies can definitely fund it. But to be fair the gov, including NIST, also relies on CVE.
- chasontherobot 1y agoah yes, let private entities pay for it. then when there is a vulnerability with one of those entities' software, they can pay a bit more to bury it!
- padjo 1y agoAh yes the old “well can’t concerned citizens band together, form a committee, collect revenue and fund things that are in the common interest” answer you hear from small government types that makes me think you lot don’t really understand what government actually is.
- JCharante 1y ago> it probably is an anomaly that this was government funded. All of private tech relies on it, and private tech is big enough to pay for it. I mean doesn't big tech and the people they give salary money to pay taxes? Ground transportation companies rely on public roads and but we fund it because having the infrastructure is an economic multiplier. I'm not arguing in favor of funding the CVE program, I just don't think that's a good reason.
- jl6 1y agoOpinions vary on what the purpose of government is, but if you take the view that the government's priorities should be providing services that are impossible, inefficient, or unethical to provide privately, then I don't see the CVE program making the cut, when the tech industry is collectively flush with resources and has every incentive to form an industry consortium to take it over. A modern Open Group, perhaps?
- bslanej 1y ago[flagged]
- goku12 1y agoOh! It will be even more fun when the entire infotech and infosec industry starts seething soon. Then the rest of the world will just make alternative arrangements and move on, leaving the US behind because they can't be trusted anymore. HN's reaction is just a small taste of things to come.
- bslanej 1y ago[flagged]
- karel-3d 1y agoPhew, no new annoying CVE reports in my Docker images from today
- dhx 1y agoThe latest contract[1] (I hope this is the right one) for MITRE's involvement with CVE and CWE programs was USD$29.1m for the period 2024-04-17 to 2025-04-16 with optional extension of expenditure up to USD$57.8m and to an end date of 2026-04-16. Seemingly MITRE hasn't been advised yet whether the option to extend the contract from 2025-04-16 to 2026-04-16 will be executed. And there doesn't appear to be any other publicly listed approach to market for a replacement contract. [1] https://www.fpds.gov/ezsearch/jsp/viewLinkController.jsp?agencyID=7001&PIID=70RCSJ24FR0000018&modNumber=0&transactionNumber=0&idvAgencyID=7001&idvPIID=70RSAT20D00000001&actionSource=searchScreen&actionCode=&documentVersion=1.5&contractType=AWARD&docType=C https://www.fpds.gov/ezsearch/jsp/viewLinkController.jsp?age...
- gwd 1y agoI can't figure out why the hue and cry wasn't raised until the very last minute. Did they not know a month ago that they were running out of time? Is it standard practice for the government not to say they're going to extend the contract until the day beforehand or something?
- sq_ 1y agoRight now, yes. You can pretty easily have a scenario where you’re talking to the agency you’re working with and they’re saying “we want to renew this, but we don’t know if they’ll give us the money in the end”. So you’ll get a bunch of “hopefully this week” up until it expires.
- pjmorris 1y agoI was at VulnCon last week, and an NIST representative said that there were no plans to cut CVE funding.
- breck 1y ago[dead]
- Brosper 1y agoEurope needs to save the world!
- kesor 1y agoGood, less government involvement is better for everyone.
- NilayK 1y ago> A coalition of CVE Board members launched a new CVE Foundation "to ensure the long-term viability, stability, and independence of the Common Vulnerabilities and Exposures (CVE) Program." > https://www.thecvefoundation.org https://www.thecvefoundation.org https://mastodon.social/@serghei/114346660986059236 https://mastodon.social/@serghei/114346660986059236
- hahajk 1y agoSo if the govt stops paying them they'll continue to do the work for free?
- delfinom 1y agoHow else will they continue burning out open source maintainers with bullshit?
- lou1306 1y agoMore likely they will seek funding from companies and other organizations, as every other foundation/consortium of this kind does.
- deleted 1y ago[deleted]
- pantropy 1y agoThe way their letter is worded it seems that they have a rainy day fund constituted to ride out the stormy next few week and I'm fairly certain they'll come back with more details as to how they'll be acquiring funding from now on in the next few days. Maybe paid access to an API, maybe donations from large companies that use the system, maybe something else ::shrug:: Hopefully a project as important as this doesn't just dissapear completely because of government pressure.
- jmcgough 1y agoThey're converting to a nonprofit, so instead of federal funding they will need funding from big tech companies.
- londons_explore 1y agoHow much was this contract worth? If it was $5000/yr it's very different to if it's $5M/year for what amounts to little more than an instance of mediawiki.
- deleted 1y ago[deleted]
- deleted 1y ago[deleted]
- harisec 1y ago$44M/year? https://www.usaspending.gov/award/CONT_AWD_70RCSJ23FR0000015_7001_70RSAT20D00000001_7001 https://www.usaspending.gov/award/CONT_AWD_70RCSJ23FR0000015...
- londons_explore 1y agoTotally worth cancelling then. Some volunteer will set up a GitHub pages and mailing list to fulfill the same duties.
- Peanuts99 1y agoOr 10 people will create that list and nobody will use any of them. The whole point here is that the CVE program had the network effect of being the defacto list of issues but now that's been pissed away.
- anilakar 1y agoLet me guess: Trump is going to make China pay for it.
- jibal 1y agoBad guys helping out bad guys--it's what mobsters do.
- mzhaase 1y agoLong term its probably good to have a less US-centric world.
- jeroenhd 1y agoThis is a chance for the EU to step up and take over. If the US government won't pay for the CVE program, the EU surely could. Many EU countries already run a program like this to server their own interests, and I believe the EU does as well. If the US is willing to give up influence and control over the cybersecurity sector, we should accept that gift and use it to our advantage.
- moomin 1y agoI’m sure a much better private sector alternative will appear any day, in line with conservative dogma.
- drdrek 1y agoLOL this is Amazing... Holy shit
- rvba 1y agoWhy cant wikipedia foundation step in? They have millions of dollars.
- gorbachev 1y agoI wonder what would happen to CVE program funding if Tesla and SpaceX would be zero-dayed to hell and back.
- redleader55 1y agoWe will soon find out, probably.
- phtrivier 1y agoI'm really curious about the "soon" part, though. What is the timeline for something very visible to happen, and still be directly relatable to DOGE ? Just imagine if it happens in three years, after the midterms - someone will be able to blame the Dems for it :) !
- dools 1y agoUh oh did someone CVE grok or twitter?
- WillAdams 1y agoFWIW, I've never understood why this sort of thing wasn't just directly handled by the NSA --- aren't they the group which should be tasked with cybersecurity? I always suspected that "Department of Homeland Security" would lead to Banana-republic-like shenanigans --- could we defund them?
- donohoe 1y agoI don’t think anyone trusts the NSA to run a program like this.
- dfedbeef 1y ago"National Security" doesn't mean you personally. It's the government only. There's a conflict of interest that immediately arises if a part of the DoD (who owns cyberwarafe, which uses vulns) maintains a public vuln database. (Edited to be less salty, sorry)
- thih9 1y agoI can’t see any long term benefits for the US. It looks like the current administration is fine with chaos and disruption on an unprecedented scale.
- donatj 1y agoPractically speaking, how much could it cost to maintain the CVE database? Given its enormous value, isn't this something that the community, especially FAANG (MAANA?) could step up and fund as a nonprofit?
- uptownfunk 1y agoSeems like a big miss on the part of DOGE?
- i_love_retros 1y agoAt this point it's not crazy to believe Russia is running the country
- dfedbeef 1y agoThis level of stupidity seems pretty American to me
- paulmendoza 1y agoAnyone who voted for Trump voted for this type of dumb action. This is a major loss for society and safety.
- jnovacho 1y agoIt looks like the decision has been reverted, for now at least: https://www.forbes.com/sites/kateoflahertyuk/2025/04/16/cve-program-funding-cut-what-it-means-and-what-to-do-next/ https://www.forbes.com/sites/kateoflahertyuk/2025/04/16/cve-...
- deleted 1y ago[deleted]
- jeff_carr 1y agoThe contract with MITRE has been extended. https://www.forbes.com/sites/kateoflahertyuk/2025/04/16/cve-program-funding-cut-what-it-means-and-what-to-do-next/ https://www.forbes.com/sites/kateoflahertyuk/2025/04/16/cve-... My guess indefinitely. DOGE might be a bunch of idiots, but in the entire DOD, there are non-idiots.
- metalliqaz 1y ago[flagged]
- lenerdenator 1y ago[flagged]
- fennecfoxy 1y agoHasn't that always been the case for society at large? From Wernher Von Braun to Oppenheimer.
- xpe 1y ago> Malicious idiots surrounded by sheepish intelligent people. Prefixing people with "sheepish intelligent" is bound to oversimplify this. Many of the non-DOGE employees who directly see wrongdoing are likely making calculated decisions on what to do. It depends on many factors, including the law and whistleblower protections. Many of them are responding in various ways that they hope will have an impact. Some resign in protest. Others file lawsuits. Others leak to the press. Could they do more? Yes. So let's help them. What can we do? Just to give two relatively middle-of-the-ground recommendations: First, donate to legal-protection funds for whistleblowers. Second, call your representatives and demand reinstatement of the inspectors general.
- lenerdenator 1y agoThe current administration is shipping people out of American territory to a hellhole in El Salvador without trial. It'd like to do that more often. Whistleblower protections don't mean much if the brute squad snatches you off the street and throws you on a plane regardless of what the law says.
- hatly22 1y agoMaybe Europe should charge the US for access to their CVE databases.
- jovial_cavalier 1y agoI didn't realize that CVE was funded by the DHS. Isn't it better for it to be independent and not funded by an intelligence agency? It's enough of a public good to have a common advisory for vulnerabilities that FAANG should just kick it a few million a year. How much can it possibly cost to run this anyway?
- trothamel 1y agoDoes anyone know what the CVE program was costing per year? I searched around a bit, but wasn't able to find the number.
- deleted 1y ago[deleted]
- m4r71n 1y agoThe title of this article is simply false. The CVE Program is a separate entity from MITRE and is most definitely not ending. The CVE Program has been acquiring assets from MITRE for years now. That is why the main site shifted from cve.mitre.org to cve.org. MITRE has always simply been the workhorse of the program, and now that is being shifted to others (CVE foundation, which has global representation).
- gcollard- 1y agoForget everything you know and consider that it might be a misguided and risky negotiation tactic. Disclaimer: This is not business advice and should be read using Cartman’s voice. Step 1: Announce publicly that you are not renewing your contract. Step 2: If the market has viable alternatives or the service you are negotiating isn’t that hard to replicate, other actors will manifest to fill in the gaps, especially if your business is attractive. (E.g., The top comment is building an alternative; other comments point to alternative services.) Step 3: Congratulations, you now have leverage for a significant discount with your previous provider because they face the real prospect of losing your business entirely to a competitor. If the competitor is private, you can even double dip by investing in their company before attributing them the contract.
- deleted 1y ago[deleted]
- Aperocky 1y agoThere's always a cost even if there doesn't seem to be one, credibility is measurable in markets and when it bite I think we'll all be in rough times.
- ThinkBeat 1y agoThere seems to be little reason for the US government to pay for this since it is vital information that a lot of companies rely upon. Some form of a foundation or NGO could be given a reasonable endowment from the industry to operate the CVE program. O am quite hesitant to trust the DOD to keep track of software vulnerabilities. Some parts are developing and exploiting vulnerabilities. And given a fresh feed of what people find, and usually a delay from notification until publication, which may sometimes just be a bit longer of a delay, would allow the DOD to weaponize the vulnerability for their own use as well.
- froggertoaster 1y agoBelieve me when I say that DOGE is filled with smart people (I know a few of them). Just because they're scattershot cutting doesn't mean they're stupid.
- raegis 1y agoI guess I'm naive, but given the current situation, wouldn't a smart person resign from DOGE? If I were smart and highly employable, like these guys, I would not want to be associated with all the indiscriminate firings of DOGE.
- froggertoaster 1y agoI guess it depends on what you value. I think it speaks a lot about a person who assumes "a smart person would resign from DOGE".
- p0w3n3d 1y agoOne man appears at one position and so many things stop working in so little time
- Alifatisk 1y agoYet, he is still praised and cherished. I can't comprehend how.
- RKFADU_UOFCCLEL 1y agoIncluding this as a prime example, the overall trend seems to be that we're going back to the bad old days where a kid gets to code the entire security infrastructure because the CEO thinks he's smart and then the bugs are covered up with legal threats (because they were able to mislead the courts), obfuscation, while being easily discoverable by 3rd parties. Another example is the way the bug bounty gimmick is run and most researchers never disclose their findings nor are they patched in any consistent manner, plus the companies threaten to sue you for disclosing even if it's 100 years later.
- blindriver 1y agoHow much does CVE cost to maintain and why must the US fund the entire thing?
- manmal 1y agoThe bureaucracy of internationalizing it would likely be more expensive than the current cost.
- GuinansEyebrows 1y agoWe can afford it.
- blindriver 1y agoNot with 36T in debt.
- GuinansEyebrows 1y agoBy that logic, we can’t afford anything.
- blindriver 1y agoYes we can’t afford anything new. And that’s why we need to cut back. It’s unfortunate but our children are going to suffer. The debt is unsustainable at this point.
- andrehacker 1y agoMaybe change the headline now ? As-is the headline is click-baity. (spoiler alert: the contract has been extended)
- rbolla 1y agoImportant update April 16, 2025: Since this story was first published, CISA signed a contract extension that averts a shutdown of the MITRE CVE program.
- deleted 1y ago[deleted]
- dang 1y agoRelated ongoing threads: CVE Foundation - https://news.ycombinator.com/item?id=43704430 https://news.ycombinator.com/item?id=43704430 Replacing CVE - https://news.ycombinator.com/item?id=43708409 https://news.ycombinator.com/item?id=43708409