[HN Gopher] CVE program faces swift end after DHS fails to renew...
       ___________________________________________________________________
        
       CVE program faces swift end after DHS fails to renew contract
        
       Author : healsdata
       Score  : 1815 points
       Date   : 2025-04-16 01:57 UTC (15 hours ago)
        
 (HTM) web link (www.csoonline.com)
 (TXT) w3m dump (www.csoonline.com)
        
       | bytematic wrote:
       | What are the implications of this? No more centralized store of
       | vulnerability information?
        
         | neuronexmachina wrote:
         | According to Brian Krebs:
         | https://infosec.exchange/@briankrebs/114343835430587973
         | 
         | > Hearing a bit more on this. Apparently it's up to the CVE
         | board to decide what to do, but for now no new CVEs will be
         | added after tomorrow. the CVE website will still be up.
        
         | Incipient wrote:
         | Basically when any software/library/whatever has a
         | vulnerability, they have to communicate that out themselves, in
         | some format.
         | 
         | If I'm developing a product built on 20 libraries, it won't
         | just be a matter of scanning CVEs for major vulnerabilities any
         | more, so I'm more likely to miss one.
         | 
         | "always update" doesn't always work, when to manage a product
         | you realistically have to version pin.
        
           | cantrecallmypwd wrote:
           | They surprise is: they won't. This will weaken the West.
           | 
           | This is dangerously stupid.
        
             | t0lo wrote:
             | This is deliberate. I just want to figure out the avenues
             | of communication and coordination between trump admin and
             | moscow so we can pin them down better.
        
           | worthless-trash wrote:
           | So, while arguably true, there wont be a single source of
           | truth of new cve's. It doesn't however mean there wont be.
           | 
           | I would imagine the only SANE option would be some kind of
           | git repository where CNA's can collaborate. Probably run some
           | code across to make the website that people can easily
           | access.
           | 
           | It's going to be a mess.
        
       | joshuanapoli wrote:
       | Is MITRE's CVE program redundant with NIST's National
       | Vulnerability Database? I'm having a hard time telling how the
       | two are related, or if NVD is simply performing the same service
       | as MITRE.
        
         | detaro wrote:
         | NIST NVE relies on the CVE program. (vulnerabilities get
         | reported, MITRE assigns CVEs and publishes them, NIST then
         | copies that list and adds their own scoring etc to it)
        
         | Spooky23 wrote:
         | Once they fire everyone at NIST, they'll have that in common.
        
       | Rebelgecko wrote:
       | I'm trying to steelman but I really can't think of a non-
       | nefarious justification for this
        
         | sneak wrote:
         | We don't need to spend tax dollars to increment sequential
         | integers.
         | 
         | The "CVE program" can be done by a volunteer or two in spare
         | time. It's not some major operation, it's just a registry of
         | integers that can live on GitHub.
        
           | viraptor wrote:
           | Yet so far no volunteer has emerged and people who do run CNA
           | are pretty busy with it.
        
             | _zer0 wrote:
             | I think sneak would volunteer to do it since it is pretty
             | simple according to them.
        
               | mlinhares wrote:
               | Any work people don't understand must be easy and
               | replaceable by chatgpt. Just look at how easy people here
               | think farming is.
        
               | johnnyjeans wrote:
               | Grok becoming an artificial nepobaby running the entire
               | CVE program with zero oversight sounds so fucking funny I
               | don't even care, PLEASE god make this real holy shit I
               | can't breathe at the thought
        
             | stevekemp wrote:
             | There were some, short-lived, projects/groups trying to run
             | their own processes. DWF is one that I recall, though it is
             | dead again:
             | 
             | https://lwn.net/Articles/851849/
        
           | Rebelgecko wrote:
           | How do you get your volunteers in the first place and manage
           | them so you know it's time to get a new one if the quality of
           | their work is slipping?
        
           | skeledrew wrote:
           | Who needs volunteers? Let AI handle it!
        
           | fnordpiglet wrote:
           | This is like saying the patent system is just an incrementing
           | counter.
        
             | sneak wrote:
             | Have you seen the patents they have been giving out lately?
        
           | gessha wrote:
           | Found the blackhat
        
           | _carbyau_ wrote:
           | Thanks for volunteering to manage the "300-600 CVEs each
           | month"!
           | 
           | The world needs more volunteers like you.
        
             | charcircuit wrote:
             | You manage the system and not the CVEs themselves. The
             | simplist thing would be a list of numbers that correspond
             | to Google docs. The owner of the Google doc can share it
             | with the needed parties and eventually set it as public.
        
               | goku12 wrote:
               | You truly believe that the CVE database (and others like
               | CWE) are only about assigning serial numbers to random
               | reports, don't you? I see people underestimating and
               | understanding the work of others in matters like this. Is
               | that a trend now?
        
               | charcircuit wrote:
               | No I don't believe that, but it might as well operate
               | like that. The extra stuff isn't truly needed and was
               | being outsourced to the companies that own the products
               | since it wasn't providing much value. Take a look at
               | Daniel's blog posts about CVEs for curl for what happens
               | when you let them handle it.
        
               | worthless-trash wrote:
               | I saw this same behavior quite a while back. While I'm
               | out of the CVE game these days, it seems that there is a
               | forever rotating new group of people who simply don't and
               | can never see the complexities on the process.
               | 
               | I think it's a testament to the previous stewardship that
               | it appears so simple.
        
             | techky wrote:
             | Make that 3,000-4,000 on average per month, according to
             | NISTs stats on CVEs for last year. ~40,000 for 2024.
        
             | JCharante wrote:
             | I imagine most of those CVEs not being anything meaningful
             | and just script kiddies trying to put something on their
             | portfolio
             | 
             | all the meaningful ones will show up on HN
        
         | duxup wrote:
         | The process seems to be to dismantle anything not nailed down
         | in government.
         | 
         | Now if you want that (even just funding) to be a thing ... you
         | have to go through Trump & Co and pay your bribe to get it back
         | up.
        
         | esafak wrote:
         | Privatize all teh things?
        
           | benfortuna wrote:
           | This neo-liberal approach has no place for soft diplomacy,
           | which is what US hegemoney relies on.
           | 
           | This isn't just a rapid disassembly of economic structures,
           | any trust and goodwill is completely obliterated as well.
        
             | tart-lemonade wrote:
             | For decades, the US could be counted upon to fund things
             | with little immediate benefit but massive long-term
             | positive externalities. I don't think its likely that the
             | republican party will "go back to normal" post-Trump, so we
             | can all kiss the long-term reputation building that
             | American hegemony relied upon goodbye. Short of a great
             | depression-esque political reset, I do not see things
             | changing for the better.
        
           | transpute wrote:
           | April 2024 article on the result of NVD funding cutbacks,
           | with comments by Linux Foundation OpenSSF, security startups
           | like ChainGuard and commercial vendors,
           | https://www.securityweek.com/cve-and-nvd-a-weak-and-
           | fracture...                 Threat intelligence firm
           | Flashpoint noted in March 2024 it was aware of 100,000
           | vulnerabilities with no CVE number and consequently no
           | inclusion in NVD. More worryingly, it said that 330 of these
           | vulnerabilities (with no CVE number) had been exploited in
           | the wild.. Since the start of 2024 there have been a total of
           | 6,171 total CVE IDs with only 3,625 being enriched by NVD.
           | That leaves a gap of 2,546 (42%!) IDs.
           | 
           | Despite all those private companies and various OSS projects
           | being willing to contribute ideas, infrastructure and code,
           | they have somehow failed to coalesce into a decentralized
           | replacement for NVD, built on CC0 data and OSS tooling.
        
             | cma wrote:
             | I tried to look over the history and I only see a funding
             | increase, CISA cut $3.7 million at the end of 2023 for the
             | next year and in response NIST reallocated extra funding to
             | NVD: $8.5 million in 2024
             | 
             | A funding shortfall and strain isn't a funding cut. And
             | from what I see there was a funding increase.
        
               | transpute wrote:
               | Would appreciate a pointer to the source, thank you.
               | 
               | 2025 article claims 30% increase in 2024 workload,
               | https://www.securityweek.com/mitre-signals-potential-cve-
               | pro...
               | 
               |  _> According to NIST, while the National Vulnerability
               | Database (NVD) is processing incoming CVEs at the same
               | rate as before the slowdown in spring and early summer
               | 2024, a 32 percent jump in submissions last year means
               | that the backlog continues to grow._
        
               | cma wrote:
               | Can search these for the links
               | 
               | 2023
               | 
               | > CISA had previously been supporting the NIST NVD
               | program with approximately $3.7 million per year in
               | interagency funding, which they have discontinued
               | 
               | 2024
               | 
               | > While NIST has since reallocated $8.5 million to NVD
               | for fiscal years 2024 and 2025
               | 
               | Assuming that's spread over both years it wasn't as big
               | of an increase as I said, but is still an increase even
               | inflation adjusted.
               | 
               | > 2025 article claims 30% increase in 2024 workload
               | 
               | Underfunding in the face of more workload isn't itself a
               | funding cut.
        
               | transpute wrote:
               | Thanks for the pointer. Is this a lobbying org? https://w
               | ww.fdd.org/analysis/policy_briefs/2025/03/21/delaye...
               | 
               |  _> While NIST has since reallocated $8.5 million to NVD
               | for fiscal years 2024 and 2025, this funding remains a
               | fraction of the $300 million to $400 million estimated to
               | be needed annually to fully restore capacity, with an
               | additional $120 million to $150 million required to
               | prevent further system "deterioration."_
               | 
               | Did NVD receive 300MM annual funding pre-2024? That would
               | be a 98% funding cut.
        
               | formerly_proven wrote:
               | 300 million would've been a quarter of the NIST budget.
               | Doubt.
        
               | transpute wrote:
               | Yeah, bizarre site.
               | 
               | MITRE CVE/CWE budget is more transparent than NVD since
               | it's a contract, listed on USAspending.gov.
        
         | giraffe_lady wrote:
         | > I'm trying to steelman
         | 
         | Why? This administration is not acting in good faith, you don't
         | have to act as if they are. People and institutions doing that
         | is part of how we got here in the first place.
        
           | jfengel wrote:
           | Force of habit. We don't have a framework for talking under
           | these circumstances, so we apply our outdated ones.
           | 
           | As you say, that's exactly what got us here. But the
           | alternatives are very unclear, and seem deeply unpleasant.
        
             | MiguelX413 wrote:
             | People should suck it up and not do it again.
        
               | jfengel wrote:
               | The question is what they should do instead.
               | 
               | They could attack the non-steelmanned version, but that
               | just opens them up to having their own comments attacked.
               | You quickly get derailed. (It's sometimes called
               | "sealioning".)
               | 
               | They could propose alternatives, but that too is subject
               | to sealioning. Real alternatives are always subject to
               | tradeoffs, and the answer to "how about you do X instead
               | of attacking me?" is always "no".
               | 
               | They could refrain from discussing it, but that just
               | allows the offenses to continue.
               | 
               | So what often happens is that people persist in acting as
               | if this were a sincere discussion, and hope that a
               | majority will recognize the quality of your argument.
               | It's a lousy plan but I don't have much else to suggest.
        
           | King-Aaron wrote:
           | I still find it wild that so many people are trying to frame
           | these decisions through a political lens. This is the actions
           | of a foreign bad actor dismantling critical institutions from
           | within, not "bad policy".
           | 
           | Surely there's an antibody response.
        
             | inejge wrote:
             | > I still find it wild that so many people are trying to
             | frame these decisions through a political lens.
             | 
             | Why? The decisions are pretty well politically aligned with
             | the ideology which detests the size and scope of the
             | government (realistically, those aspects which the
             | ideologues feel are not in their interest). What _is_
             | unexpected is the swiftness and the brutality of action,
             | but revolutions tend to be messy, and make no mistake, this
             | is a revolution.
             | 
             | > This is the actions of a foreign bad actor
             | 
             | Now _this_ sounds like a coping strategy: everything is so
             | preposterous it couldn 't possibly be homegrown. Foreign
             | influence and underhanded actions are as old as human
             | interactions, but IMO outright plants can't succeed without
             | a massive economic and power asymmetry between the
             | adversaries.
        
               | King-Aaron wrote:
               | lol, coping strategy? I'm not American and have no reason
               | to 'cope' with anything. There is enough evidence to make
               | a strong allegation about Trump being a Russian asset.
               | 
               | The entire world seems to be able to 'cope' with that
               | assessment.
        
               | rat87 wrote:
               | They are not. Trump is no libertarian or small government
               | guy. The build the wall guy is the opposite of that. Even
               | with stuff like social security he usually at least
               | rhetorically claimed to be for more benifits (as long as
               | it goes to "real Americans") and he is all for increasing
               | police and military spending. And generally spending more
               | on stuff that gives him money. Plus giant tax increases
               | (tarrifs). He doesn't care much if government is
               | dismembered as long as it owns the libs and gets rid of
               | the public corruption prosecutors/others who might stand
               | up to him
               | 
               | Trump's actions towards Putin are highly irrational.
               | Maybe he's being blackmailed, maybe he's being bought,
               | maybe he just has likes Putins style but there is a
               | reason people suspect him despite it being unlikely in
               | the general case.
        
               | King-Aaron wrote:
               | > He doesn't care much if government is dismembered
               | 
               | This is exactly the process that conservatives take to
               | privatise services into their own friends pockets.
               | Destroy services until they're ineffective and use it as
               | an excuse to privatise it.
               | 
               | There's no such thing as small government, only large
               | sprawling private services that the government hands
               | money to.
        
           | almostgotcaught wrote:
           | Imagine being eaten alive by a cackling hyena that ambushed
           | you and all the while being like "hmm what is the appropriate
           | steelman here? why do I deserve this? why is this just?"
           | 
           | In reality this would never happen so all these people
           | playing steelman are just detached/insulated.
        
           | petesergeant wrote:
           | >> I'm trying to steelman
           | 
           | > Why?
           | 
           | It's a sensible practice and good practice
        
             | giraffe_lady wrote:
             | I just don't see how it is _universally_ so, frankly. As a
             | general guideline sure but some discernment is necessary
             | nothing is gained from steelmanning apartheid or the third
             | reich or torture prisons or or you see my point I hope.
        
               | petesergeant wrote:
               | How can you argue effectively against something if you
               | don't understand the strongest version of the argument
               | _for_ it?
        
               | giraffe_lady wrote:
               | We're way past the point of policy disagreements the
               | relevant question right now is _how do you stop them_. It
               | 's certainly not by reimagining your adversary's actions
               | in the most charitable light.
        
           | emmelaich wrote:
           | It is the belief that it is not in good faith that makes it
           | _more_ important that you try to steelman it.
           | 
           | If the steelmanning fails then you can you can be even more
           | confident that it is in bad faith.
        
         | rqtwteye wrote:
         | I think it's ignorance and arrogance. The US seems to be on a
         | path to lose technological and science leadership. The current
         | leadership doesn't seem to understand things that aren't
         | flashy. I wonder when they'll dial back on food safety. I am
         | sure RFK knows some vitamins that protect against salmonella
        
           | johnnyjeans wrote:
           | important to note: the US's food safety is already really
           | bad. salmonella isn't a thing you have to worry about in
           | first world countries. can't wait to see what plague demon
           | spawns out of a food industry running amok after the FDA gets
           | gutted.
        
             | ac29 wrote:
             | > important to note: the US's food safety is already really
             | bad. salmonella isn't a thing you have to worry about in
             | first world countries.
             | 
             | There were 65,000 cases of salmonellosis in the EU in the
             | most recent data I could find (2022). Thats a lower per
             | capita rate than the US, but definitely not zero.
        
               | rickard wrote:
               | I agree that it's not zero, but according to CDC, the US
               | sees about 1.35 million cases per year in a population of
               | about 346 million, which is about 390 cases per 100,000
               | people. Your figure for the EU over a population of 447
               | million in 2022 gives 14.5 cases per 100,000 people, or
               | more than a factor of 26 less.
               | 
               | Being 26 times less worried about something translates,
               | at least for most things, for me, to not being worried
               | about it any more.
        
             | WrongAssumption wrote:
             | That's just not true.
             | 
             | https://www.npr.org/sections/shots-health-
             | news/2025/04/15/nx...
        
             | jjmarr wrote:
             | At least American chicken is chlorinated:
             | 
             | https://www.npr.org/sections/shots-health-
             | news/2025/04/15/nx...
        
               | WrongAssumption wrote:
               | From the the very article you linked
               | 
               | "The vast majority of chicken processed in the United
               | States is not chilled in chlorine and hasn't been for
               | quite a few years," says Dianna Bourassa, an applied
               | poultry microbiologist at Auburn University, "So that's
               | not the issue."
        
             | buzer wrote:
             | Salmonella and it causes are very regional in EU. Places
             | like Finland have basically 0 cases of salmonella caused by
             | domestic poultry products per year. If there salmonella is
             | found from any chicken in the flock, the whole flock will
             | be quarantined and generally fully slaughtered (meat & eggs
             | must be pasteurized after the slaughter if they are sold).
             | In 2023 0.1% of the tested flocks had salmonella.
             | 
             | According to
             | https://pmc.ncbi.nlm.nih.gov/articles/PMC11945640/ most of
             | the outbreaks in humans (where exact cause was found) were
             | caused by foreign vegetables.
             | 
             | On other hand countries like Italy find positive samples
             | from 27% of their flocks ( https://efsa.onlinelibrary.wiley
             | .com/doi/epdf/10.2903/j.efsa... ). USA doesn't do testing
             | at that level as far I understand, I only found that 8% of
             | the tested chicken parts have salmonella
             | (https://www.propublica.org/article/salmonella-chicken-
             | usda-f...).
        
           | senectus1 wrote:
           | the guy is ultimate small gov. he wants to rip it out by the
           | roots.
        
             | dmix wrote:
             | I don't think he's considered a small gov conservative. He
             | increased spending last time and has continued so far this
             | term. His tariffs are one of the biggest expansions in gov
             | interference in modern history. They are also attempting to
             | significantly expand executive power beyond even 9/11
             | terrorism days.
        
             | 01HNNWZ0MV43FF wrote:
             | Small enough to fit in a uterus, big enough to kidnap and
             | shoot citizens
        
           | parrellel wrote:
           | According to the radio this morning, they're currently
           | working to close all the FDA branches that do food safety
           | testing, so, good guess?
        
         | polski-g wrote:
         | We have a 2tn deficit. If Congress wants to fund this, they
         | need to make it mandatory spending and raise taxes.
        
           | toomuchtodo wrote:
           | Or cut from $877B in defense spending instead?
           | 
           | https://usafacts.org/government-spending/
        
             | xphos wrote:
             | Listen, I hate the debt, but we have an income problem, not
             | a spending problem. The military looks like a waste, but it
             | does more than build bombs i.e research etc.
             | 
             | The issue we have is that republican every chance they get
             | since the 1970s have cut taxes. And then blamed democrats
             | for causing the deficits. We don't need smaller
             | governments. We need a reasonable tax system that taxes
             | people. It can be progressive like it was before we decided
             | rich people just need it easier than poor people.
             | 
             | Yes, I will pay more taxes sign me up, especially if they
             | can finally fix the roads and fund research. The problem is
             | my taxes as a middle-class person go up and rich people get
             | a tax cut. It's stupid. I like water provided by government
             | utilities, I like planes that don't crash into stuff
             | because there are air traffic controllers. These things
             | used to work because we paid for them. When you buy cheap
             | you get cheap.
        
               | dboreham wrote:
               | Military also employs a bunch of people who otherwise
               | would be poor. Also provides a gentrification path for a
               | bunch of previously poor people extending throughout
               | their lives.
        
               | LPisGood wrote:
               | Yes, a big part of the size is because the military is a
               | massive and horrendously inefficient jobs, education,
               | housing, and healthcare program.
        
               | throitallaway wrote:
               | Don't forget all the beak-wetting that happens along the
               | way when signing contracts etc. That's where an actual
               | difference could be made.
        
               | matteotom wrote:
               | Yeah republicans claim to want to run the government like
               | a business, but the first thing a business should do when
               | they have a deficit is raise revenue! And especially in
               | the case of the US government, the the only barriers to
               | doing that are self-imposed.
        
           | viraptor wrote:
           | That's a good idea to raise during the budget time or with
           | some warning ahead of time. But even discussing the cost of
           | CVE program itself is likely a waste of time and money. When
           | trying to deal with 2tn deficit, looking at things that
           | historically got ~$5M is just a distraction. And the lack of
           | it may cost even more given how many existing
           | agreements/contracts rely on cve to be a thing - maybe just
           | in gov lawyers having to rewrite things.
        
           | rgreek42 wrote:
           | Selling bonds is not the same thing as a family budget being
           | in the red. Either you know this and you're making this
           | argument in bad faith, or you don't and, well...
        
           | chris_wot wrote:
           | Dear god, you don't just stop running government completely
           | because you have a deficit.
        
           | tootie wrote:
           | This is an absolute pittance compared to the total budget.
           | And considering the current administration wants a $4T tax
           | cut they are not interested in trimming the deficit at all.
        
             | throitallaway wrote:
             | Yep, DOGE is a song and dance distraction. If they were
             | serious about lowering the deficit they wouldn't have laid
             | off ~12K IRS workers (whom show a 7x ROI per head.) They
             | also wouldn't be asking to increase the military budget to
             | $1 trillion per year. Trump has spent 1/3 of his days in
             | office so far golfing; $30 million+ so far paid to Trump
             | properties for the privilege of that. This is the biggest
             | capture in US history and it's all out in the open.
        
           | 01HNNWZ0MV43FF wrote:
           | Republicans control Congress, this is bait
        
         | alephnerd wrote:
         | > I really can't think of a non- nefarious justification for
         | this
         | 
         | Tragedy of the commons - NVD and the CVE project havr been
         | backlogged and facing funding issues for a couple years now,
         | and most security vendors are either cagey about providing
         | vulns in a timely manner (as it can reduce their own
         | comparative advantage), or try upsell their own alternative
         | risk prioritization scores.
         | 
         | Every company will gladly use NVD and CVE data, but no one
         | wants to subsidize it and help a competitor, especially in an
         | industry as competitive as cybersecurity.
        
         | WesternWind wrote:
         | It's incredibly foolish. Whatever the justification is, it
         | doesn't matter as much as the horrible outcome.
         | 
         | This is one of those things the government does for the benefit
         | of the whole.
        
         | ajross wrote:
         | _Probably_ the thinking goes that someone in the international
         | community will step in. CVE is in practice a global registry
         | for all, thus  "Why should the USA Department of Homeland
         | Security pay for all the freeloaders".
         | 
         | Still shortsighted and stupid, but it's plausible this is
         | intended as leverage to get someone else to pony up.
        
         | Cthulhu_ wrote:
         | Reduce government spending; since it's not actually a
         | government organization (as far as I can tell, I never looked
         | into it before), other organizations can fund it. How much goes
         | into this organization a year anyway? I'm seeing a Mitre
         | corporation that does lots of other stuff too that has a
         | revenue of 2.2 billion a year.
         | 
         | Multi-trillion-dollar companies benefit from and contribute to
         | this system, surely they can spare 0.01% of their revenue to
         | this bit of critical infrastruture?
        
           | bert-ye wrote:
           | > surely they can spare 0.01% of their revenue
           | 
           | They would, if we made companies pay their taxes.
           | 
           | Yes, you can also run such a system based on donations. But I
           | personally think that such a system is important enough to be
           | paid for by the government. When you run on donations, there
           | will always be conflicts of interest and the risk of running
           | out of funds.
           | 
           | But yeah, Mitre being a private organization that was paid
           | for by the government was a problem.
        
           | terribleperson wrote:
           | Yes, I'm sure corporations funding the CVE system would go
           | wonderfully. "It would be best if we don't see any severe
           | CVEs for our products this quarter, if you want our funding
           | next quarter."
        
           | kesor wrote:
           | MITRE is a non-profit, it receives about $1.5B from the
           | federal government, and another almost $2B from Virginia.
        
         | karel-3d wrote:
         | Reduce spending. Steelmanning (not actually believing this): it
         | probably cost a lot for what is essentially a database, and can
         | be done cheaply by private sector (Google, Microsoft).
        
         | myko wrote:
         | It's a dying empire, really nothing else to say. The USA led
         | world order is over, we've voted ourselves out of it, and now
         | need to learn how to deal with that.
        
           | drstewart wrote:
           | Wow! So who is leading the world order now (aka who is
           | funding MITRE)?
        
         | throw4847285 wrote:
         | I'll admit this is a bugbear of mine, but I think this is the
         | reason "steelmanning" is counterproductive.
         | 
         | Steelmanning is a neologism that serves no purpose other than
         | in-group signaling. There was already a perfectly acceptable
         | term for the same concept, one with more nuance and a rich
         | history: Charitability.
         | 
         | The major difference is that charitability is about treating
         | your interlocutor with respect. Steelmanning is about using
         | one's own intellect to make your interlocutor's argument better
         | than them. Because charitability is based on a concept of
         | mutual respect, if somebody clearly doesn't respect you one
         | iota, then why would you be charitable? Steelmanning tries to
         | divorce the person from the argument, and is ironically both
         | arrogant and naive.
        
       | transpute wrote:
       | If you work on OSS software on CVE management, then you already
       | know that NVD funding reductions have been ongoing for more than
       | a year.
       | 
       | April 2024, https://nvd.nist.gov/general/news/nvd-program-
       | transition-ann...                 NIST maintains the National
       | Vulnerability Database (NVD).. This is a key piece of the
       | nation's cybersecurity infrastructure. There is a growing backlog
       | of vulnerabilities.. based on.. an increase in software and,
       | therefore, vulnerabilities, as well as a change in interagency
       | support.. We are also looking into longer-term solutions to this
       | challenge, including the establishment of a consortium of
       | industry, government, and other stakeholder organizations that
       | can collaborate on research to improve the NVD.
       | 
       | Sep 2024, Yocto Project, "An open letter to the CVE Project and
       | CNAs", https://github.com/yoctoproject/cve-cna-open-
       | letter/blob/mai...
       | 
       |  _> Security and vulnerability handling in software is of ever
       | increasing importance. Recent events have adversely affected many
       | project 's ability to identify and ensure these issues are
       | addressed in a timely manner. This is extremely worrying.. Until
       | recently many of us were relying not on the CVE project's data
       | but on the NVD data that added that information._
       | 
       | Five years ago (2019), I helped to organize a presentation by the
       | CERT Director from Carnegie Mellon, who covered the CVE backlog
       | and lack of resources, e.g. many reported vulnerabilities never
       | even receive a CVE number. It has since averaged < 100 views per
       | year, even as the queue increased and funding decreased,
       | https://www.youtube.com/watch?v=WmC65VrnBPI
        
         | kulahan wrote:
         | What has been ongoing for more than a year?
         | 
         | The funding appears to have been cut off today, and both of
         | these comments seem to talk about continuing work and how
         | important it is.
         | 
         | Do you mean to say that some form of threat to the NVD has been
         | around for over a year now? Just want to be sure I'm parsing
         | correctly!
        
           | transpute wrote:
           | Yes, NVD funding cuts and a growing CVE backlog began in late
           | 2023.
           | 
           | May 2024, https://therecord.media/nist-database-backlog-
           | growing-vulnch...
           | 
           |  _> Moving forward, cybersecurity companies will have to
           | "fill the void" .. NVD said in April [2024] that it is
           | "working to establish a consortium to address challenges in
           | the NVD program and develop improved tools and methods." ..
           | CISA acknowledged the concerns and outrage of the security
           | community and said it is starting an enrichment effort called
           | "Vulnrichment, " which will add much of the information
           | described by Garrity to CVEs._
           | 
           | The second VulnCon event took place last week and no silver
           | bullet has appeared,
           | https://ygreky.com/2025/04/vulncon-2025-impressions/
           | Vulnerability enrichment was mentioned in many talks.
           | However, most organizations seem to handle it internally.
           | There doesn't appear to be momentum toward a shared or open
           | source solution - at least not yet.
        
             | cma wrote:
             | That says nothing about a funding cut, see my comment below
        
               | transpute wrote:
               | Following your comment's reference leads to a claim of
               | NVD needing 300 to 550 million (?!) per year, but only
               | receiving 4 million in funding. If anyone has pre-2024
               | data on NVD or MITRE CVE funding, that would be helpful,
               | https://news.ycombinator.com/item?id=43701532
        
         | cowpig wrote:
         | I've noticed that there's a post like this in most articles on
         | HN that could be construed as negative for the current
         | administration: some vague false statement followed by either a
         | factually incorrect explanation or some quote that does not
         | support the statement.
        
           | transpute wrote:
           | What is incorrect about the post above? There are citations
           | from multiple reputable news outlets for each claim.
           | 
           | People who actually work with CVEs have been posting about
           | this problem on HN for 18 months.
        
             | cowpig wrote:
             | Your post has now been edited to be factually correct. But
             | the misleading implication that this abrupt cut is part of
             | some other cuts that started before remains.
        
               | transpute wrote:
               | The post (currently AND previous to comments being moved
               | here from a different HN thread) links to the official
               | _2024_ (not 2025) statement about NVD cutbacks. Here's a
               | 3000 word article with quotes from Linux Foundation and
               | commercial vendors, around the same time,
               | https://news.ycombinator.com/item?id=43700884
        
               | RVuRnvbM2e wrote:
               | NVD != CVE
        
               | transpute wrote:
               | NIST owns the budget for both NVD and CVE, contracting
               | MITRE to operate the CVE program.
               | 
               | NIST budget was cut 12% in FY 2024 (Oct 2023 - Sep 2024).
               | 
               | An earlier bill to supplement NIST funding has been
               | reintroduced in 2025, https://fedscoop.com/public-
               | private-partnerships-bill-nist-h...
        
               | Larrikin wrote:
               | Anyone that silently edits their posts after being called
               | out for misleading statements or lies is arguing in bad
               | faith.
               | 
               | If you still have a cached copy of their original post
               | you should publicly edit your earliest reply with their
               | original quote.
        
           | flanked-evergl wrote:
           | Why do you post this on a comment that is neither of those
           | things then?
        
         | matthewdgreen wrote:
         | I did find this post to be non-helpful and confusing. It would
         | be helpful to edit it (or write differently in the future) to
         | clarify that the sudden defunding event occurring today is
         | separate and not related to the previous funding cuts. If
         | that's the case.
        
           | transpute wrote:
           | Is there no connection between 2025 funding cuts and previous
           | ones? e.g. If a year of work after the previous cuts resulted
           | in an open-data collaboration between NVD and commercial
           | vendors to share a subset of CC0 vulnerability metadata,
           | could that industry collective now argue for government to
           | share (with companies) the burden of funding an open,
           | decentralized program for CVE tracking? Commercial vendors
           | could still offer additional metadata and analytics, over and
           | above the public baseline.
           | 
           | Edit_1: found a proposed bill, April 2025,
           | https://fedscoop.com/public-private-partnerships-bill-
           | nist-h...
           | 
           |  _> A bipartisan bill that would establish a nonprofit
           | foundation aimed at boosting private-sector partnerships at
           | the National Institute of Standards and Technology was
           | reintroduced in the House and the Senate.. the proposed
           | foundation structure was described as replicating similar
           | nonprofits that support public-private partnerships at other
           | science agencies.. we encourage a strategy that leverages
           | NIST's leadership and expertise on standards development,
           | voluntary frameworks, public-private sector collaboration,
           | and international harmonization.. NIST's funding has been in
           | focus following a budget cut of roughly 12% to $1.46 billion
           | in fiscal year 2024._
           | 
           | Edit_2: is there a shortage of database rows, or people to
           | write a shell script? Why not pre-allocate N CVE IDs for
           | every CNA, while a new plan is worked out? At least one
           | random commercial vendor could foresee the shutdown early
           | enough to reserve CVEs.
           | 
           |  _> Garrity posted on LinkedIn, "Given the current
           | uncertainty surrounding which services at MITRE or within the
           | CVE Program may be affected, VulnCheck has proactively
           | reserved 1,000 CVEs for 2025," adding that Vulncheck "will
           | continue to provide CVE assignments to the community in the
           | days and weeks ahead."_
        
             | matthewdgreen wrote:
             | I am now more confused and not less.
        
               | transpute wrote:
               | Do you have any visibility into pre-2024 funding for the
               | NIST NVD and MITRE CVE programs?
               | 
               | MITRE CVE/CWE contract, $29M for 2024-2025, https://www.u
               | saspending.gov/award/CONT_AWD_70RCSJ24FR0000018...
        
               | transpute wrote:
               | Apparently 2024 NVD funding cuts did motivate CVE
               | contingency planning, https://www.thecvefoundation.org/
               | 
               |  _> A coalition of longtime, active CVE Board members
               | have spent the past year developing a strategy to
               | transition CVE to a dedicated, non-profit foundation. The
               | new CVE Foundation will focus solely on continuing the
               | mission of delivering high-quality vulnerability
               | identification and maintaining the integrity and
               | availability of CVE data for defenders worldwide. "CVE,
               | as a cornerstone of the global cybersecurity ecosystem,
               | is too important to be vulnerable itself," said Kent
               | Landfield, an officer of the Foundation._
        
         | RVuRnvbM2e wrote:
         | There is nothing in that article mentioning funding reductions.
         | 
         | That article is about how the volume of software
         | vulnerabilities are increasing, resulting in difficulty keeping
         | up by the CVE and NVD projects.
         | 
         | Please stop spamming this thread with political spin.
        
           | transpute wrote:
           | Both CVE (MITRE contract) and NVD are funded by NIST, https:/
           | /www.securitymagazine.com/articles/100795-understandi...
           | 
           |  _> Since February 2024, the National Institute of Standards
           | and Technology's (NIST) National Vulnerability Database (NVD)
           | has encountered delays in processing vulnerabilities.. caused
           | by factors such as software proliferation, budget cuts and
           | changes in support.. NIST, an agency within the United States
           | Commerce Department, saw its budget cut by nearly 12% this
           | year._
        
             | cma wrote:
             | Reading that article closely it says nothing about an NVD
             | budget cut, only a NIST one. They were trackijg the changes
             | after NIST's budget was cut, not NVD's. As pointed out
             | below, CISA announced a cut and then NIST more than made up
             | for it by reallocating funds, for an NVD funding increase,
             | even though NIST had their overall budget cut.
        
               | transpute wrote:
               | One of your references has budget numbers that are two
               | orders (?!) of magnitude higher than the CISA number.
               | Hopefully someone can chime in with granular historical
               | data for NIST NVD and MITRE-via-NIST CVE funding.
        
       | bradac56 wrote:
       | dupe of a dupe https://news.ycombinator.com/item?id=43700258
        
         | dang wrote:
         | I'm not sure, but the current article looks to have somewhat
         | more information in it, so I've merged that thread hither
         | instead.
        
       | 9283409232 wrote:
       | Reminds me of Trump's first term where he said if we stopped
       | testing for Covid, we'd stop catching new cases and case numbers
       | would go down. If you stop testing for vulnerabilities then
       | vulnerabilities go down. Easy stuff.
        
         | dboreham wrote:
         | So easy having the brain of a toddler.
        
         | goku12 wrote:
         | That's exactly what they're saying about the HHS cuts and the
         | measles outbreak.
        
         | flanked-evergl wrote:
         | What I don't get is why people make things up and then get
         | angry at the thing they made up. Is there not enough real
         | things to be angry at?
        
       | mjevans wrote:
       | Mr. President, Do you want China to get the reports instead, or
       | do you want the NSA to have a lead time where the vuln's are
       | useful tools?
        
         | hsbauauvhabzb wrote:
         | If you /s/China/Russia/, when asking Trump, it's no longer a
         | rhetorical question.
        
           | hsbauauvhabzb wrote:
           | For those reading, a fair few of my recent posts were
           | downvoted after this comment, and it was initially flagged.
           | 
           | If I violated some rule so be it, and I could care less about
           | internet points, but it certainly feels like suppression of
           | individuals based on individual posts which is a behaviour
           | that could end up being the death of hn.
        
         | mjevans wrote:
         | It seems phrasing it in the form of a joke was too much.
         | 
         | I was trying to convey (with levity/humor) WHY it should
         | continue to be funded as well as the argument that should be
         | made to the one currently in control of the spineless US
         | Congress.
         | 
         | Yes, fixing the vulnerabilities is important. However what the
         | government probably does gain from it is an inside advantage in
         | the lead time for vulnerabilities to protect against, as well
         | as to exploit on adversaries.
        
       | stego-tech wrote:
       | Man, I just can't even muster the snark I usually have for these
       | sorts of boneheaded decisions.
       | 
       | This sucks, plain and simple.
        
         | aprilthird2021 wrote:
         | I can't believe what a bunch of bollocks this administration
         | is. I couldn't believe it the first time, and this time I
         | thought "Well at least I'm ready, it will be a lot like last
         | time" and it's so much worse
        
           | 01HNNWZ0MV43FF wrote:
           | A lot was lost in the midterms and Supreme Court
           | appointments.
           | 
           | Hopefully these 4 years energize people to vote. I know
           | protesting and direct action and so on are also important,
           | but the gradient is not negative for voting for every office
           | you can vote for in every election.
        
             | aprilthird2021 wrote:
             | Yes, the next elections are all I have to look forward to
             | really.
        
               | jjav wrote:
               | Given the current government has blown off an unanimous
               | 9-0 supreme court decision, right now I can't feel too
               | optimistic there will even be more elections.
        
               | hn_throwaway_99 wrote:
               | I think there will be more elections, but I think they
               | will be fraudulent, because I think Trump has shown he is
               | adept at turning things around and then trying to pretend
               | that what he's doing is analogous to what the other side
               | has done.
               | 
               | For example, a lot of people have forgotten, but the
               | phrase "fake news" originally came about in the wake of
               | the 2016 election about all the (actually false)
               | misinformation that was spread on social media in the run
               | up to the election. Trump adeptly then co-opted the term,
               | so any news he didn't like he could just call it "fake
               | news", and who was to say any news he called fake was any
               | less fake than what people were calling fake before?
               | 
               | My guess is the 2028 elections will be marked by fraud,
               | and then when people protest or object, Trump and the
               | Republicans will just say "Hey, you called all those Jan
               | 6 protesters traitors and said the election was secure,
               | how is now any different? Now you're all the traitors."
               | 
               | The only belief that gives me hope these days is "History
               | will judge the complicit."
        
             | Terr_ wrote:
             | I'm scared that elections won't be secure, especially with
             | the way the Republicans are trying to (arguably
             | unconstitutionally) wield federal power to force individual
             | states to change their systems in abrupt ways.
        
             | sofixa wrote:
             | > Hopefully these 4 years energize people to vote
             | 
             | You are assuming there will be next elections that are
             | free, fair, and matter.
             | 
             | Trump says a lot of things that ultimately doesn't matter,
             | but he has also said, and is the type of brute to believe
             | it, that he intends to stay in power. He and his cronies
             | have successfully dismantled the checks and balances that
             | should have prevented him from doing they, legally. IMO the
             | only way he leaves the White House without stirring trouble
             | is in a casket.
        
               | the-chitmonger wrote:
               | Let's pray that his health suffers, in that case. I am so
               | unbelievably tired of reading the news and seeing another
               | pillar of civilization dismantled.
        
               | Onawa wrote:
               | I would rather that he stays alive for the rest of his
               | term. I am more scared of the damage that could be done
               | by Vance. Trump is inept and easy to manipulate, but is
               | fairly predictable in his actions. Vance and his
               | technocrat bros could cause a lot more damage on the
               | other hand. I'll take the devil we "know".
        
             | xyzal wrote:
             | I fear the situation either ends badly or in a bloodshed.
             | They aren't respecting the courts, so assuming they will
             | accept defeat in elections is naive.
        
               | MiguelX413 wrote:
               | Maybe that's the only way that people can learn.
        
               | ThatMedicIsASpy wrote:
               | People can learn once the world puts most of its money
               | into education.
               | 
               | The unfortunate part is that education is often also part
               | of propaganda and spinning history for said propaganda.
               | These days I wish education had a bigger emphasis on
               | history and history should be looked at from different
               | angles, like how the same thing is being taught from
               | different angles.
        
               | scoresomefeed wrote:
               | No. Look at the bloodshed in the Middle East. Man is a
               | bad animal.
        
             | AlexandrB wrote:
             | > Hopefully these 4 years energize people to vote.
             | 
             | This euphemism has to end. I think you mean: "Hopefully
             | these 4 years energize people to vote Democrat".
             | 
             | Why not just say it plainly instead of using supposedly
             | non-partisan language? This neutral phrasing seems to be an
             | appeal to a "silent majority" that agrees with you and
             | disagrees with Republican leadership. What if that silent
             | majority doesn't exist?
        
           | roughly wrote:
           | > it will be a lot like last time
           | 
           | A lot of people seemed to have had this theory, despite all
           | the evidence to the contrary.
        
             | crazygringo wrote:
             | There wasn't any evidence, that's the problem.
             | 
             | It was all opinion. Trump said a lot of stuff before this
             | election, but he said a lot of stuff before his first one
             | too.
             | 
             | When people disagreed on what he might do, it was all
             | guesses. There was no evidence to base anything on. Would
             | his second term be restrained by people around him like in
             | his first? That would be an evidence-based extrapolation.
             | Would tariffs be all talk and little action, like in his
             | first term? Extrapolating from evidence, they would be. But
             | 2025 isn't 2017. Things would be different, but _how_? It
             | 's all guesses.
             | 
             | It's only hindsight that is 20/20.
        
               | ddejohn wrote:
               | It's insanely naive to have thought a second Trump admin
               | would not be worse in every possible way. Did you pay
               | attention at all to what was going on with SCOTUS?
               | Project 2025?
               | 
               | Saying "there wasn't any evidence" is borderline bot-
               | speak. Anybody who thought Trump 2.0 was going to be like
               | the first round was simply not paying attention _at all_
               | and anybody telling others it wasn 't going to be like
               | the first admin is either a Russian troll, the mainstream
               | media, or just plain irresponsibly ignorant.
               | 
               | "Nobody could have foreseen this" is about the dumbest
               | take I think I've seen so far.
        
               | crazygringo wrote:
               | Oh please.
               | 
               | Can you tell me where in Project 2025 it talked about
               | sending legal immigrants to an Ecuadorian gulag? Or where
               | it talked about 145% tariffs on China? Or removing
               | fluoride from water, or going anti-vax? Or sending the
               | economy into what might be a recession? Or where Musk
               | would be invited in to rampage?
               | 
               | You're being completely intellectually dishonest here. I
               | don't support Trump _at all_ , but even people who
               | thought they were braced for the worst have been
               | blindsided by what's been happening. To call them
               | "Russian trolls" or "irresponsibly ignorant" is the
               | dumbest take _I 've_ seen so far. But it's real easy to
               | pretend like you're smarter than everyone else _after_
               | events have occurred, isn 't it? Like I said, hindsight
               | is 20/20. But go on believing you're so much smarter than
               | everyone else, if that's what your ego needs.
        
               | alpha_squared wrote:
               | Sorry, but this is a very misguided take. He tried to do
               | all the same things his first term, but enough people
               | around him kept him in check. Now, he explicitly got
               | "yes" folks around him and purged the career folks who'd
               | uphold the Constitution. He's emboldened like a child who
               | just learned they can command the world to do their
               | bidding without restraint.
        
               | ddejohn wrote:
               | It's one of the worst takes I've ever seen, and there are
               | a lot of bad takes out there.
               | 
               | Even the premise of their argument is silly -- "evidence-
               | based extrapolation" lmao that's not how politics work at
               | all.
        
       | hansvm wrote:
       | Weren't there major problems with the current CVE implementation,
       | especially with the waves of script kiddies and AI tools spamming
       | the database and the fact that projects who take security
       | seriously have little to no say in the "score" that gets
       | assigned?
        
         | czk wrote:
         | and then a random 9.8 critical comes that affects some software
         | you have in a way that makes it a 0 in your environment but it
         | doesn't matter cause the cve tanks your organizational Security
         | Score (tm) by 10 arbitrary points and management is wondering
         | when you'll secure the company again because the Security Score
         | is their only tangible deliverable to measure success
        
           | idiotsecant wrote:
           | I feel that. So tired of management being completely
           | uninterested in actual, actionable security holes but getting
           | wildly spun up because they saw a notice with a big scary
           | number that has absolutely no relevance in our architecture.
        
           | icameron wrote:
           | Yeah like when we bundled in a .js library for client side
           | date processing that has a CVE affecting node.js servers with
           | high score. Our auditors don't care they tag the whole app as
           | high risk. It doesn't even run on the server!
        
             | czk wrote:
             | the auditors that sign off on your security to meet your
             | clients requirements usually know way less about your
             | security posture than your clients do
             | 
             | its all just surface-level box-checking. most companies
             | required to get 'penetration tests' just get an overpriced
             | Nessus scan sold as a pentest and that meets their reqs.
        
               | JohnMakin wrote:
               | while this is true it in no way diminishes the value that
               | orgs like cve provide
        
             | jeroenhd wrote:
             | Incompetent auditors don't detract from the classification
             | system, though. If we removed every data point auditors
             | misinterpret or don't care to understand, we may as well
             | remove all metrics.
        
           | giantg2 wrote:
           | Most tracking tools have exception processes. But yeah,
           | security as a product family instead of a simple score seems
           | to be a foreign concept at most companies.
        
           | maronato wrote:
           | Don't let the perfect be the enemy of good. It is(was?) a
           | very useful and important system.
           | 
           | Trump must be receiving a lot of emails from companies
           | wanting to fill the void, and I bet the Trumpiest of them all
           | is going to be awarded a contract worth 10x the budget CVE
           | had, and do a much worse job.
        
           | horacemorace wrote:
           | It's Way Better than what we had before: software vendors
           | making even arbitrarier decisions about how to classify them.
           | 
           | There are far too many bad actors for us to operate as an
           | industry with no yardstick.
        
             | ngneer wrote:
             | I disagree that it is Way Better than before. A judgement
             | call is worth more than a team wasting effort chasing
             | irrelevant pseudo-vulnerabilities being reported as
             | vulnerabilities. A broken yardstick is worse than no
             | yardstick.
        
               | grumbelbart2 wrote:
               | But that's an issue organizations bring upon themselves,
               | by defining semi-arbitrary KPIs that are used without
               | proper interpretation. It's not directly caused by CVEs
               | or assigned scores. It's like blaming git that it count
               | lines in diffs, because your company created a KPI that
               | measures developer's based on LOC changes.
        
               | ngneer wrote:
               | Fair point. I was not blaming CVE for the situation,
               | simply bemoaning the situation.
        
           | ngneer wrote:
           | Spot on. Vulnerability scanners that make up an
           | organizational Security Score (TM) tend to operate at the
           | wrong level of abstraction, flagging some library somewhere
           | that never runs and has nothing to do with your production
           | flow or architecture, or some test keys with zero security
           | impact. Go explain that to management, because obviously the
           | security tools are right and you are wrong. This sad state of
           | affairs is unfortunately the best that the security industry
           | has been able to deliver. Trying to wrangle complexity by
           | adding more complexity is the craziest notion to me. Yes, no
           | scoring scheme is perfect, but when the scheme introduces
           | more noise, what have we gained (well, security vendors gain,
           | but what have organizations gained).
        
             | j-krieger wrote:
             | This is my research field. Do you have any input you can
             | think of at the top of your head?
        
               | ngneer wrote:
               | That's very cool. You probably know more about it than I
               | do, then, but my advice is to articulate the exact
               | problem you try to solve.
               | 
               | I expect your field is probably teeming with AI proposals
               | or offers on how to manage vulnerabilities, but that is
               | doubtful the way, because again it is adding complexity,
               | and no classifier is perfect, especially when scanners
               | fail to understand scanned applications and their threat
               | models or environment.
               | 
               | Stop selling external scanners, start simplifying code?
               | This will never work, of course, because security vendors
               | sell the promise of security to those willing to buy it,
               | in the form of add-on products and capabilities.
               | 
               | Empower people to ignore scanner reports without so much
               | red tape? That would never work either, because megacorp
               | wants compliance and reduced liability.
               | 
               | Build secure systems as opposed to cataloging and scoring
               | flaws? That would never work, because building secure
               | systems is hard, nature tends to favor otherwise.
               | 
               | Charge people for adding complexity and credit them for
               | removing complexity? Sadly, there is no way to do that,
               | especially since products must ship and quality is hard
               | to observe, since it is often invisible and only surfaces
               | when things are broken.
               | 
               | Off the top of my head, would be nice to require proof of
               | exploitation, by adding CTF-like capabilities to apps,
               | such that only if the flag is captured do we consider the
               | report real. This places more burden on scanners, in that
               | it is no longer enough to report an outdated library.
               | Requiring some proof of exploitability reduces noise and
               | increases SNR, reducing false positives. Naturally, not
               | all vulnerabilities have working exploits, and scanners
               | can never fully simulate an adversary, so we may get more
               | false negatives, but at least we would not have to waste
               | so much time upgrading pointless modules and breaking
               | applications to appease a false report. So the idea is
               | "here is a dummy asset, show me how you leaked or
               | compromised it". Adding the dummy asset should be cheap,
               | but would force scanners to better simulate an attack.
               | 
               | At the very least, there ought to be a knob to decrease
               | scanner sensitivity.
        
             | nikanj wrote:
             | And it's not enough to explain it to management, you also
             | need to explain it to your ISO auditors, your customers et
             | cetera ad nauseam.
        
           | elric wrote:
           | Solving this problem in a generalized way is really hard.
           | 
           | Maybe I have a dependency on Foo which has a critical
           | vulnerability in a feature that I don't use. I suppress the
           | warning and all is well. Then two weeks later someone on my
           | team decides to use that feature, not knowing that there's a
           | problem with it. Now we're fucked, and we'll never know
           | because the vulnerability has been suppressed.
        
         | sepositus wrote:
         | I don't know of anyone who doesn't quickly become exhausted
         | after running a CVE scanner on their code.
        
         | gcr wrote:
         | These sound like downstream effects of funding stress to me,
         | no?
        
         | tdb7893 wrote:
         | The scores were never going to be that accurate across people's
         | environments (IDK how much other places relied on them, places
         | I worked never did that much) and issues with the scores don't
         | seem to be a good justification to torch the whole CVE system
         | anyway.
        
           | hashstring wrote:
           | This^ and to add to that, at the very least MITRE assigned
           | IDs which is great. Plus they did an initial scoring, which,
           | well... will never be perfect like you said and I'm sure
           | these things evolve throughout time and get better (not
           | talking necessarily CVSS vX).
           | 
           | What a shame on this current gov. administration, if you can
           | even call it that.
        
           | mike_hearn wrote:
           | Why isn't it a good justification?
           | 
           | I think the question everyone in this thread should ask is:
           | why is it the government's job to do this, especially given
           | the prior widespread view that they're doing a bad job? Is
           | the software industry so immiserated by poverty that it
           | cannot organize its own distribution of security bulletins?
           | Clearly not: GitHub already runs its own vuln tracking scheme
           | that's better integrated with the tooling we use for open
           | source software. The industry routinely sets up
           | collaborations like standards bodies, information sharing
           | groups and more. And there is as whole ecosystem of security
           | companies to help you understand vulns in your stack.
           | 
           | So there seems nothing specific to CVEs that requires
           | government involvement, but the existence of the tax funded
           | scheme does discourage the creation of competitors that might
           | function better.
           | 
           | But, to CVE or not to CVE ... that is not the question. US
           | deficit spending is out of control. This sort of thing had to
           | happen some day. It's what Europeans in the 2010s called
           | "austerity" and it always makes some people scream but this
           | graph:
           | 
           | https://fiscaldata.treasury.gov/americas-finance-
           | guide/natio...
           | 
           | ... is not sustainable. Up to 1984 overall US debt was
           | stable. Since then its growth rate became dangerous. Debt/GDP
           | ratio is now worse than just after WW2. The federal
           | government is currently spending more on interest than on
           | defense or Medicare:
           | 
           | https://www.crfb.org/blogs/interest-costs-have-nearly-
           | triple...
           | 
           | The US is currently getting its first taste of what parts of
           | Europe started going through in 2008, and unfortunately
           | there's bad news: the cuts you're seeing now are mostly
           | cosmetic. They're what can be done within the current
           | framework of laws, sort of, with lots of bending of the rules
           | and creative interpretations of them and maybe some
           | oversteps. But it's just the start of what's needed. Large
           | scale reform of the laws themselves will be required
           | regardless of whoever wins the next elections.
        
             | theteapot wrote:
             | > why is it the government's job to do this?
             | 
             | Because the private sector can't see past their profit
             | motive to the national defense motive.
        
             | danso wrote:
             | > _But, to CVE or not to CVE ... that is not the question.
             | US deficit spending is out of control. This sort of thing
             | had to happen some day._
             | 
             | I suppose more people would be more amenable to these
             | wholesale cuts if the current administration weren't
             | blowing through even more money than before [0]:
             | 
             | > _The new Treasury Department data shows a deficit of
             | $1.307 trillion for October through March, the first six
             | months of the fiscal year 2025. And spending is $139
             | billion more in the first three months of 2025 compared to
             | the same period last year, with borrowing over that period
             | $41 billion higher._
             | 
             | We're currently fighting no wars and yet Trump is proposing
             | a record $1 trillion defense budget [1]:
             | 
             | > _"We're going to be approving a budget, and I'm proud to
             | say, actually, the biggest one we've ever done for the
             | military," he said. "$1 trillion. Nobody has seen anything
             | like it._
             | 
             | And that's _before_ proposed cuts to tax revenue [2]:
             | 
             | > _Extending the expiring 2017 Tax Cuts and Jobs Act (TCJA)
             | would decrease federal tax revenue by $4.5 trillion from
             | 2025 through 2034. Long-run GDP would be 1.1 percent
             | higher, offsetting $710 billion, or 16 percent, of the
             | revenue losses._
             | 
             | So this whole "we're just imposing much needed austerity"
             | to justify penny-wise-pound-foolish policies is kind of
             | laughable when the proposed increase to our peacetime
             | defense budget alone wipes out Elon's most recent estimate
             | of DOGE's total savings [3].
             | 
             | [0] https://apnews.com/article/trump-biden-budget-deficit-
             | spendi...
             | 
             | [1] https://www.militarytimes.com/news/pentagon-
             | congress/2025/04...
             | 
             | [2] https://taxfoundation.org/research/all/federal/trump-
             | tax-cut...
             | 
             | [3] https://www.nytimes.com/2025/04/14/us/politics/elon-
             | musk-dog...
        
               | mike_hearn wrote:
               | Yes. The Republicans are not and never have been united
               | around fiscal conservatism. Eliminate-the-deficit
               | libertarians are one faction within the party but not the
               | dominant one, and Trump doesn't come from it. Same with
               | most right wing parties the world over: the bigger
               | faction is usually one that likes both tax cuts and
               | spending increases. That's why deficits are out of
               | control across the west: between the tax-and-spend left
               | and the don't-tax-but-spend right, the don't-tax-and-
               | don't-spend contingent isn't big enough to outvote the
               | others. Clinton was very unusual in this regard, perhaps
               | a product of the short post-USSR consensus.
               | 
               | Elon is a libertarian and has been allowed to go do some
               | spending cuts around the edges. This gets support from
               | Republican members of Congress partly because the USG
               | turns out to be spending a lot of money on highly
               | partisan Democrat projects, but mostly because it's
               | someone else doing the cutting and not them. Even if they
               | know they should be doing it themselves they don't want
               | the crazies trashing _their_ cars, so if some outsider
               | does it for them that 's a deal they'll happily take
               | whilst it lasts.
               | 
               | All that said, it's inevitable that the administration
               | would be blowing through more money than before even with
               | DOGE. It's the nature of debt that it compounds. The
               | level of cuts required to even keep the deficit stable
               | would be huge because interest payments are accelerating,
               | and the cuts DOGE are allowed to make are small (even
               | when they go further than they might technically be
               | allowed).
               | 
               | Right now there's just no mainstream support in US
               | politics for serious austerity. There never is in any
               | country, but sometimes the public can be convinced to
               | agree to some amount if politicians do a good job of
               | communicating the deficit problem. The UK in 2010 is an
               | example of that, where the Conservative/Lib Dem alliance
               | was able to convince the public to vote for spending cuts
               | (albeit not as deep as were actually required... but it
               | tided the UK over until the economy started growing
               | again).
        
             | rco8786 wrote:
             | > why is it the government's job to do this
             | 
             | This is like, exactly the sort of thing that the public
             | sector should be doing. There's no profit incentive for
             | this to happen in the private sector.
             | 
             | I don't disagree with your overall sentiment re:
             | unsustainable debt. But the answer must be reform and
             | taking hard looks at the military budget, not just randomly
             | cutting programs that you disagree with politically.
             | 
             | More like the Clinton approach.
        
               | mike_hearn wrote:
               | But, why is there no profit incentive to do this when
               | for-profit companies are already doing so?
               | 
               | https://github.com/advisories
               | 
               | Note that many of these entries start with GHSA not CVE.
               | 
               | Agree that the military budget should face large cuts
               | too, unless I guess a major war breaks out.
        
               | rco8786 wrote:
               | They are doing it, but there's no profit incentive.
               | Github is a bit of a special case because of their
               | commitment to OSS and the broader engineering community,
               | but the moment a downturn occurs and MS takes a harder
               | look at P&Ls, you better believe that's on the chopping
               | block.
               | 
               | The public sector is exactly where you need things that
               | are important to society but don't make money.
        
         | cantrecallmypwd wrote:
         | This is bikeshedding. The point is an authoritative process and
         | an identifier
         | 
         | All this does is help Putin and other rich grifters.
        
           | GolberThorce wrote:
           | you like to say word 'bikeshedding', adoption of formal
           | intellectualish sounding terminology even when inappropriate
           | is orange-site affliction I advise against. I am saying this
           | for your own sake... speak truths with POWER
        
             | benatkin wrote:
             | It's a legitimate term. It's like criticizing use of the
             | word _startup_ or demanding someone put a dash in
             | _frontend_ or _backend_.
        
               | GolberThorce wrote:
               | term is real... but is more like criticizing misuse of
               | word startup. to be even more accurate it is what I said
               | and not anything else
        
               | benatkin wrote:
               | Maybe you don't see how it's bikeshedding. Ah well, let
               | me try to explain.
               | 
               | It's because it's like if someone had forgotten to
               | validate the user's role in an endpoint in a Django app,
               | and someone said that they should have used Rails because
               | it's easier to understand. In reality both are easy
               | enough to understand to be able to do an authorization
               | check, and the framework isn't the issue. So the person
               | suggesting Rails is bikeshedding.
               | 
               | Likewise, if someone made another vulnerability database
               | it would likely have the same issue, and this isn't
               | really the place to solve it. If somehow this does
               | trigger the realization to solve it, then it will be by
               | luck.
        
               | stavros wrote:
               | We're getting into pedantic arguments, but bikeshedding
               | is when multiple people argue to death about the easy
               | stuff _because it 's easy_, and don't argue at all about
               | the actually hard stuff, because none of them know enough
               | to argue about it. I don't know what your example is, but
               | it's not bikeshedding.
        
               | benatkin wrote:
               | I had argued for a less pedantic take, but I guess by
               | replying to you I'm being pedantic. It seems to me that
               | my example not only is bikeshedding by the definitions I
               | find but also that to me it fits your definition of it.
               | It's easier to talk about what framework you think is
               | best than it is to talk meaningfully about process, which
               | is more relevant place to look to prevent serious bugs,
               | assuming both frameworks are capable.
               | https://en.wiktionary.org/wiki/bikeshedding
        
               | stavros wrote:
               | Bikeshedding is when people need to make a decision on
               | something, and keep talking and talking about the easy
               | stuff. Your example of someone offering a driveby opinion
               | isn't an instance of a group of people needing to make a
               | decision.
        
               | benatkin wrote:
               | Ah, it wasn't a driveby opinion how I imagined it, and
               | I've experienced stuff like it in the past. It would then
               | go into talking about rails features and libraries that
               | could save the day, and the django counterparts. The
               | decision that needed to be made would be what action to
               | take to prevent a similar issue from occurring in the
               | future.
        
               | stavros wrote:
               | I'm not saying it doesn't happen, but bikeshedding is
               | when you say "OK guys we need to figure out the
               | architecture of this complicated new service" and then
               | there's a bunch of debate on libraries and frameworks and
               | very little debate on the actual (hard) problem it needs
               | to solve.
        
               | cantrecallmypwd wrote:
               | Thank you for the unsolicited defense. Linguistic
               | _bikeshedding_ is tantamount to an ad hominem. It 's the
               | mark of someone unable or unwilling to form a rational,
               | valid argument or engage in civil discourse. Let's
               | instead refocus to the HN site guidelines please. :o)
        
         | aprilthird2021 wrote:
         | Sure. There's also major problems with the video encoding
         | pipeline at my big tech job. Let's just delete it
        
         | ajross wrote:
         | > Weren't there major problems with the current CVE
         | implementation
         | 
         | Absolutely. And if the headline was "DHS proposes improvements
         | and streamlining to the CVE program" we'd all probably be
         | cheering.
         | 
         | Leaping from "This is Flawed" to "Let's kill This" is a logical
         | fallacy. A flawed security registry is clearly better than no
         | security registry.
        
           | GolberThorce wrote:
           | There are a lot of logical fallacies. Have you heard of the
           | sunk-cost one? Or fallacy fallacy maybe? Or ten-tendril
           | eschatomon fallacy?
           | 
           | In honesty to say "logical fallacy" is spoddy, I advise
           | against for aesthetic reason.
        
         | worthless-trash wrote:
         | This will get lost in the noise, but i think you mean cvss.
         | 
         | CVE is simply identification of a flaw, not a scoring system.
        
         | bjackman wrote:
         | As an active consumer of CVEs: yea there are major problems. No
         | there's nothing better and no I don't have any better ideas.
         | 
         | The scores are mostly useless, I would not care if they
         | disappeared, I do not look at them. I don't really understand
         | why people get so upset about garbage scores though. If a high
         | CVSS score creates a bunch of work for you then your vuln mag
         | process is broken IMO. (Or alternatively, you are in the
         | business of compliance rather than security. If you don't like
         | working in compliance, CVSS scores aren't the root cause of
         | your misery).
         | 
         | Having a central list of "here's a bunch of things with stable
         | IDs that you might or might not care about" is very valuable.
        
           | Sander_Marechal wrote:
           | > you are in the business of compliance rather than security.
           | 
           | So, most businesses. They all need their ISO/NIST/HIPAA/etc
           | certs.
        
             | bjackman wrote:
             | Yeah, most businesses need window cleaners too. If you're a
             | window cleaner and you complain about all the birds
             | shitting on windows, I dunno what to tell ya.
             | 
             | If you're working in compliance either
             | 
             | A) you're stuck in your compliance job, that sucks, CVSS
             | scores aren't the reason why though.
             | 
             | B) you enjoy compliance.
             | 
             | C) you should change jobs.
        
               | SkyBelow wrote:
               | Often it is a second order impact. This creates a bunch
               | of work for the compliance people, but then the
               | compliance people end up competing a bunch of work for
               | everyone else. If you count anyone who might have to
               | follow compliance as working in compliance, then I
               | purpose that there isn't enough non-compliance jobs to go
               | around.
        
               | bjackman wrote:
               | Hmm I dunnno I think
               | 
               | a) If you are having to do busywork for compliance
               | reasons, you are either disempowered to push back on
               | bullshit work (case A above, unfortunate, but your job
               | was gonna suck anyway), or it's not really a second order
               | effect, you work in compliance in a meaningful way.
               | 
               | b) Compliance bullshit seems to expand into the space
               | available to it. Nobody thinks CVSS scores are
               | meaningful, the fact that they feed into compliance
               | processes is not the CVSS scores' fault it's the
               | compliance machine just globbing onto random bullshit as
               | its expansion continues. If you took away CVSS scores it
               | feels like it would just glob onto something else
               | instead.
               | 
               | Anyway, in the end I think we aren't disagreeing about
               | that much. I think they're silly, if someone wanted to
               | get rid of them I wouldn't try to defend them at all. I
               | just wouldn'e be the person to push for that.
        
         | bamboozled wrote:
         | Getting a bit tired of posts like this (no offense), something
         | dumb / nefarious happens like funding is cut for <useful
         | thing>, then someone posts an off the cuff comment or question
         | like, "wasn't this <useful thing> not that useful because
         | <superficial reason>?".
         | 
         | Why do people do this, to down play all the destruction of the
         | last few months? Seems to be some type of coping mechanism.
        
         | rco8786 wrote:
         | Every system has problems. The challenge is to address the
         | problems and fix them. Not just delete the entire system and
         | claim a win.
        
         | declan_roberts wrote:
         | Yes it earnestly needed new direction and leadership.
        
         | bearjaws wrote:
         | Classic "oh its broken so throw it all away".
         | 
         | It's the way it is because there isn't a good alternative. They
         | cannot possibly know every environment that we operate in.
         | 
         | To this day we still have large corporations down playing their
         | issues, and it was way worse 20 years ago.
        
       | ggm wrote:
       | I wish this hadn't happened.
       | 
       | I wonder what level of compartmentalisation inside DHS means they
       | didn't see this as having sufficient downsides?
       | 
       | I ask this, because I don't think anyone in the subject matter
       | specialist space would have made a strong case "kill it, we don't
       | need this" and I am sure if asked would have made a strong case
       | "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior
       | finance would do their own research (tm) and mis-understand what
       | they saw in how other people work with CVE, and who funds it.
        
         | hackyhacky wrote:
         | > I wonder what level of compartmentalisation inside DHS means
         | they didn't see this as having sufficient downsides?
         | 
         | This was not a carefully-weighed decision based on a cost-
         | benefit analysis. This was a political order, consistent with
         | the administration's policy of "cut everything, recklessly,
         | indiscriminately."
        
           | tmpz22 wrote:
           | Destroy, destroy, destroy. Promise to rebuild but don't. Take
           | it all.
        
             | cantrecallmypwd wrote:
             | Vampire capitalism. They want civilization to break down so
             | they can offer a solution for profit. The enemies of all
             | people and life on the planet are a tiny group of oligarchs
             | and their supplicants.
        
               | 01HNNWZ0MV43FF wrote:
               | Not unlike the manga Berserk
        
               | CamperBob2 wrote:
               | This isn't capitalism, any more than arson, burglary, or
               | extortion is capitalism. Get some new material.
        
               | tigerBL00D wrote:
               | To be fair, we don't yet know how capitalism ends.
        
               | Nevermark wrote:
               | I agree, given the right definition of "capitalism".
               | 
               | Unfortunately "capitalism" has two quite different
               | meanings. Which are rarely clarified in use.
               | 
               | Capitalism with a big C, a too common overarching
               | ideology, gets bent to mean whatever the greedy,
               | unethical and rich want it to mean so they can get more
               | money.
               | 
               | But small c capitalism, evolving from both practical and
               | ethical foundations, is a system so useful it has
               | multiplied the benefits of civilization. But it is just
               | one such system.
               | 
               | It can't do everything, it needs other independent
               | systems (justice, dispute resolution, rules of clarity,
               | risk & trust limiting systems, for starters) to work, and
               | extending it to places it doesn't work causes great harm.
               | 
               | (Like when perversely applied to those enabling systems,
               | in big C form, as is happening now.)
        
               | roughly wrote:
               | > any more than arson, burglary, or extortion is
               | capitalism
               | 
               | Indeed.
        
             | chris_wot wrote:
             | So much for the wunderkinds in DOGE.
        
               | sitkack wrote:
               | @bigballs, please save U.S.
        
               | drivingmenuts wrote:
               | Given that the Kids at DOGE are all computer experts,
               | this reeks of a calculated move.
        
               | consp wrote:
               | I think expert is not the right word for what looks like
               | mostly rookies.
        
               | krferriter wrote:
               | Absolutely not. They are not broadly experts, and they
               | are not making these decisions after careful
               | consideration, as evidenced by their continual acts of
               | stupidity and basic errors and cutting things despite
               | having no idea what it is they are cutting. Musk got in
               | an argument with someone who said DOGE cut funding for a
               | cancer treatment program, and Musk was calling the person
               | a liar, and the person provided evidence and Musk
               | admitted it was an accident. They are a clown car of
               | idiots who vastly overestimate their own knowledge and
               | underestimate how much good the government actually does.
               | They think they can just slash and burn and there will be
               | no negative consequences because they think the
               | government is worthless.
        
               | chris_wot wrote:
               | Until, like Ayn Rand, they actually need the government.
               | Then they'll be complaining how the government doesn't
               | provide services.
        
               | riffraff wrote:
               | My knowledge of Ayn Rand stops at having read a book (and
               | considered it silly), when did she need the government
               | and complained about it?
        
               | chris_wot wrote:
               | She was an Objectivist. She considered social security to
               | be "legalized plunder". Then when she needed it, she
               | decided to take it.
               | 
               | One of her wonderful worldviews was to rejects altruism
               | as a moral imperative, arguing that individuals should
               | live for their own rational self-interest. Social
               | security, based on the idea of supporting others,
               | contradicts this principle.
        
               | Nevermark wrote:
               | It takes strong and complex social glue to create a place
               | where millions can safely follow their own self-interest.
               | 
               | Which means anyone whose wisdom matches their self-
               | interest is going to understand that different things
               | have very different efficiencies at different scales.
               | 
               | And some things happen to be dramatically more
               | efficient/person and more effective, the larger the scale
               | they can be coordinated at.
        
               | InsideOutSanta wrote:
               | _> It takes strong and complex social glue to create a
               | place where millions can safely follow their own self-
               | interest._
               | 
               | This exactly. All of these people who profess to believe
               | in objectivism could easily move to a failed state and do
               | anything they want to with zero government intervention.
               | But they don't do that. They want all of the benefits of
               | a working government with none of the things required to
               | actually create a working government.
        
               | cratermoon wrote:
               | Side note: if they wait a little bit, they may end up not
               | needing to move anywhere after all.
        
               | jay_kyburz wrote:
               | It is in your self interest to have a strong social
               | safety net, because one day you might need it too.
        
               | ndsipa_pomu wrote:
               | Also, even if you don't need it yourself, it's far nicer
               | to live in a society where people's basic needs can be
               | met otherwise we end up living in some kind of Mad Max
               | apocalyptic wasteland where people with nothing and
               | nothing to lose roam the country looking for targets.
        
               | Tainnor wrote:
               | > One of her wonderful worldviews was to rejects altruism
               | as a moral imperative, arguing that individuals should
               | live for their own rational self-interest. Social
               | security, based on the idea of supporting others,
               | contradicts this principle.
               | 
               | This position was already pointed out by Plato (in the
               | Gorgias IIRC) as being inconsistent. Political systems
               | are made up by people - if a society, in particular a
               | democratic one, has certain systems in place, then this
               | is probably because it was (at least believed to be) in
               | the people's self interest.
        
               | drivingmenuts wrote:
               | I don't see altruism as being outside of my own self-
               | interest. I think that you get what you give, so having
               | to give up some money to the public good is OK (usually
               | not awesome, but OK).
        
               | orwin wrote:
               | What's funny, and it might be because of the translation,
               | but I first thought her book where all entrepreneurs are
               | hidden away in a sort of parallel country was a dystopian
               | satire and a joke about some people sense of self
               | importance. Then I learned about her (and when the book
               | was written too) and realised her book was to be read as
               | it was written, 'seriously'. Which makes it silly, but a
               | funny story.
        
               | aaronbrethorst wrote:
               | Medicare and social security after a lung cancer
               | diagnosis (from being a heavy smoker)
               | 
               | https://www.openculture.com/2016/12/when-ayn-rand-
               | collected-...
        
               | drivingmenuts wrote:
               | Sorry, I really should have said "experts" with the
               | rabbit ears. But it still reeks.
        
               | chris_wot wrote:
               | They've done their degrees and masters in Computer
               | Science, and many of them dropped out. But they focused
               | on AI, so I'm assuming this makes them great at
               | statistics, but does this mean they are great at
               | security? Given the way they've gone through a variety of
               | departments, I'd say they aren't.
               | 
               | The DOGE crew are incompetent. Witness their firing of
               | all the people who look after the nuclear stockpile and
               | Ebola research.
        
               | yowzadave wrote:
               | They are clueless kids at their first job, following the
               | orders of their hero. You think they'll resist when the
               | boss tells them, "cut everything"?
        
               | shakna wrote:
               | No. [0] I wouldn't say they are computer experts. [1][2]
               | 
               | [0] https://www.404media.co/anyone-can-push-updates-to-
               | the-doge-...
               | 
               | [1] https://www.npr.org/2025/04/15/nx-s1-5355895/doge-
               | musk-nlrb-...
               | 
               | [2]
               | https://www.bloomberg.com/news/articles/2025-03-14/doge-
               | staf...
        
               | RALaBarge wrote:
               | Hang out around here for a while and you will realize
               | quickly that us tech bros mostly just know tech stuff.
               | Our perceived intelligence in topics which we don't spend
               | our time on is called hubris and we are swimming in it at
               | all times.
        
               | ForOldHack wrote:
               | Soon to be powned, by their own extreme short
               | sightedness. Duh.
        
               | nwatson wrote:
               | Maybe "they" want to do the pwning with less coordinated
               | resistance. Doing away with CVEs would help with that
               | objective.
        
               | jeltz wrote:
               | No, they are not skilled enough to hack anything. These
               | are just a bunch of average junior engineers with hubris.
        
               | pohuing wrote:
               | Soon to be? They already failed to deploy a website
               | safely by exposing the db.
               | https://www.404media.co/anyone-can-push-updates-to-the-
               | doge-...
        
               | tw04 wrote:
               | I think you mean wonder kids.
        
               | riffraff wrote:
               | wunderkind is a loanword, it's one of those cases of a
               | German word being used but being odd in English since
               | it's so similar. Like kindergarten which is often speller
               | as "garden".
               | 
               | https://en.m.wikipedia.org/wiki/Wunderkind_(disambiguatio
               | n)
        
               | markhahn wrote:
               | "tariff as wunderwaffe" often comes to mind these days.
        
               | oezi wrote:
               | Many of these terms originate during the Nazi regime and
               | thus aren't used lightly in Germany anymore.
               | 
               | Other example includes: Endgegner (final boss) or
               | Endlosung (final solution)
               | 
               | I would suggest to avoid such terms.
        
               | ben_w wrote:
               | > Endgegner
               | 
               | I did not know about this, thanks for _die Vorwarnung_.
               | In context, I 'd assume "ultimate enemy"
               | (Gegner=opponent) as "final boss" sounds videogame.
        
               | consp wrote:
               | Many did in the golden age of German research, then to be
               | destroyed by those mentioned.
               | 
               | Either the philosophers or the mathematicians/physicists
               | likely coined them.
        
               | pseudalopex wrote:
               | Wunderkind and Endgegner are used lightly in Germany.
               | 
               | The parallels to Nazi Germany's striking but impractical
               | weapons seemed intended every time I heard or read
               | Wunderwaffe in English.
        
               | hnlmorg wrote:
               | I think the GP was making a reference to the Apple TV
               | show "Ted Lasso".
               | 
               | "Wunderkind" mispronounced as "Wonder Kid" is a running
               | joke in that show.
               | 
               | https://www.reddit.com/r/TedLasso/comments/132rw9v/what_t
               | he_...
        
               | obelos wrote:
               | I'm pretty sure this is a joke reference to Ted Lasso.
        
               | chris_wot wrote:
               | Same thing.
        
               | addandsubtract wrote:
               | They were able to eliminate all open CVE's while cutting
               | costs at the same time. Amazing!
        
             | Cthulhu_ wrote:
             | Did they promise to rebuild?
             | 
             | If I'm giving them the benefit of the doubt (which I hate),
             | it's a shotgun approach; cut things relentlessly and see
             | what falls apart. Chaos engineering applied to a country
             | and / or the world.
        
               | willy_k wrote:
               | That's exactly what it is, and they said as much
               | repeatedly while campaigning. Voters, in their zealotry
               | against the perceived status quo, failed to realize how
               | much of what we have right now you don't want to cut
               | recklessly, as well as just how reckless the people that
               | they were choosing to do that job were.
        
               | coldpie wrote:
               | > in their zealotry against the perceived status quo,
               | 
               | Perceived, not actual, because spreading lies and
               | misinformation is what makes the most money for the ad
               | sellers that make up 90% of our industry.
        
               | watwut wrote:
               | There are various glorious futures floating around about
               | how this will make America better, stronger, more
               | independent.
        
           | SecretDreams wrote:
           | > cut everything, recklessly, indiscriminately
           | 
           | Mostly discriminately, tbh.
        
             | MiguelX413 wrote:
             | https://mathstodon.xyz/@johncarlosbaez/114000054766059217
             | 
             | Ah yes, like the woke DEI grants for "Homotopical macrocosm
             | for higher category theory" for having the prefix homo-
             | 
             | Get a hold of yourself
        
               | SecretDreams wrote:
               | I can't tell what argument you're making within the
               | context of my post?
               | 
               | The OP said indiscriminately, which means they're cutting
               | uniformly across the board. I responded with "mostly
               | discriminately" which means they're more selectively
               | cutting based on prejudice. You then linked me a data
               | point where you show they cut funding because it has the
               | word "homo" in it and tell me to "get a hold of myself"..
               | but your link would directly support what I've said?
        
               | dTal wrote:
               | It is clear from context that the original comment is
               | using "indiscriminately" in a sense of "without due care;
               | thoughtlessly". Your first reply comes across as simply
               | contradicting it, i.e. asserting that actually these cuts
               | were made with an appropriate level of thoughtfulness.
               | Your point that there _are_ criteria which are being
               | applied is a useful contribution, but you should have
               | expanded on this in your original comment, as it was not
               | clear that you were reframing the discussion in this way.
        
               | SecretDreams wrote:
               | Respectfully, I took the word at face value and made what
               | I thought was a fair, albeit half-jokingly correction.
               | Certainly, I understood the context of the original post
               | and I expected that this community would understand my
               | follow up comment which is using correctly applied
               | English. For whatever it's worth, I see no synonyms for
               | indiscriminately that would fall under "without due care;
               | thoughtlessly" on Merriam-Webster. Even if I understood
               | what the OP was saying, it was not technically the
               | correct verbiage to use. I would have thought I'd receive
               | a similar level of "allowable nuance" in my comment that
               | the OP was afforded.
               | 
               | https://www.merriam-
               | webster.com/thesaurus/indiscriminately
        
               | howenterprisey wrote:
               | You're completely right, for what it's worth, and I
               | appreciated the wordplay.
        
               | SecretDreams wrote:
               | Thank you.
        
               | metabagel wrote:
               | I interpreted "discriminately" as exercising due
               | diligence. I think in this instance you were perhaps too
               | clever by half.
        
               | qzw wrote:
               | Most of the general population can't read above something
               | like a fifth grade level. Here on HN it's higher, but I
               | wouldn't say it's safe to assume you can just engage in
               | even mild word play without risking being misinterpreted,
               | unfortunately.
        
               | HelloMcFly wrote:
               | Written word play, especially in such a short sentence,
               | will be hit or miss with even capable readers because
               | one's interpretation will be devoid of interpersonal
               | context (including nonverbal signals) and heavy on other
               | context such as expecting some in this community to
               | continue to defend Elon/DOGE because we've seen it plenty
               | on HN to date.
        
               | albedoa wrote:
               | > albeit half-jokingly
               | 
               | It seems then that you could have acknowledged
               | MiguelX413's comment without the feigned aloofness?
        
               | SecretDreams wrote:
               | He came in quite hot and has made no acknowledgements of
               | my rebuttal. To be honest, taking a deep breath and
               | giving me a more sensible response than what I got could
               | have gone a lot way.
               | 
               | We're allowed, and should be encouraged, to write with a
               | small amount of nuance and creativity.
        
               | rfrey wrote:
               | Indiscriminate means at random or without judgement. The
               | comment you're arguing with clearly (and cleverly) said
               | the cuts are not random. As one data point, I did not
               | read the comment as contradicting anything, but as
               | agreeing and expanding.
        
               | fennecfoxy wrote:
               | Afaik there's never been a DEI initiative (or similar,
               | I'm not American) that I've ever heard of to hire more
               | gay people specifically. Most of us would hate to be
               | hired for our sexuality rather than our skills.
               | 
               | There's nothing "woke" about it and screaming woke woke
               | woke isn't going to change the fact that we exist and you
               | don't like it. I'd tell you what I really think of you
               | but it would invoke Dang.
        
               | metabagel wrote:
               | You misinterpreted that comment, which was sarcastically
               | pointing out a study which was purportedly cut simply
               | because it had the word part "homo" in it.
        
               | GuinansEyebrows wrote:
               | You have got to stop engaging with the idea of "woke" as
               | a specific ideology to stand against. It's like you
               | purposefully intend to misunderstand common shared
               | meanings of words.
        
           | derbOac wrote:
           | There are many problems going on right now, but in terms of
           | cuts this is one of the most problematic: everything is
           | secret, with no oversight or deliberation. It's
           | indistinguishable from corrupt malice because it's not done
           | with open thoughtfulness.
        
             | jacobyoder wrote:
             | I just can't believe your take on this. The White House
             | press secretary has directly said, multiple times, "this is
             | the most transparent administration ever". /s
             | 
             | In reality, this entire process is insanity. We've had
             | examples of government spending overhaul in the past -
             | early(?) 90s - both sides worked together, cut lots of
             | spending across programs, downsized tens of thousands of
             | federal workers, and balanced a budget, to the point where
             | we had a surplus. It was tough, took time, wasn't perfect,
             | but was deliberated and debated and far far far more open
             | and transparent than all this. But their goal was actually
             | improving government (even if that meant reducing some
             | areas). The current 'leadership' goal is to
             | dismantle/destroy as much as possible, as this is led by
             | people who think government in general should not exist.
        
           | tlogan wrote:
           | Yes, this is 100% consistent with their policy: cut
           | everything and if you find out that something is really
           | really needed then reverse it.
        
         | markhahn wrote:
         | it might be ignorance; it might be malice.
         | 
         | it might also be deliberate: that they actually don't think the
         | government should be involved in this sort of thing. after all,
         | someone could be making a profit on this, and that seems to be
         | their highest value. if gov is involved, that makes it a
         | communal effort, and you know what else starts with "commun-"?
         | 
         | yes, those reasons are stupid and ignorant AND intentional.
         | 
         | but is there any evidence against that interpretation?
        
           | ggm wrote:
           | Hanlon's razor. I also tend to impute malice to things I
           | don't like, but I think it's hard to go past stupidity.
        
             | groby_b wrote:
             | Stupidity rarely has a _consistent_ destructive track
             | record. You score occasional wins. Only malice allows every
             | decision to do damage. (The other razor, essentially -
             | Occam)
        
             | JoshTriplett wrote:
             | Sufficiently advanced stupidity is indistinguishable from
             | malice.
             | 
             | (Leaving aside that there's plenty of evidence of malice
             | here.)
        
             | gregw2 wrote:
             | I love Hanlon's razor. Super-helpful in certain contexts:
             | "Never attribute to malice that which is adequately
             | explained by stupidity."
             | 
             | But, having known about it for a dozen years now, I also
             | find it inadequate alone as a razor without the following
             | caveats/corollaries:
             | 
             | Hubbard's corollary to Hanlon's Razor: "Never attribute to
             | malice or stupidity that which can be explained by
             | moderately rational individuals following incentives in a
             | complex system". (
             | https://en.m.wikipedia.org/wiki/Hanlon's_razor#Exceptions )
             | 
             | Or (HN) Nerdponx's punchier simplification: "When money is
             | at stake, never attribute to incompetence what could be
             | attributed to greed." (
             | https://news.ycombinator.com/item?id=41066724 )
        
             | Terr_ wrote:
             | Hanlon's Razor is susceptible to pathological inputs,
             | causing unbounded runtime.
             | 
             | A large amount of things related to Trump fall into that
             | category, and it's important to recognize when you need to
             | instead treat it as a superposition: It is both malice
             | _and_ incompetence, unless the perpetrators decide to plead
             | just one or the other.
        
           | incompatible wrote:
           | > someone could be making a profit on this
           | 
           | Yes, there are apparently various ways of profiting from
           | vulnerabilities. The interesting question would be whether
           | any of the regime insiders have a way to profit.
        
             | markhahn wrote:
             | I think it's more of a principle: if it looks like someone
             | could charge money for it, they think that would make the
             | country stronger, because all they understand is first-
             | order profit. Trump's ethics is "get away with whatever you
             | can".
             | 
             | For instance, most people find healthcare middlemen
             | (pharmacy benefit managers, etc) to be grotesque parasites.
             | But to a laissez-faire fundamentalist, they're smart for
             | finding a way to liberate some profit, even laudable.
        
         | Aurornis wrote:
         | This sort of thing is happening across the federal government.
         | There is no rhyme or reason. DOGE has been given an unrealistic
         | target for cuts and they're desperately cutting whatever they
         | can get their hands on. If you look at the federal budget it's
         | nearly impossible for DOGE to hit their stated goals without
         | touching benefits like medicare and social security (which are
         | off limits so far) so the only option is deep, deep cuts into
         | the narrow slice of the federal budget that excludes those
         | protected categories.
         | 
         | There is no rhyme or reason to what gets cut, other than
         | someone under pressure to hit KPIs (dollars cut) was
         | desperately searching for things that looked easy to cancel.
         | 
         | This is happening _everywhere_ the federal government touches.
         | Most people aren 't aware of it until they come around and pull
         | the rug on something that intersects with your own life.
         | 
         | Even my die-hard Republican distant relatives are suddenly
         | shocked because programs they benefited from are being cut.
         | They thought they voted for something different.
        
           | shakna wrote:
           | I'd say that the rhyme and reason are quite clear [0]. They
           | published a playbook, and they are implementing it at a
           | record pace.
           | 
           | > The NSC [National Security Council] staff will need to
           | consolidate the functions of both the NSC and the Homeland
           | Security Council (HSC), incorporate the recently established
           | Office of the National Cyber Director, and evaluate the
           | required regional and functional directorates.
           | 
           | > Given the aforementioned prerequisites, the NSC should be
           | properly resourced with sufficient policy professionals, and
           | the NSA should prioritize staffing the vast majority of NSC
           | directorates with aligned political appointees and trusted
           | career officials. - Project 2025, pg 52.
           | 
           | > ... History shows that an unsupervised NSC staff can stray
           | from its statutory role and adversely affect a President and
           | his policies. Moreover, while the NSC should be fully
           | incorporated into the White House, it should also be allowed
           | to do its job without the impediment of dually hatted staff
           | that report to other offices. - Project 2025, pg 53.
           | 
           | The goal is to build up a political organisation to use as a
           | weapon, and to scrap the rest - as a legal excuse to say that
           | the political appointments will be necessary.
           | 
           | [0] https://www.project2025.observer/
        
             | ForOldHack wrote:
             | They have to find some gumbah to head the security
             | dept,because the best one they had,left in a hurry. Heard
             | he went to Denmark. ( I am really really kidding )
        
           | sofixa wrote:
           | > This sort of thing is happening across the federal
           | government. There is no rhyme or reason. DOGE has been given
           | an unrealistic target for cuts and they're desperately
           | cutting whatever they can get their hands on
           | 
           | You make it sound like poor DOGE employees are being forced
           | to do this on this kind of schedule, which definitely isn't
           | the impression I got. They're all a bunch of incompetent
           | overconfident weirdos who think they know better and what to
           | do. Is there any pressure to do anything quickly?
           | 
           | And the US federal budget is quite easy to trim. E.g. remove
           | an aircraft carrier from the planned construction pipeline
           | and you've saved $15 billion with no actual ramifications.
        
             | SpicyLemonZest wrote:
             | Who knows whether it will happen, but in principle DOGE is
             | working under some time pressure as they're scheduled to be
             | dissolved in mid-2026.
        
           | ForOldHack wrote:
           | The ryme is Humpty Dumpty, had a great fall. Now China and
           | Russian security forces step up their relentless attacks.
           | Let's hope the white house falls first.
        
           | riffraff wrote:
           | > Even my die-hard Republican distant relatives are suddenly
           | shocked because programs they benefited from are being cut.
           | They thought they voted for something different.
           | 
           | Out of curiosity, which programs? And is this enough to
           | change their opinion about Trump, or do they still think
           | it'll be worth it?
        
           | bruce511 wrote:
           | >>They thought they voted for something different
           | 
           | Like what exactly? I mean the guy ran on cutting the budget
           | by 2 trillion. In his last term he gave tax breaks yo the
           | rich. Where did they think the cuts were coming from?
           | 
           | He ran very hard on raising tarrifs. Which demonstrably raise
           | prices (thats literally their goal.) But now people claim "I
           | didn't vote for this."
           | 
           | In truth they voted for him because he was the Republican on
           | offer and they're die-hard Republican. The Republican party
           | has made no secret of its agenda for decades.
           | 
           | I get it, people are good at cognitive dissonance. But this
           | is the place for blunt truth. They voted for this. I'm not
           | letting Republicans got off the hook here. They voted for
           | this.
           | 
           | Just like to my Republican friends who are upset that CVE is
           | cut. You voted for this. The general public benefit from CVE
           | even though they dont know it exists. Just like you
           | benefitted from dozens of other programs you didn't know
           | existed, but have also been cut.
           | 
           | That's the problem with cuts. They ultimately end up hurting
           | everyone.
           | 
           | Now clearly there's some fat that could be trimmed. Companies
           | do it all the time. Done well its good. Swinging a hatchet in
           | a crowded elevator does not seem like "Done well".
        
             | lolinder wrote:
             | > In truth they voted for him because he was the Republican
             | on offer and they're die-hard Republican. The Republican
             | party has made no secret of its agenda for decades.
             | 
             | This is actually simply not true. The Republican party
             | before the Tea Party looked nothing at all like this. Trump
             | won the presidency last year riding a wave of distinctly
             | not-your-typical-Republican lower class voters. As he rose
             | the old guard Republican establishment formed the anti-
             | Trump wing of the party until they were forced out one by
             | one.
             | 
             | To put some numbers to this: Bush won the upper income
             | brackets by 5+ points in 2000, with a lead that widened as
             | you went up the income ladder. Trump lost the equivalent
             | brackets in 2024 by 5+ points, a 10 point swing away from
             | what Bush won them by. The lower brackets are even more
             | stark, with a whopping 18-point swing towards Trump in the
             | $30k-$50k bracket (inflation adjusted to $15k-$30k).
             | 
             | These numbers show that Trump is not a Republican in the
             | George W Bush sense and he's certainly not a Republican in
             | the Ronald Reagan sense. He's a populist and won on a
             | populist agenda by putting together a coalition of rabid
             | social conservatives (who probably really did go Bush in
             | 2000) and poor people (who largely did not).
        
               | rat87 wrote:
               | Populism is not an agenda it's a style. Also the majority
               | of poor people voted Democrat, the majority of people
               | with low education levels voted for Trump (which is not
               | the same thing as dumb, although voting for Trump is dumb
               | regardless of PhD or lack of HS diploma). There's overlap
               | between low levels of education and income but if you
               | define class by income then low income people mostly
               | voted Dem
        
               | sanktanglia wrote:
               | You are ignoring that trump rode to power explicitly by
               | enabling the shittest of Republicans that already exist.
               | To try and let republicans off the hook for supporting
               | him, especially a 2nd time? Is hilarious
        
               | lolinder wrote:
               | Even the first wave of Republican support came from the
               | Tea Party types more than the establishment types.
        
               | bruce511 wrote:
               | I'm upvoting you because you make a coherent argument,
               | and votes here should be for that, not whether I agree
               | with you or not.
               | 
               | I would agree he's not George Bush, much less Ronald
               | Reagan. Nevertheless those who voted for Bush and Reagan
               | also voted for Trump.
               | 
               | This has been "decades" in the making in the sense that
               | since Obama was elected (in 2008), Republicans have
               | embraced racism at the heart of their populist message.
               | That swing rightward was made palatable to center
               | republicans with a woman democratic candidate in 2016
               | (one not terribly well liked in democratic circles) and a
               | black woman candidate in 2024.
               | 
               | While racism, and misogyny gather a bunch of votes, long-
               | term distrust of institutions is sown, and fostered.
               | Republican policy becomes protecting white guys, and
               | especially old, rich, white guys.
               | 
               | Reagan was popular and competent, and worked for the good
               | of America. Today's president is nothing like him, but
               | wins because a bunch of people "vote Republican".
        
               | lolinder wrote:
               | > Today's president is nothing like him, but wins because
               | a bunch of people "vote Republican".
               | 
               | There's a component of that, but it's not the primary
               | cause. A lot of former Republicans stopped voting
               | Republican with Trump, including a lot of old rich white
               | guys, and a lot of the current Republican voters didn't
               | vote for Bush. He wins because of the new wave of voters
               | that counterbalanced the flight of the educated core of
               | the Republican establishment.
        
               | pseudalopex wrote:
               | > The Republican party before the Tea Party looked
               | nothing at all like this.
               | 
               | Starve the beast is older than the Tea Party.[1]
               | 
               | [1] https://en.wikipedia.org/wiki/Starve_the_beast
        
               | lolinder wrote:
               | There are extremely superficial similarities here, but
               | they're just that: extremely superficial. Along the same
               | axis but in totally different orders of magnitude, and
               | orders of magnitude make a difference.
               | 
               | Obamacare and communism are along the same axis too, but
               | the Republicans who claimed they were the same thing were
               | obviously wrong.
        
             | michaelt wrote:
             | _> Where did they think the cuts were coming from?_
             | 
             | When someone hands you a pencil, you don't wonder what
             | variety of tree the wood came from, or what paint chemistry
             | was used for the coating. It's a pencil. You might have
             | broad opinions on whether the one in your hand is
             | comfortable to use, and sharp - but you leave the details
             | to the pencil makers.
             | 
             | About 70% of the population engage with politics the same
             | way: Leave the details to the people who do this stuff for
             | a living.
             | 
             | Do they expect to be disappointed? Sure, but everyone who
             | engages with politics expects to be disappointed.
        
               | virgildotcodes wrote:
               | This pencil was proudly advertised as being comprised of
               | the remains of all that was decent in humanity. The fact
               | that it wrote in blood was gleefully touted and cheered.
        
               | pseudalopex wrote:
               | You are a pencil company director. A CEO candidate
               | promised to cut expenses by 30% by eliminating waste.
               | People who do this stuff for a living countered wood and
               | graphite exceed 70% of your expenses. The CEO candidate
               | proposed to increase graphite spending. Do you wonder
               | what the CEO would do if hired?
               | 
               | > Do they expect to be disappointed?
               | 
               | Aurornis said their relatives were shocked.
        
               | jeltz wrote:
               | It is traditionally cedar.
        
               | daveguy wrote:
               | This is exactly the attitude Putin tries to encourage in
               | his population. If enough people don't pay attention or
               | don't think what they do matters, it's easier to
               | subjugate a population.
               | 
               | If people in the US aren't starting to notice what
               | Musk/Trump are doing it will bode very poorly for the
               | future of the US.
        
           | eCa wrote:
           | > They thought they voted for something different.
           | 
           | They voted for the leopards to eat other people's faces, not
           | _their's_.
        
           | russellbeattie wrote:
           | Remember, DOGE has nothing to do with money or "efficiency".
           | It's a pure ideological dismantling of the Federal government
           | aimed at eliminating oversight, regulations, assistance and
           | entitlements as envisioned by ultra-conservatives for
           | decades.
           | 
           | This isn't speculation or hyperbole, it's specifically laid
           | out in their published plans: By hobbling or outright
           | eliminating federal agencies responsible for executing the
           | laws passed by Congress, the administration can circumvent
           | the democratic process and impose their extreme vision of
           | limited government on the country, regardless of popular
           | support.
           | 
           | The U.S. system of government relies on established norms as
           | much as it does law. Conservatives realized that they can
           | ignore precedent with impunity if they had an executive
           | willing to do so. They then spelled out exactly how, and are
           | now enacting that plan.
           | 
           | Then SCOTUS's decisions last summer turbo boosted their
           | agenda. The ruling that only Congress can hold the President
           | legally accountable essentially means executive power is
           | unchecked if the legislature is unwilling or unable to
           | Impeach and convict. The President can now confidently ignore
           | the law and judicial orders with a veneer of legality. And
           | this is what he's doing.
           | 
           | (The fact that all this just so happens to benefit Russia
           | after their decade long campaign to destabilize their
           | opponents in the West is a topic for speculation.)
           | 
           | DOGE is about permanently altering how our country works
           | modeled on the right wing worldview, plain and simple. Since
           | that's their overall goal, they're not concerned where they
           | swing the wrecking ball - it's all going to get destroyed
           | eventually.
        
             | misantroop wrote:
             | That plus privatising a lot of it. Kills two birds with one
             | stone, eliminate regulation and fill your pockets with
             | cash.
        
             | pron wrote:
             | > The U.S. system of government relies on established norms
             | as much as it does law.
             | 
             | And it's also happily breaking the law. The Executive
             | doesn't legally have the power to allocate resources (or
             | not), not to mention the power to arbitrarily suspend due
             | process.
        
           | fennecfoxy wrote:
           | Something different like gay people, women, immigrants all
           | suffering while they laugh. Who's laughing now? From an
           | outsiders perspective, I sincerely hope that Republicans get
           | to feel a fraction of what these usually marginalised groups
           | feel every day.
           | 
           | You'd think that lessons would incite learning but that has
           | never seemed to be the case throughout history.
        
         | Spooky23 wrote:
         | No, we're in a middle of a coup. Palantir or some other odious
         | company will get paid 100x more to do something.
        
           | cavisne wrote:
           | MITRE has a trademark on the term CVE.
        
             | pjmlp wrote:
             | As if laws have any meaning to this administration, and
             | anyone expecting this will only last four years instead of
             | turning into one of those countries so much admired by the
             | captain at the helm, is fooling themselves.
             | 
             | When the citizens realise this, the structures to clamp
             | down any revolution will be in place.
        
               | fennecfoxy wrote:
               | TBF trade-marking a term like "CVE" is the most
               | ridiculous fucking thing and just reeks of modern
               | American copyright law type stuff.
        
               | quesera wrote:
               | It's only superficially ridiculous.
               | 
               | "CVE" is trademarked and emphasized (e.g. included in the
               | shorthand notations, e.g. _CVE-2014-0160_ ), explicitly
               | to prevent other groups from using "CVE" in a way that
               | causes confusion in the marketplace. And yes, this is the
               | same reason trademarks exist for commercial purposes.
               | 
               | But imagine if Microsoft could issue CVEs against Apple
               | ... or OpenAI against Anthropic, etc.
               | 
               | The label "CVE" has to have a known authority to be
               | useful. And the only way to ensure that is to trademark
               | it. See also: "Linux(tm)".
        
           | ozim wrote:
           | People will not submit vulns as happily to such business.
           | 
           | Most of vulns will go unaddressed because company like
           | palantir will most likely want only really good vulns like
           | 0-click RCE.
        
             | daveguy wrote:
             | Putin, Xi, and Un say thank you.
        
         | epistasis wrote:
         | Your words don't make any sense in this environment. The idea
         | that any person at an agency could stand up to or convince the
         | DOGE team of anything is preposterous.
         | 
         | Anything that weakens the US or puts our cybersecurity in a
         | place that Russia can exfiltrate data will happen. This is not
         | about the US needing anything and it's silly to think
         | otherwise. See also the NLRB whistleblower and the security
         | backdoors that DOGE demanded to allow data exfiltration and the
         | subsequent death threats to the whistle blower.
         | 
         | You mindset is behind the times and needs to adjust to a,
         | frankly, insane current reality.
        
           | mmooss wrote:
           | > Your words don't make any sense in this environment. The
           | idea that any person at an agency could stand up to or
           | convince the DOGE team of anything is preposterous.
           | 
           | Your comment embraces and spreads the powerlessness they want
           | you to feel and spread.
           | 
           | Of course you can stop them - like any other negotiation in
           | life, especially non-friendly ones, you need to make it in
           | Trump's interest either by carrot or stick. Trump has
           | interests; identify them and identify your power in those
           | regards ('power and interest' is the term), and use it.
           | 
           | Also, stop helping them make DOGE the scapegoat. It's Trump.
        
             | epistasis wrote:
             | DOGE is doing this, it's not a "scapegoat", and Trump is
             | not going to negotiate anything here, that's ridiculous.
             | 
             | What leverage do you have for the DOGE boys? What power?
             | Resigning? Because on the Defense side of the government
             | the best leverage that some teams have found is mass
             | resignation, meaning that nothing happens.
             | 
             | There is no negotiating with bullies, it merely breeds more
             | concessions.
        
               | mmooss wrote:
               | > DOGE is doing this, it's not a "scapegoat", and Trump
               | is not going to negotiate anything here, that's
               | ridiculous.
               | 
               | DOGE follows Trump's direction and acts on his behalf, as
               | you must know. They make a big deal out of DOGE so
               | Trump's name is less attached to these actions. Then they
               | can take much of the blame with them when they go away,
               | with Trump and the GOP blaming them for 'excesses'.
               | 
               | > Trump is not going to negotiate anything here, that's
               | ridiculous.
               | 
               | > What leverage do you have for the DOGE boys?
               | 
               | You don't understand how negotiations work. Everyone has
               | interests, strengths and weaknesses, and power. You need
               | to make it in Trump's interest to keep the CVE program.
               | 
               | Everyone saying they are helpless, and that anything else
               | is ridiculous, are panicking. Very unfortunately -
               | dangerously - many people legitimize the panic. It's so
               | normalized that it's "ridiculous" not to panic.
               | 
               | Every day you continue this behavior, you fall further
               | and further behind and lead others in that direction.
               | Will you wake up in time?
        
               | djur wrote:
               | I don't think there's any reason to believe that Trump is
               | mentally competent to understand what's happening here or
               | engage in any kind of meaningful negotiation.
        
               | figgis wrote:
               | Currently the "discussion of leverage" you are talking
               | about is out of the hands of the leaders who run these
               | programs.
               | 
               | The amount of disrespect you have shown for someone that
               | is just telling you 99% of federal workers have
               | absolutely no leverage says a lot.
        
               | stavros wrote:
               | Isn't the US supposed to be the birthplace of modern
               | democracy? When did you guys forget about protests and
               | rallies?
        
               | SpicyLemonZest wrote:
               | It's just not practical to organize a rally to save a
               | niche cybersecurity program. People are busy protesting
               | to protect Medicaid and keep themselves out of foreign
               | gulags, they can't divert the attention to CVE.
        
               | stavros wrote:
               | That's fine, protests aren't surgical tools anyway. As
               | long as people are protesting, it's OK.
        
               | nosianu wrote:
               | > _Isn 't the US supposed to be the birthplace of modern
               | democracy?_
               | 
               | I would not dare not mention the revolutions in England
               | and in France. And before that some Greece city states,
               | and definitely Rome. The US declaration of independence
               | is just another point.
        
               | throitallaway wrote:
               | > You need to make it in Trump's interest to keep the CVE
               | program.
               | 
               | This guy is ~80 years old and bragged about "person,
               | woman, man, camera, TV." He recently got into a Tesler
               | and exclaimed "everything's computer!" Have you seen the
               | way his aids explain executive orders to him (like a
               | child) before he signs them?
               | 
               | He doesn't have the foggiest notion of comprehension of
               | what the CVE program is, or how it would benefit him.
               | Unless you're greasing his wheels, it's not going to
               | happen.
        
               | 1oooqooq wrote:
               | he sure understand two things.
               | 
               | one it costs the us and is needed by everyone, so he
               | thinks but paying it someone will pick it up and then the
               | us will be the free loader.
               | 
               | second, he understands that helps he and his pals wash
               | dirty money.
        
               | markhahn wrote:
               | I'm curious by what means you think Trump can be
               | bargained with.
               | 
               | Do you mean things like handsfull of like-minded
               | countries selling t-bonds? No one in the R party has any
               | leverage, and it's not clear that even a few US
               | billionaires could exert any influence.
               | 
               | Do you really think Trump has ever heard of "CVE" or
               | could comprehend them?
        
             | chris_wot wrote:
             | No, it's definitely DOGE doing all of this. Each one of
             | these young fools need to be named and shamed. The level of
             | damage they have done is unprecedented. They will, in their
             | later years, hopefully look back at this time in their life
             | with a great deal of shame and embarrassment.
        
               | Wololooo wrote:
               | I have the feeling that there will be no redemption arc
               | for those ones and the repenting would be for show before
               | a court of public opinion.
               | 
               | I'm going to be to the point here, if you guys over there
               | don't start to heavily push and organise, and I said it
               | already, you're one Reichstag fire away from something
               | very bad, and from my point of view, there is probably
               | one kristallnacht pending in the mix.
               | 
               | This is not a hyperbole and if someone wonders why this
               | has relevance to the discussions, in this case most of
               | the people around here are blue team, and it does feel
               | like the red team has already taken anything that wasn't
               | attached and now taking the time to take what's bolted
               | on...
               | 
               | I guess the silver lining of all this, is in their
               | hubris, they forgot the bread and games motto, so they're
               | might still be a chance to turn things around somewhat...
               | But the window is closing at an impressive speed.
        
               | chris_wot wrote:
               | I'm an Australian. We have a guy called Clive Palmer, who
               | has formed a party called (no joke) the "Trumpet of
               | Patriots". It's certain nobody will vote for him. The
               | opposition leader married himself to MAGA (and close to
               | Trump) and now it appears like this will prevent him from
               | winning.
               | 
               | The rest of the world is mostly against Trump.
        
               | throwawaygmbno wrote:
               | It needs to be the "shame and embarrassment" Nazis felt
               | at the end of WWII and not the traditional shame and
               | embarrassment they are used to feeling after losing the
               | civil war and Jim Crow laws. It will just happen again in
               | a generation otherwise.
        
               | watwut wrote:
               | Nazi did not felt shame and embarrassment. They felt
               | loss. They felt to be weak. Nazi and Germans felt sorry
               | for themselves after the WWII. The feeling of sorry for
               | stuff they have done to others is something Germany found
               | a bit later, largely due to Nuremberg and general
               | policies not allowing it to stay hidden.
               | 
               | Forget about them feeling sorry for anyone but
               | themselves. They will feel resentful and as if they were
               | being treated unfairly even when actual clear criminal
               | investigation happens.
        
             | watwut wrote:
             | No, blaming "someone inside DHS" is what makes no sense. It
             | 100% makes sense to blame DOGE and actual perpetrators. You
             | can stop them only if you start to blame those who do the
             | stuff you dont like instead of blaming everyone else except
             | them.
        
         | tgsovlerkhgsel wrote:
         | If you made this careful analysis, you'd hear "CRISSAKE WE NEED
         | THIS DONT TOUCH IT" for almost everything (and it likely would
         | be right for a significant portion but not everything).
         | 
         | That's why the current approach seems to be to axe everything,
         | listen to how much screaming there is, then reinstate only the
         | projects where the screaming is _really_ loud.
        
           | delusional wrote:
           | You forget that their stated policy (and I don't doubt their
           | commitment) is that whoever complains the loudest were
           | probably scamming. That "honest people don't complain"
        
           | conception wrote:
           | So the dumbest way to do anything. Got it.
        
             | phtrivier wrote:
             | Please read Isaacson biography of Musk.
             | 
             | The "Musk algorithm" is described in detail, and can be
             | summed up as a "reverse Chesterton's fence"
             | 
             | "If you are not forced to reinstitute 10% of the rules you
             | slashed, you have not slashed enough".
             | 
             | What happens while the 10% are slashed is left as an
             | exercise to the voter.
             | 
             | Hopefully, the cve db will be deemed part of the 10%.
        
         | overfeed wrote:
         | > "kill it, we don't need this"
         | 
         | "We are paying MITRE how much? Bigballs and co will write a
         | better ststem in 1 week and have it integrated with xAI. How
         | hard could it be? Send out a first draft of an xAI contract to
         | our DHS contact"
        
         | IOT_Apprentice wrote:
         | They were at the mercy of 20 year olds from doge. I wonder when
         | doge enters the NSA & NRO WHAT information will they steal &
         | put in their hard drives.
         | 
         | All of this is criminal behavior on the the current regime.
        
         | eadmund wrote:
         | > I wonder what level of compartmentalisation inside DHS means
         | they didn't see this as having sufficient downsides?
         | 
         | The National Vulnerability Database has been unable to keep up
         | with the flow of CVEs for over a year now:
         | 
         | - https://anchore.com/blog/national-vulnerability-database-
         | opa...
         | 
         | - https://www.cyberreport.io/news/cve-backlog-update-the-
         | nvd-s...
         | 
         | - https://www.ibm.com/think/insights/cve-backlog-update-nvd-
         | st...
         | 
         | - and many, many, _many_ others
         | 
         | It has been a complete disaster for months. At this point,
         | perhaps the thinking is to radically change approaches?
        
           | gtirloni wrote:
           | You assume there's a plan. Interesting.
        
           | rco8786 wrote:
           | > perhaps the thinking is to radically change approaches?
           | 
           | If there had been a replacement or reform plan for even one
           | single iota of the things this admin has cut, I might give
           | them the benefit of the doubt. But there's not. It's just
           | kill, kill, kill.
        
           | metabagel wrote:
           | Cutting the program would seem to go in the opposite
           | direction of what is needed.
        
         | rco8786 wrote:
         | > I wonder what level of compartmentalisation inside DHS means
         | they didn't see this as having sufficient downsides?
         | 
         | Come on, are you living under a rock right now? There are
         | massive indiscriminate funding cuts to anything that Elon/Doge
         | deems to be "fraud", and they explicitly do not care about the
         | collateral damage.
         | 
         | This is not about the DHS or "compartmentalization". This is
         | just a politician running amok and having real consequences.
        
           | martin8412 wrote:
           | Also there has been funding cuts to all agencies where Musk
           | is currently under investigation. NHTSA is getting cut so
           | they can't get in the way of Tesla.
        
         | paulmendoza wrote:
         | No one analyzed it most likely. It's possible on of the college
         | students working for Doge doesn't understand security because
         | they are a child with no real world experience that Elon
         | brought in to slash costs.
        
       | yawnxyz wrote:
       | I guess their new business model is to sell zero days to the
       | highest bidder
        
         | alephnerd wrote:
         | The private sector zero day market collapsed last year with
         | Zerodium - corporate bug bounties, nation states in-housing
         | offensive security operations, and the democratization of
         | knowhow destroyed the Zero Day market.
        
       | nkassis wrote:
       | My tinfoil hat says they want to privatize this through one of
       | the administrations friends. A disastrous decision here.
        
         | 9283409232 wrote:
         | Palantir is about to get a contract.
        
           | goku12 wrote:
           | I thought that the point of the CVE database is to improve
           | security, not wreck it?
        
             | jacobsenscott wrote:
             | s/is/was/
        
           | aprilthird2021 wrote:
           | Or worse, NSO Group
        
         | epistasis wrote:
         | Why would they spend money to replace it? The idea is to weaken
         | and destroy the US and its institutions. Giving Palantir money
         | might mean that security improves, and that goes against their
         | goals. They have already demanded that Russia stop being
         | treated as a cybersecurity threat in other areas of the
         | government, this is a way to ensure that systems are vulnerable
         | to attack.
        
           | throitallaway wrote:
           | Exactly. The Trump admin is well on its way tanking the USD
           | with tariffs and getting every country (including the
           | penguins) mad at us. The rationalization given by the admin
           | for tariffs (trade imbalance) make zero sense, and they
           | haven't offered anything else.
        
           | phatfish wrote:
           | These sort of government services are always under attack by
           | private organizations. The US Gov doesn't have to give
           | Palantir or whoever a contract, they just cede the ground,
           | give the right people a heads up, and then make the new
           | subscription service a "recommended service provider" as a
           | solid to whichever of Elon's circle gets the nod.
           | 
           | In the UK the some "entrepreneur" was after monetizing access
           | to the Land Registry a couple of years ago. Apparently the
           | free UK Gov service was not fit for purpose it needed a
           | paywall to make it better. Nothing as globally significant as
           | the CVE database, but you can see if the vultures are going
           | after small UK Gov services, something like the CVE database
           | is absolutely a chance to add to the executive bonus pool.
        
       | markhahn wrote:
       | Trump stupidity hurts the country and world.
       | 
       | But maybe this is an opportunity to do CVE better.
        
         | cantrecallmypwd wrote:
         | > But maybe this is an opportunity to do CVE better.
         | 
         | Okay, how? This sounds like looking for lemonade in a genocide.
        
           | robertlagrant wrote:
           | > This sounds like looking for lemonade in a genocide.
           | 
           | It really doesn't. This level of catastrophising has no
           | point. It would be nice if CVE continued to exist, but it
           | wasn't close to perfect, and perhaps it can continue in
           | another form. There's no particular reason the US taxpayer
           | has to sponsor global security threat tracking any more than
           | any other taxpayer or customer.
        
             | cantrecallmypwd wrote:
             | This is also a myopic argument against funding standards
             | bodies that support the internet.
             | 
             | The point of having a global, shared database is a single,
             | authoritative (more-or-less), semi-vetted repository that
             | can hold vendor accountable externally without digital
             | amnesia or downplaying issues, and global unique
             | identifiers. If that takes an international nonprofit
             | funded by bits of the free world who are okay with
             | investing in commonwealth infrastructure, so be it. Those
             | who don't understand what they're destroying so casually
             | are ignorant, and possibly evil if they do understand.
        
               | robertlagrant wrote:
               | > This is also a myopic argument against funding
               | standards bodies that support the internet.
               | 
               | No, it's the opposite. Things like this shouldn't be in
               | the hands of a single government. They should be
               | independent and funded by many parties. The part of your
               | message that isn't catastrophisation is agreeing with
               | exactly what I'm saying.
        
       | bathtub365 wrote:
       | Now the NSA can hoard more 0days and the general public suffers.
       | Win win for this administration
        
         | goku12 wrote:
         | It's more likely to boost the zero day black market. I don't
         | know if I want to attribute this to idiocy (indiscriminate cost
         | cutting), greed (contracts for their crony pals) or malice
         | (hoarding and trading 0 days).
        
           | gryfft wrote:
           | ?Por que no los tres?
        
       | outside1234 wrote:
       | These four years are going to be the death of all of us.
        
         | cantrecallmypwd wrote:
         | War with China and doing enough reprehensible acts to stoke
         | protests to declare martial law to stay in power indefinitely.
        
           | throitallaway wrote:
           | I feel like we're only a few weeks away from someone "home
           | grown" experiencing an "administrative error." The slide into
           | madness continues.
        
             | gryfft wrote:
             | More like only a few days away, honestly.
        
           | wiseowise wrote:
           | Wait until they start a war against Albania.
        
         | Latty wrote:
         | I find it a little incredible people are still talking about
         | "four years".
         | 
         | They tried to reject the election result and do a coup, and
         | were rewarded for it by getting back into power. They are
         | refusing to follow the law or the courts. They are sending
         | people to gulags in foreign countries. All the checks and
         | balances were destroyed last time. The party has been stripped
         | of anyone who would fight the admin or reject this illegality.
         | They have set up a power grab over elections.
         | 
         | There will not be free and fair elections in four years unless
         | they are simply too incompetent to rig it, the rubicon was
         | crossed _long_ ago. Without mass protest that makes it
         | impossible for them to hold power, American democracy is dead.
         | 
         | They have tried to do it, they say they want to do it, they
         | have the ability to do it, they are actively doing it, and no
         | one is stopping them. How are people still acting like in four
         | years they are going to neatly hand over power to be prosecuted
         | for their crimes?
        
           | SpicyLemonZest wrote:
           | Organizing mass protests isn't something you do _instead of_
           | organizing electoral opposition. Even in countries that haven
           | 't had fair elections for a while, people generally still
           | organize opposition and talk about how they're going to vote.
           | The best way to ensure your opponents retain power is to go
           | around telling people it's too late and they've already won.
        
             | Latty wrote:
             | I'm not saying people should not organise to vote, I'm
             | objecting to the framing of "in four years this will be
             | over" or "in four years we can fight this", if you are
             | waiting for elections to solve this alone, that's a
             | mistake. Elections _alone_ won 't be enough. It's not too
             | late to do anything, it is too late for _just_ voting
             | against it to be enough.
        
           | phtrivier wrote:
           | I understand you have elections in two years, don't you ? I
           | don't know if a complete reversal congress is possible.
           | 
           | That would be a good litmus test. "They" have not prevented
           | special elections so far ; if "They" need to prevent the next
           | one, whatever they try will happen then, I suppose ?
        
             | Latty wrote:
             | I'm British, but I think to expect free and fair election
             | in the US in two years is to stick your head in the sand.
             | 
             | I don't see them _preventing_ elections, but just rejecting
             | or altering results that don 't support them: the litmus
             | test is already triggered: the special election in North
             | Carolina has an ongoing court case trying to throw out
             | ballots to allow the Republican to win.
             | 
             | They have also pushed a executive order claiming sweeping
             | powers over elections which they will use as pretext to do
             | this nationally. Blatantly illegal, but they have already
             | shown they are ignoring the courts, so who will hold them
             | to account? Mass civil unrest is the only thing left.
        
       | atomicbeanie wrote:
       | The white house prefers chaos. This will certainly be a step in
       | that direction.
        
       | yieldcrv wrote:
       | if only there were 188 other countries and an entire private
       | sector in each one that could fund this thing they are also
       | affected by
        
       | xyst wrote:
       | Some companies are already clueless when it comes to CVE
       | management. Probably won't see the effects immediately but give
       | it a few more years for new generation of vulns to be
       | created/found and we will be back to early 2000s level security.
       | 
       | Open season on American corporations for domestic and foreign
       | hackers.
       | 
       | If program isn't brought back then CVE database likely to be
       | fragmented amongst the "private" CVE databases.
       | 
       | Sec Corp A has 700 well documented CVEs but Sec Corp B has 702
       | CVEs in their database since NIST funding pulled. What do corps
       | do? Maybe some of them with massive budgets setup contracts with
       | both to get "full spectrum coverage". Maybe other non-technical
       | companies that think of IT as strictly a cost will go with the
       | cheapest or forego it all together.
       | 
       | Who knows maybe we get ~~~free labor~~~ open source community to
       | pick up the slack?
       | 
       | This country with the orange man administration is quickly going
       | to shit. Not in a "I dislike {opposing party} way" either. In a
       | "I dislike authoritarian regimes" way.
        
       | mmooss wrote:
       | > In a stunning development
       | 
       | Who is still stunned by these things? They want you to be
       | stunned; they want you to tell everyone else that you're stunned
       | to spread feelings of terror and powerlessness. If you actually
       | are stunned, you are stunningly ignorant. If you are not and
       | still saying it, perhaps to emphasize your unhappiness, you are a
       | 'useful idiot'. Either way, if you are saying it, you are a
       | useful idiot.
       | 
       | You should have known decades ago: The GOP impeached a President
       | for lying about sex; they fabricated intelligence to invade
       | another country (killing thousands of Americans and 100,000+
       | Iraqis) - and that was all before 2004. They've voted almost
       | unanimously, multiple times, to bankrupt the country (by refusing
       | to authorize debt for existing obligations). Nobody (i.e., the
       | Dems failed to) stopped them or made them pay a price, so why
       | wouldn't they keep doing those things. (Edit: And if you object
       | because the analysis criticizes one side and therefore you reject
       | it as partisan, that's a big part of the reason nothing was
       | done.)
       | 
       | This time they published Project 2025, telling you what they were
       | going to do.
        
         | mcintyre1994 wrote:
         | Project 2025 literally calls for dismantling the DHS. Seems
         | pretty unsurprising that the CVE database wouldn't be in the
         | list of things they'd care to maintain in that process.
        
       | arghandugh wrote:
       | This industry relentlessly lionized Trump and Musk, elevating
       | them to positions of power and handing them the power to destroy
       | at will.
       | 
       | This is your moment! Enjoy it!
        
         | Gigachad wrote:
         | It's astounding that the users here watched all the horrendous
         | things going on and ignored them. But now the CVE numbers are
         | gone it's shocking and too far.
        
           | throitallaway wrote:
           | Come again? This is Hacker News, a heavily moderated forum
           | with a narrow focus. We don't discuss Israel or El Salvador
           | here (unless it's tech related.)
        
             | gortok wrote:
             | I would hope the folks that frequent HN would not be so
             | insular as to only read what happens on HN and not read any
             | other news source.
             | 
             | If you've somehow missed Trump's systematic dismantling of
             | academic freedom or his disappearing of folks he doesn't
             | like, then we have a far bigger problem than the limits of
             | what is discussed on HN.
        
           | flanked-evergl wrote:
           | Please, this place has permeated with Trump rage since before
           | he took office. The only way you could think he was ignored
           | is to not have read any comments.
        
           | pseudalopex wrote:
           | > It's astounding that the users here watched all the
           | horrendous things going on and ignored them.
           | 
           | Many most voted and most commented submissions were the other
           | things.
        
       | Ferret7446 wrote:
       | I don't see why this should be publicly funded, so I don't really
       | see an issue with this. The industry benefits from having a CVE
       | database, so the industry should fund it.
        
         | klysm wrote:
         | There are going to be all kinds of messed up incentives if this
         | is funded from industry.
        
           | throitallaway wrote:
           | True, although Google's Project Zero seems to be run pretty
           | well.
        
             | worthless-trash wrote:
             | Different goals, not cve related.
        
           | Ferret7446 wrote:
           | Like what?
        
         | guhidalg wrote:
         | No, "the industry" is all of us alive in the 21st century who
         | depend on software to make material decisions and to be
         | resilient to attacks and tampering. We were all funding it, and
         | now surely we will see some big tech company now assume
         | responsibility from the federal government (please god don't
         | let it be Oracle...)
        
           | skirge wrote:
           | so "all" should pay, not only US taxpayers.
        
             | guhidalg wrote:
             | That would be an improvement. Perhaps the UN should fund
             | it.
        
         | kristjansson wrote:
         | Because secure systems benefit the public generally, not just
         | the corporations that make a profit operating those systems.
        
         | maronato wrote:
         | The industry won't want to fund it. It'll want to profit from
         | it.
        
         | insane_dreamer wrote:
         | So you trust industry now?
        
           | sMarsIntruder wrote:
           | Same question would be for government funded agencies.
        
             | insane_dreamer wrote:
             | No, because the gov funded agencies don't have a personal
             | stake in the outcome.
             | 
             | That's why industry regulating itself doesn't work, and why
             | government regulations exist.
        
         | Xelynega wrote:
         | Don't open source developers and users of their software also
         | benefit from the CVE database?
         | 
         | If it were privately funded, what incentive would these private
         | companies have to track bugs for these open source projects
         | that don't make money?
        
         | sMarsIntruder wrote:
         | The insane number of downvotes you're getting for saying basic
         | common sense stuff, it's why we should push for stricter
         | political rules here in HN.
         | 
         | You didn't say something wrong or controversial, just an
         | opinion. Some ideologies love to pay things with other people's
         | wallets, and they'll do whatever they can to pursue this.
        
           | sMarsIntruder wrote:
           | Especially the L guy who downvoted this after 10 seconds. get
           | a life
        
       | the_doctah wrote:
       | Why is the government responsible for CVEs again?
        
         | throitallaway wrote:
         | Every now and then the government decides to fund things.
         | Public schools, roads, police, firemen, GPS, NOAA,
         | cybersecurity, government cheese, etc.
        
         | sschueller wrote:
         | "the government" aka "We the people". It is in all our
         | interest. This is like asking why the government is responsible
         | for roads.
        
           | dingaling wrote:
           | > This is like asking why the government is responsible for
           | roads.
           | 
           | Thought experiment:
           | 
           | If roads were built by private companies, could a Government
           | justify the expense maintaining a database of all the
           | potholes?
        
             | Xelynega wrote:
             | Yes, as it would be a public good to everyone to be able to
             | know where the potholes(that aren't profitable to fix for
             | these private companies apparently) are so they can avoid
             | them.
             | 
             | They might take a step back and realize that it would be
             | more cost-effective to just own the roads, in which case
             | your thought experiment ends where we are, because where we
             | are was a place reasoned to(to an extent).
        
             | pseudalopex wrote:
             | Pot holes do not enable fraud, ransom schemes, data
             | breaches, denial of essential services to millions of
             | people, and so on.
        
             | goku12 wrote:
             | Doesn't the government use those software (private and open
             | source) to handle private information of citizens and other
             | sensitive information? And what about their contractors?
             | That alone justifies maintaining such a database.
        
         | jowea wrote:
         | National (technological) security?
        
       | wichitawch wrote:
       | I'm surprised that it was USA's responsibility to fund this in
       | the first place. Why weren't other countries providing funds?
        
         | defrost wrote:
         | It's a near certitude that Russia and China each have databases
         | of exploitable software errors and prize zero days.
         | 
         | It was to the advantage of the US and allies to coordinate and
         | lead in tracking and fixing such errors.
         | 
         | Multiple countries, companies, and individuals contributed
         | finding and fixing bugs.
         | 
         | The administrative task of keeping track was one part of a
         | greater picture, a part that came with first to be advised and
         | other perks.
         | 
         | It's not that the US had a _responsibility_ to take on the lead
         | admin task, more that in past times the US saw an advantage to
         | being at the centre of global action.
         | 
         | This is just another part of increasing US isolationism.
        
           | wichitawch wrote:
           | > It was to the advantage of the US and allies to coordinate
           | and lead in tracking and fixing such errors.
           | 
           | From what I understand of the article, none of these allies
           | were funding it.
           | 
           | > Multiple countries, companies, and individuals contributed
           | finding and fixing bugs.
           | 
           | Clearly that itself isn't enough. Someone has to pay for
           | maintaining this service. It appears that no one other than
           | USA spent money in funding it.
        
             | epistasis wrote:
             | Why would other companies pay for it if they had never been
             | asked?
             | 
             | Why would it be shut down without asking for others to fund
             | it, if it's some sort of burden on the US?
             | 
             | Programs like this pay for themselves many times over.
             | There are only two reasons for cutting this: absolute
             | idiocy, or active sabotage of the US.
        
             | lyu07282 wrote:
             | Almost every other western country does fund their own
             | databases, CVE was just significant because its the one
             | central source of truth. its like a standard. Instead of
             | having to coordinate with dozens of different registries
             | every time you publish a vulnerability you just communicate
             | with one instead.
             | 
             | Researchers also don't directly talk with MITRE they go
             | through one of the intermediaries that assigns the number.
        
         | insane_dreamer wrote:
         | It's called providing leadership. Worth the money. China will
         | happily fill the void.
        
           | bamboozled wrote:
           | I hate this whole disaster but why can't Europe step in for
           | stuff like this?
        
             | Peanuts99 wrote:
             | Because they have their own programs for this already.
        
         | lars_francke wrote:
         | The CVE program was started over 25 years ago. It is very
         | reputable (until yesterday) and it was very much in the
         | interest of the US to be seen as the stewards of this.
         | 
         | The funding requirements can't be that high and I'm willing to
         | bet that other countries and entities would have happily
         | stepped up if they had the chance.
         | 
         | Up until recently CVE was very centralized and only in the last
         | few years have there been steps in more decentralization with
         | CNAs taking more responsibility, Red Hat as a CNA of last-
         | resort etc. So, the cost of doing all of this work has already
         | been shifted partially (!) away from the US but I have not seen
         | any movement towards e.g. moving the program to a foundation
         | which could have been done.
         | 
         | Personally I would conclude that it was the responsibility of
         | the US to pay for this because they wanted to and it was in
         | their best interest to control this program.
        
           | flanked-evergl wrote:
           | They have the chance to step up now. Every Comercial company
           | that is supposedly so reliant on this for their very
           | existence has the opportunity today. They can fund it.
        
             | lars_francke wrote:
             | I mention this in another comment. The infrastructure for
             | an alternative is already partially in place.
             | 
             | In my opinion it's mostly the industry needing to adapt to
             | a new setup that needs to happen. It was just "easy" to
             | rely on what's already there. A lot of company policies
             | need to be adapted etc.
        
             | epistasis wrote:
             | What commercial company is going to "fund" this? It's such
             | a strange idea, disconnected from the real world. You may
             | as well say "companies can start doing road maintenance, as
             | they are so reliant on them for their very existence."
             | 
             | And perhaps if there had been more than a days notice, some
             | consortium could be pulled together, but who's going to
             | pay? Why would private companies do this, how do they
             | profit? CVE program was the roads that everybody could
             | drive on.
             | 
             | The basic lack of understanding of how the world works is
             | killing the US. Why do people think we have such a massive
             | GDP? Where do people think that comes from? We've given
             | control of everything in society over to our dumbest and
             | greediest members that have no clue about how anything
             | works.
        
               | flanked-evergl wrote:
               | Ask the person I was responding to:
               | 
               | > I'm willing to bet that other countries and entities
               | would have happily stepped up if they had the chance.
        
               | drstewart wrote:
               | >but who's going to pay?
               | 
               | The EU. They can have all the massive advantages that
               | funding MITRE will give them. Why won't they step up to
               | the plate? It's killing the EU and they have absolutely
               | no idea how anything works. It's why they're a dying
               | empire.
        
               | flanked-evergl wrote:
               | I will bet money that removing the cap from a bottle will
               | be a hate crime in Europe before they start funding a
               | institution like MITRE that actually functions.
        
         | happosai wrote:
         | Because USA was a superpower that can afford it easily. Taking
         | the leadership in everything is quite cheap price to pay when
         | the other end of the bargain is everyone else has to follow
         | you.
         | 
         | Now of course USA is ceasing (voluntarily, by stripping down
         | every international soft power effector in government) to be a
         | superpower, to the great glee of dictators all around the
         | world.
         | 
         | The "we can't afford being great" is a direct admission that
         | USA is no longer a superpower. And is not going to become great
         | again, just another nation again (at whims of China).
        
           | lyu07282 wrote:
           | The nazis don't think that though, uh I mean conservatives.
           | After they've burned down everything, they expect still to be
           | a superpower somehow. Do they think they can just start a war
           | with everyone who doesn't play ball? It's hard to comprehend
           | what their rational is, if there is one.
        
         | aabhay wrote:
         | I'm surprised that the world's greatest universities are in the
         | United States. Why weren't other countries providing funds?
        
           | toyg wrote:
           | Don't worry, that will also end soon. Regimes that require
           | political subservience from universities, like the current US
           | administration, inevitably result in poor research
           | capabilities in the long run.
        
         | tdb7893 wrote:
         | The US has made at least hundreds of billions of dollars from
         | it's tech companies and has had a dominance over global tech
         | for a long time. The tech industry has brought a crazy amount
         | of money and power to the US so it makes sense the US puts
         | extra effort to support it.
         | 
         | The US isn't supporting it out of charity, it's good for US
         | businesses to have someone coordinating this for everyone. Why
         | would we want to rely on other countries to be supporting our
         | tech sector? At least now we are subject to only the capricious
         | whims of our own government, as little comfort as that is right
         | now (if another country was funding it we would be relying on
         | the whims of a foreign government, which isn't ideal when tech
         | is the golden goose of your modern economy).
        
         | jeroenhd wrote:
         | It's a program the US government spun up to serve America's
         | interests. Why would someone else pay for American interests?
         | 
         | Other countries have their own programs, some cooperating with
         | the US, others separate. China has the CNNVD if you're
         | interested in helping Chinese society safe. My government
         | operates https://advisories.ncsc.nl/advisories to serve my
         | country's interests.
         | 
         | Of course, the US is free to abandon their programme and rely
         | on Chinese, Russian, and European vulnerability databases to
         | keep their country safe. It does save them a couple of million
         | after all!
        
         | phtrivier wrote:
         | Because, contrary to popular views, there is no "government of
         | the world".
         | 
         | So, since the US government needed that (it provides security
         | to US businesses), they organised and funded it (as everything
         | else, with US taxpayers money, and savings from investors in US
         | and abroad.)
         | 
         | Now, the US government decided to commit temporary-seppuku, so
         | a number of things will happen:
         | 
         | * state-level government will use their local-taxpayer money to
         | fund similar efforts (with duplication of effort), or share it
         | with everyone
         | 
         | * another country or block of country will do it, and decide
         | whether they want to "share". (I suppose Russia and China have
         | more of an incentive to keep their CVE DB private, given their
         | level of dis-integration with US economy ? EU maybe ?)
         | 
         | * an international, ad-hoc organisation is created to share the
         | funding (something like NATO.) Multi-latteralism is not exactly
         | in fashion this days, but if EU does it, it will be
         | "international" by design since we're not really a federation ;
         | so, states in "Southern Canada" are welcome to join.
         | 
         | * or none of that happens, the CVE db rots for a while, until a
         | sufficiently embarrassing cybersecurity problem occurs, and the
         | CVE db is deemed worthy of the "10% you need to bring back" by
         | President Elon.
         | 
         | Pray your company, families and friends are never on the wrong
         | side of the "reverse-Chersteron's fence".
        
       | rurban wrote:
       | So who will maintain it then? Either the EU or China I suppose.
       | They can easily fund it.
       | 
       | Maybe the Dutch should go ahead.
        
         | lars_francke wrote:
         | ENISA in Europe has the mandate of building a EU vulnerability
         | database for the NIS 2 directive anyway and it's coming soon...
         | 
         | And CIRCL in Luxembourg are providing vulnerability-lookup
         | which can also assign IDs but in a more decentralized way:
         | https://www.vulnerability-lookup.org/documentation/
         | 
         | VulnerableCode can help with discovery etc.
         | https://vulnerablecode.readthedocs.io/en/latest/introduction...
         | 
         | So, parts of this are already in place and I assume this will
         | be a big boost towards a new vulnerability ecosystem.
        
           | esnard wrote:
           | This sounds like good news, thanks!
           | 
           | Do we already have an ETA for the ENISA vulnerability
           | database?
        
         | jeroenhd wrote:
         | Us Dutch have https://advisories.ncsc.nl/advisories although a
         | lot of that is just analysing CVEs and their impact on society.
         | 
         | An EU solution would probably be much better. Would suck for
         | Americans, though, they'd need to get up early to meet European
         | office hours.
        
       | cbondurant wrote:
       | Am I missing something or was this literally announced with less
       | than 24 hours of warning that one of the critical components to
       | the cyber security landscape was disappearing.
       | 
       | What the fuck are you supposed to do about this. This is
       | something that should have had multiple MONTHS of warning in
       | order to allow those who depend on the CVE infrastructure to plan
       | what to do next with their security posture.
        
         | mrtesthah wrote:
         | Consider this part of the attack on the American
         | infrastructure, economy, and society. Attacks do not abide by
         | laws, official procedures, or come with warnings.
        
         | pjc50 wrote:
         | CVE-zero: the attack is coming from inside the White House.
        
       | cookiengineer wrote:
       | If there are any Europeans here, I'd love to make my
       | vulnerability database that's accumulated from all linux security
       | trackers and the CVE/NVD open source if I can manage to find some
       | folks who'd help with maintenance.
       | 
       | Currently hosting costs are unclear, but it should be doable if
       | we offer API access for like 5 bucks / month for private and 100
       | / month for corporate or similar.
       | 
       | Already did a backup of the NVD in the last couple hours,
       | currently backing up the security trackers and OVAL feeds.
       | 
       | Gonna need some sleep now, it's morning again.
       | 
       | My project criteria:
       | 
       | - hosting within the EU
       | 
       | - must have a copyleft license (AGPL)
       | 
       | - must have open source backend and frontend
       | 
       | - dataset size is around 90-148 GB (compressed vs uncompressed)
       | 
       | - ideally an e.V. for managing funds and costs, so it can survive
       | me
       | 
       | - already built my vulnerability scraper in Go, would contribute
       | it under AGPL
       | 
       | - already built all schema parsers, would contribute them also
       | under AGPL
       | 
       | - backend and frontend needs to be built
       | 
       | - would make it prerendered, so that cves can be static HTML
       | files that can be hosted on a CDN
       | 
       | - needs submission/PoC/advisory web forms and database/workflow
       | for it
       | 
       | - data is accumulated into a JSON format (sources are mixed non
       | standard formats for each security tracker. Enterprise distros
       | use odata or oval for the most parts)
       | 
       | If you are interested, write me on linkedin.com/in/cookiengineer
       | or here.
        
         | f_devd wrote:
         | Maybe something to bring up to one of these e.V.'s if it ends
         | up being difficult to get started: Codeberg.org, nlnet.nl,
         | ccc.de
        
           | tagyro wrote:
           | +1 for ccc.de
        
           | cookiengineer wrote:
           | Codeberg might be a nice cooperation partner for hosting the
           | git repositories. Gonna write them!
           | 
           | I'm also visiting the local CCC chapters here this week,
           | maybe it makes sense to have a separate e.V. where the CCC
           | chapters are beneficiaries?
        
         | weinzierl wrote:
         | Try to talk to the people from the Sovereign Tech Fund, they
         | have a history of sponsoring security relevant projects in the
         | EU.
        
           | jauco wrote:
           | And maybe the sidn fund?
        
             | decide1000 wrote:
             | Nlnet for opensource
        
               | Sander_Marechal wrote:
               | Yes, maybe reach out to Michiel Leenaars from the NLNet
               | foundation. But IIRC NLNet mostly funds shorter
               | development tracks, not ongoing upkeep/maintenance.
        
           | NekkoDroid wrote:
           | > Sovereign Tech Fund
           | 
           | It's actually been upgraded to the Sovereign Tech Agency now
        
         | greenRust wrote:
         | Great idea. I'm interested in helping. I'll dm you.
        
         | Ucalegon wrote:
         | The EU should just buy MITRE. Move it to the EU and make it a
         | EU based project.
        
           | panny wrote:
           | This would be hilarious. That would be a good thumb in the
           | eye to the current administration who complained long and
           | loud about how Obama let ICANN leave US possession. Just
           | imagine the campaign commercials in 2026,
           | 
           | >The POTUS transferred our cyber defenses to the EU
           | 
           | Ouch
        
             | rob74 wrote:
             | Well, that's kind of the point? The current administration
             | doesn't care about cyber defense, any less than it cares
             | about protecting the environment, protecting consumers,
             | having top-notch universities and research, foreign aid
             | etc. etc. Actually, it takes pride in not caring about all
             | of these things.
        
               | Ucalegon wrote:
               | Not to mention the administration aren't going to be held
               | accountable for, or actually be impacted by, the harms
               | that come for their actions.
        
               | rocqua wrote:
               | My guess is that they feel they are supplying something
               | the whole world is benefiting from, and they believe that
               | unfair. That ignores the fact that the US benefits
               | immensely from this, and that they benefit domestically
               | from providing that benefit more widely by getting a lot
               | of free contributions from the outside. But the US foots
               | the bill of those who do get payed, so its unfair...
        
               | fragmede wrote:
               | It's so unfair that I have an great job so I can treat my
               | friends to dinner all the time! I hate being rich.
        
               | imcritic wrote:
               | It's rather "I know I'm rich, but why do friends expect
               | ME to pay for dinner all the time? It's so unfair!".
        
               | clort wrote:
               | Its a bit like when you are a two-bit loser but have a
               | private island where you can do whatever you like, and
               | invite every celebrity you can find over to party every
               | weekend, then start complaining that they haven't paid
               | any of the island running costs and that they are all
               | spongers because you are the main attraction of the
               | island parties.
        
               | pyrale wrote:
               | Another analogy: my friends and I often eat at the
               | restaurant I own, and occasionally, I pick the tab. I
               | complained angrily about it, and now they want to try out
               | other restaurants or dine at home.
        
               | chillingeffect wrote:
               | And at the best restaurants! And I get to choose the
               | restaurant! And choose when we eat! And pick the
               | appetizers, drinks, entrees, and desert!
               | 
               | So instead I will allow myself to be robbed and we'll all
               | share the cost of a low-key restuarant. Or maybe let's
               | charge each other to eat together, yeah!
        
               | chillingeffect wrote:
               | This american admin doesnt seem to understand the
               | benefits of leadership. Like being de facto currency,
               | ability to operate while deep in debt, etc.
        
               | 1659447091 wrote:
               | > The current administration doesn't care about cyber
               | defense, any less than it cares about protecting the
               | environment
               | 
               | On the contrary, I would argue that they deeply care
               | about the environment. The REAL point of all those tit-
               | for-tat tariffs with China including with small
               | mail/packages are to drastically cut cargo/shipping
               | emissions. The threatening of annexation of Canada? That
               | was really to get ~70% reduction in air passenger traffic
               | BECAUSE they care about the environment. Same with
               | creating a few high profile border horror story incidents
               | against nationals from allied countries. The real point
               | of it? Reduce transoceanic air passenger loads and save
               | the environment. /s
        
               | jibal wrote:
               | You need to make that /s more prominent.
        
               | nottorp wrote:
               | HN is extremely humour challenged. I suppose the majority
               | fails to put a monetary value on it...
        
           | jonnybgood wrote:
           | MITRE is a non-profit. All the EU has to do is reach out to
           | MITRE and be willing to fund the project.
        
             | Ucalegon wrote:
             | I know that they are a 501(c)3, but they have significant
             | revenue and intellectual property, so in order to do the
             | lift and shift, there would need to be some money changing
             | hands to accomplish it. Not only that, but being owned by
             | the EU gives the ability for MITRE employees to have the
             | option to immigrate to the EU to protect against any
             | retaliation.
             | 
             | I cannot believe I am typing that second sentence, but here
             | we are.
        
               | bkor wrote:
               | > Not only that, but being owned by the EU gives the
               | ability for MITRE employees to have the option to
               | immigrate to the EU to protect against any retaliation.
               | 
               | According to which rule would "owning by the EU" result
               | in an option to immigrate? Immigration is handled on a
               | per country basis. I don't see how the EU provide such an
               | option.
        
               | labster wrote:
               | The EU can accomplish it with diplomacy. It's unknown
               | technology in America, but diplomacy and asking to work
               | together is truly powerful.
        
               | bkor wrote:
               | > The EU can accomplish it with diplomacy.
               | 
               | Agree. It'll likely happen that way. Still, dislike the
               | initial incorrect assertion.
        
               | Ucalegon wrote:
               | https://eur-lex.europa.eu/eli/dir/2009/50/oj
               | 
               | The EU has agreed upon programs in order to bring in,
               | through an immigration policy, high skilled persons from
               | non-member states. More importantly, working within the
               | member nations, as to which member nation would want
               | MITRE to be located within their borders, is not
               | something that is a hard sell given that it has economic
               | advantages for whichever state(s) onboard MITRE.
        
               | graemep wrote:
               | That still leaves decisions on who to admit to states. As
               | far as I can see its main effect is to allow people
               | admitted to one country as highly skilled to travel to
               | (not live in) other countries?
        
               | bkor wrote:
               | > The EU has agreed upon programs in order to bring in,
               | through an immigration policy, high skilled persons from
               | non-member states.
               | 
               | Where in this is the option that the EU provides an
               | option to immigrate because the EU owns something?
               | 
               | I'm very well aware of knowledge workers. It's not
               | something the EU can provide as an option. What you
               | linked to is the legal framework around how EU members
               | can provide such a thing.
        
             | Cthulhu_ wrote:
             | I think all the big companies that owe their ongoing
             | business should band together and fund it. No way an
             | organization like this should rely on just one sponsor.
        
               | 2b3a51 wrote:
               | I think that I'm in favour of pricing in externalities
               | like this.
               | 
               | What cross-industry organisations exist that could
               | coordinate?
        
             | dev_l1x_be wrote:
             | Non-profit means (in this case) payed by somebody who does
             | not have anything to say about the transaction. It would be
             | better to pay for it so that people who are interested in
             | this subject have a say.
        
           | elric wrote:
           | I don't think the EU has any interest in this. They've been
           | aware of the risk of relying on the US for software security
           | for years, but AFAIK there have been no efforts to do
           | anything about it. Maybe the current situation will kick some
           | butts into gear ...
           | 
           | Off topic: your username is very appropriate given the
           | situation.
        
             | FirmwareBurner wrote:
             | _> They've been aware of the risk of relying on the US for
             | software security for years, but AFAIK there have been no
             | efforts to do anything about it. _
             | 
             | Indeed. Just as Germany knew their economy is vulnerable to
             | Russian gas and did nothing about it, even after the 2014
             | invasion of Crimea. Just as the west knew moving their
             | entire manufacturing sector to one country would make them
             | vulnerable, but choose to ignore it because it was too
             | profitable.
             | 
             | I never _EVER_ saw politicians act proactively for the good
             | of the nation or the people, all they do is act reactively
             | after the shit hits the fan to control public opinion and
             | blame someone else to make sure they get re-elected, that
             | 's it.
             | 
             | Once you realize our rulers aren't competent at their jobs
             | or acting in the peoples' best interest, it all makes
             | sense. They're in it for the grift and to enrich their
             | monopolistic friends in the private sector, to make sure
             | line goes up in the next quarter, that's it.
             | 
             | Yes, I know there are good politicians out there who care
             | and fight for their local communities, but they never make
             | it to rule at national or international stage and actually
             | change the rotten system because the status quo doesn't
             | allow that.
        
               | concordDance wrote:
               | > I never EVER saw politicians act proactively for the
               | good of the nation or the people,
               | 
               | This is almost certainly because those cases don't make
               | the news.
        
               | FirmwareBurner wrote:
               | They do where I live, but those are drops in the bucket
               | compared to the industrial scale theft(wealth transfer)
               | the central government operates.
        
               | ameister14 wrote:
               | Well, in the United States it doesn't make the news.
        
               | exceptione wrote:
               | Yup.
               | 
               | Politicians react to the public when it stands up.
               | Otherwise it will follow other agenda's.
               | 
               | That is why it is critical to have an informed public.
               | When journalism has to compete with corporate owned Fake
               | News and Entertainment, journalism dies, and democracy
               | will follow. Then, add the spy business of Big Tech in
               | the mix, with algorithmic silo's. The people don't even
               | realize they are locked up in a jar, where they live on a
               | diet of cultural engineering.
               | 
               | Now, pause a moment and think about what happens when you
               | add AI-models to the mix. Your daughter, your neighbor
               | will be totally brain-wrecked.
        
               | FirmwareBurner wrote:
               | _> When journalism has to compete with corporate owned
               | Fake News and Entertainment, journalism dies, and
               | democracy will follow. _
               | 
               | Which journalism are you referring to? The one owned by
               | Rupert Murdoch? The Washington Post owned by Jeff Bezos?
               | MSNBC? CNN? Are they better just because they're owned by
               | different billionaires and interest groups?
               | 
               | I got news for you, the journalism you knew died a long
               | time ago.
        
               | xolox wrote:
               | American independent journalism seems to be dying
               | (unfortunately) but I think in Europe there are several
               | large news organizations reporting on things that matter
               | in a relatively independent fashion, at least a lot more
               | independent than what we see happening in the US (I'm
               | thinking of e.g. The Guardian, Le Monde, I could also
               | name a couple of Dutch news sources, but they would mean
               | nothing to 95% of the readers here).
        
               | exceptione wrote:
               | That is not news to me (see my post history). The
               | information landscape in America is segmented, and works
               | to keep the Big Picture out the frame. To quote myself:
               | - No real journalism, instead, career in media house
               | depend on commercial ownership. Narratives tailored to
               | segment, but no deep and critical analysis.
               | - "Let us talk about the tariffs today, they make zero
               | economic sense"          - "I think what he meant is..."
               | - "Of course this is not entirely correct, but..."
               | - "President Trump has said.."         - "Rubio did a
               | press conference today"              - Only drama, never
               | the Big Picture.              - Elections? According to
               | the press, those are just            - The latest polls!
               | - Repeat marketing from spin doctors at affiliated media
               | houses            - "Debate" = Reality TV, scores are
               | given on wit and emotional play
               | 
               | As an English speaker, you have one option and that is to
               | read The Guardian.
        
               | jibal wrote:
               | It's certainly because they have a belief based in
               | ideology, not fact.
        
               | sharpshadow wrote:
               | Germany had with under the best deal for gas possible
               | with Russia, I don't understand the sentiment calling it
               | a vulnerability. There is still a working pipeline
               | available and Russia stated clearly if would continue
               | delivering gas, if Germany wants to.
        
               | FirmwareBurner wrote:
               | _> I don't understand the sentiment calling it a
               | vulnerability_                 - You're Germany.       -
               | You join NATO for protection from Russia, an actor with a
               | long history of military aggression[1]       - Your
               | export economy is based on manufacturing.       - The
               | energy driving your manufacturing sector is ~60% cheap
               | gas from Russia, your military aggressive partner.
               | - Russia invades Georgia in 2008 and Ukraine in 2014 to
               | no ones surprise       - Leaders of USA and Eastern
               | Europe warn you of Russia's influence on your economy
               | - You ignore all this and build another gas pipeline from
               | Russia       - You are surprised Russia invades
               | Ukraine(again) and gas sanctions cripple your
               | manufacturing economy
               | 
               | MFW German leaders and HN commenters see no vulnerability
               | in this.
               | 
               | Someone please stop the planet, I wish to get off, my
               | sanity can't handle this level of stupidity anymore.
               | 
               | [1] https://natoassociation.ca/a-timeline-of-russian-
               | aggression/
        
               | everythingisfin wrote:
               | > Someone please stop the planet, I wish to get off, my
               | sanity can't handle this level of stupidity anymore.
               | 
               | News from an American here, on an antidepressant and
               | deathly fat from stress eating:
               | 
               | I'm worried about the eventual welfare of those
               | protesting. I'm hearing that people of color are being
               | told by their pastor to stay home rather than protest so
               | as not to risk being used as scapegoats.
               | 
               | My family and friends are divided and still dividing over
               | politics. I recently was crazily ranted to by big-
               | personality entrepreneur immigrant that told me his story
               | of how easy it was to come to the states, rags-to-riches,
               | and how they were supporter of the administration because
               | "they don't want to pay taxes for illegals". Part of the
               | half of the U.S. that supports the administration isn't
               | just brainwashed, but has a very strong, angry, and
               | desperate look, and the other part says "just wait four
               | years and it will be over", but it won't; before the
               | election, this party used gerrymandering and legal action
               | to ensure that election, then post-election replaced
               | election officials and many government officials.
               | 
               | The DOE is claiming anti-semitism and the need to have
               | viewpoint diversity to deny funding to schools that are
               | known for their open viewpoints.
               | 
               | And yet somehow I'm still surprised when they kill the
               | CVE program.
               | 
               | It's an ever-escalating circus of chaos, because our
               | administration thinks this was needed to ensure U.S.
               | interests, because those vulnerable in the U.S. were
               | manipulated by outside actors and internal power-hungry
               | politicians and zealots, and all is spun to just feed
               | into the chaotic nationalism that is trying to one-up
               | every other dictator that has ever lived.
               | 
               | To top all of this off, AI, which I use daily, will take
               | my job before I retire, and I have no backup plan.
               | 
               | Despite all of this, I have the will to live, to support
               | those whom I love (even the crazy ones), and to try to
               | make the world better. I continue to pray for direction
               | on all of this.
        
               | belter wrote:
               | Follow the money...
               | 
               | "German journalist dubbed the 'Putin connoisseur' had
               | secret book deal with Russian oligarch" -
               | https://www.icij.org/investigations/cyprus-
               | confidential/germ...
               | 
               | "Russia's best friends in Germany: AfD and BSW" -
               | https://www.dw.com/en/russias-best-friends-in-germany-
               | afd-an...
               | 
               | "12 Germans who got played by Putin" -
               | https://www.politico.eu/article/blame-germany-russia-
               | policy/
        
               | holoduke wrote:
               | The sources you mention are straight out of a propoganda
               | handbook. Not worth the read and hugely fabricated fake
               | sensational news.
        
               | belter wrote:
               | Instead of countering a single fact, you labeled the
               | whole thing. That's usually how people protect a
               | narrative, not challenge one.
        
               | ta1243 wrote:
               | Politico, ICIJ and Deutsche Welle are hardly unknown
               | fringe sources with shady backgrounds
        
               | rostigerpudel wrote:
               | Except what Russia states and what Russia does are only
               | aligned when it serves Russia. Russia stopped delivering
               | gas through NordStream 1. After that, Germany took note
               | of the danger and decided it would do better without that
               | dependency.
               | 
               | https://www.aljazeera.com/economy/2022/9/2/russias-
               | gazprom-k...
        
               | m000 wrote:
               | > Germany took note of the danger and decided it would do
               | better without that dependency.
               | 
               | So they just swapped dependencies. And it's not that the
               | new dependency will have no strings attached.
               | 
               | Diversifying while keeping russian energy in the loop, as
               | part of a risk-management strategy, would make more
               | sense. Completely cutting off russian energy just gives
               | more bargaining power to their new energy provider.
        
               | throw__away7391 wrote:
               | If we put half the effort into shoring up our
               | institutions and reinforcing our shared norms and
               | cooperative values as we are into "de-risking"
               | everything, right now, and all at once, we'd all be in a
               | much better place. Overnight we all just accepted that
               | this new transactional, mercantile, hostile mentality was
               | the way of things and the only way it can be. This is a
               | self-fulfilling fatalistic prophecy and is going to move
               | us backwards into a much worse, less prosperous world,
               | empowering the bullies and the tyrants even more.
               | 
               | Greed got us here. There's a rules based world possible
               | where Russia sells gas to Germany. Russia did not
               | transform from an free and democratic society with
               | respect for human rights and the international community
               | into an authoritarian dictatorship overnight; we turned a
               | blind eye to this when it suited our short term economic
               | needs and that is how we allow ourselves to sleepwalk
               | into the situation we are now. Had we held first to our
               | principles we'd have either had the impact the neoliberal
               | trade focused policies were supposed to eventually
               | deliver or at the very least not ended up with
               | dependencies that gave such governments leverage and
               | eventually blow up in our faces. Had we instead put human
               | rights first and foremost we would not have created and
               | empowered these monsters.
               | 
               | Same thing with Trump's reelection in the US. By all
               | rights in a functioning democracy Trump should be sitting
               | in jail right now along with the January 6th
               | insurrectionists. The Biden administration had 4 years to
               | prosecute, but felt it was not politically expedient to
               | do so. Likewise what is left of the GOP within the
               | republican caucus right now faces a similar choice
               | between short term benefits and upholding the principles
               | which nearly everyone in congress and even the Trump
               | administration has previously claimed they would uphold.
        
               | m000 wrote:
               | > Had we held first to our principles
               | 
               | *our alleged principles
               | 
               | Something can't be called a "principle" when it is only
               | selectively applied.
        
               | usrusr wrote:
               | Except that Russia did not deliver (not any meaningful
               | amount anyways), when the pipelines were still intact.
               | And yes, they pretended to be willing, firing off a
               | series of excuses sufficiently transparent to make it
               | clear between the lines that it's a demonstration of
               | power. Get your history straight: "Russia stated clearly
               | if would continue" has between zero and negative value.
        
               | nosianu wrote:
               | > _There is still a working pipeline available and Russia
               | stated clearly if would continue delivering gas, if
               | Germany wants to._
               | 
               | You conveniently leave out that _minor detail_ that it
               | was RUSSIA who stopped the gas.
               | 
               | Germany tried hard to keep it going, even making a
               | sanction-exemption or a Siemens turbine repaired in
               | Canada, which according to Russia was needed. Only that
               | when they were to receive it nothing happened, gas
               | stopped anyway.
        
               | sharpshadow wrote:
               | Nordstream 1 which had if I recall correctly one working
               | turbine left and went into inspection during which an oil
               | spill was noticed and the restart of the service was
               | postponed. Shortly after Nordstream 1 Pipeline A + B and
               | Nordstream 2 Pipeline A was been blown up. It's up to
               | debate if the oil spill which was uncovered during the
               | inspection which postponed the gas delivery was a
               | political move. The turbine, which underlies sanctions,
               | should have been still in transit during that time and
               | even if delivered useless.
               | 
               | There is still Nordstream 2 Pipeline B intact available
               | to deliver gas and it uses Russian made turbines compared
               | to Nordstream 1.
               | 
               | The whole discussion is very special to say the least if
               | you leave out that some adversary blow up the
               | infrastructure.
        
               | nosianu wrote:
               | Russia _refused_ to accept the turbine! It was in
               | Germany, and Russia blocked the delivery.
               | 
               | "Moskau blockiert offenbar Weitertransport von Nord-
               | Stream-1-Turbine" ("Moscow apparently blocks further
               | transport of Nord Stream 1 turbine") --
               | https://www.rnd.de/politik/russland-blockiert-offenbar-
               | weite...
               | 
               | I'm German, I followed those developments closely at the
               | time. Russia refused to deliver gas! The blowing up of
               | the pipes happened quite some time after that!
               | 
               | You also don't mention that German Gasprom, which
               | controlled German gas reserves, emptied them just before
               | the war! -- https://www.faz.net/aktuell/wirtschaft/gas-
               | speicher-in-deuts... (German, paywall), --
               | https://www.zeit.de/news/2022-01/21/ungewoehnlich-leere-
               | gass...
               | 
               | That shows that Russia prepared for using gas as an
               | economic weapon against Germany especially well before
               | they even started the war.
               | 
               | From the Zeit article:
               | 
               | German
               | 
               | > "Die Gasflusse uber die deutschen Grenzen sind unublich
               | niedrig fur diese Jahreszeit - mit Ausnahme von Nord
               | Stream 1, die sind konstant hoch", sagt Fabian Huneke. Es
               | sei verwunderlich, dass vor dem Hintergrund der hohen
               | Preise und der hohen Nachfrage die Gaslieferkapazitaten
               | Richtung Europa so wenig genutzt wurden. "Wenn Gazprom
               | sich marktrational verhalten wurde, wurden sie die
               | Gaslieferungen nach Europa auch durch die Pipelines, die
               | durch Belarus und die Ukraine fuhren, verstarken." Den
               | Grund fur dieses Verhalten sieht der Energiemarktexperte
               | in der Ukraine-Krise.
               | 
               | English, translated by Google
               | 
               | > "The gas flows across the German borders are unusually
               | low for this time of year - with the exception of Nord
               | Stream 1, which are consistently high," says Fabian
               | Huneke. It is surprising that, given the high prices and
               | high demand, the gas delivery capacities to Europe are so
               | little used. "If Gazprom behaved in a market-rational
               | manner, they would also increase gas supplies to Europe
               | through the pipelines that run through Belarus and
               | Ukraine." The energy market expert sees the reason for
               | this behavior in the Ukraine crisis.
        
               | thaumasiotes wrote:
               | > Moskau
               | 
               | Tangentially... how did the German name of the
               | city/region get into _that_ form? Is it a loan from
               | English?? Germany and Russia have been closely entwined
               | for centuries.
               | 
               | Wikipedia has a comment which appears to make no sense:
               | 
               | > The [old] form Moskovi has left traces in other
               | languages, including English: Moscow; German: Moskau;
               | French: Moscou; Portuguese: Moscou, Moscovo; and Spanish:
               | Moscu.
        
               | detaro wrote:
               | Seems its actually (in both German and English) developed
               | from older Russian forms, and Russian shifted afterwards
               | again: https://en.wikipedia.org/wiki/Moscow#Etymology
        
               | thaumasiotes wrote:
               | But all of the older forms include a /v/. How did that
               | drop out of every language except Portuguese?
               | 
               | (There is an English term _Muscovy_ for the region, but
               | wiktionary suggests that it derives from the formal name
               | given to the region in international Latin rather than
               | deriving from Russian. In that case, a  /w/ would also
               | generate a letter V, so there's no explanatory power.)
        
               | pyrale wrote:
               | U, v and w are all derived from the same letter v, for
               | which no distinction existed in latin (same for i, j and
               | y).
               | 
               | Apparently, when different languages started to make the
               | distinction, they picked a different letter combination:
               | ov, ou, ow, au, u, etc. probably depending on the local
               | way of pronouncing the word.
               | 
               | Same for latin ivvenis, modernized to juvenis, which gave
               | young, jeune, jung, joven, etc.
        
               | sharpshadow wrote:
               | The transport of the turbine was accompanied by sanctions
               | and each party didn't wanted to get punished, awaiting
               | exemption documents for delivery. As the article already
               | states in the headline and further acknowledges in the
               | content Russia was not refusing to get their turbine back
               | but waiting for documents themselves which the article
               | beautifully conceals with the little word 'apparently'.
               | 
               | The unusual low gas storage reserves at the beginning of
               | the year 2022 in Germany with 45% compared to usual 75%
               | while Nordstream 1 is delivering at full capacity could
               | be related to the sanctions which lead Poland to stop
               | transit through the Jamal pipeline and other transit
               | routes through Ukraine and possibly gas market trade
               | activities. Having just the 'economic weapon' argument is
               | lacking, especially in regard that Russian gas is still
               | to today reaching Germany and it is in the interest of
               | Russia to deliver.
        
               | javier2 wrote:
               | NordStream 1 had been stopped from Russian side for
               | nearly 4 months before this, with constantly shifting
               | goal post excuses.
        
               | chillingeffect wrote:
               | Perfect exmple of the "one-deep" conservative response.
               | 
               | PP is looking for a pattern, finding, and abstaining from
               | questioning or contextualizing it:
               | 
               | Engaging only with the first or most obvious layer of an
               | issue--never going deeper into context, nuance, or
               | systemic causes.
               | 
               | The quickest counterexample that comes to mind is
               | Elizabeth Warren's Consumer Financial Protection Bureau.
               | It has returned billions to American citizens.
        
               | FirmwareBurner wrote:
               | I'm gonna have to stop engaging with you here if you
               | start a comment by accusing someone to be a conservative.
               | 
               | If your first reaction is putting people into
               | political/ideological camps in order to make their
               | arguments weaker and easier to attack form a holier than
               | though political/ideological angle, it's game over for me
               | as I like to judge actions objectively based on the
               | outcomes, not conservative vs democrat, left vs right,
               | etc. since corruption and incompetence is colorblind.
               | 
               | I don't care which side of the political isle did what,
               | I'm pointing at the systemic failures of the entire
               | system built like a house of cards by all political
               | parties, which collapsed as no thought was put into
               | building it, and only chased short term profits at the
               | expense of long term security. Trying to finger point a
               | single political side only detracts from the issue which
               | is the classic "divide and conquer" tactic politicians
               | have been using to deflect blame and get away with it.
        
               | bsenftner wrote:
               | It is damningly simple, the root cause beneath far too
               | many issues our advanced civilization faces: we have a
               | global adult immaturity issue, species wide. The leaders
               | that are crony capitalist and widely populist are in
               | truth terribly immature public figures. Our incredibly
               | short sighted (also an immature behavior) news and
               | analyst media pretends to be adult while never really
               | having any solutions that are not plain school yard
               | bullying and tribe glorifying. And the public is only
               | allowed outsider fringe opportunities to include their
               | voice in these public non-debates. We do not produce
               | adults anymore, we produce a civilization of Lindsay
               | Lohans that think they are adult men and women.
        
               | dsr_ wrote:
               | If capitalism is allowed to operate without regulation,
               | it corrodes.
               | 
               | If government is allowed to operate without regulation,
               | it corrodes.
               | 
               | The pattern is clear. Unchecked power imbalances are bad
               | for everyone, but the folks at the top of a power
               | imbalance generally advocate for it, and change the
               | environment to ensure their power and reduce everyone
               | else.
        
               | bsenftner wrote:
               | What is that aspect of humanity that causes unchecked
               | power to imbalance anyone and everyone? I'm saying it is
               | unchecked immaturity. Recognition is step one. If the
               | species identifies en mass there is an unchecked
               | immaturity issue in adults, a huge amount of it will
               | evaporate, and people will be given an excuse to start
               | calling other adults on their immaturity. Harsh, but
               | necessary as the immature are actively justifying
               | destroying people all over the place.
        
               | Lendal wrote:
               | The death of Occam's razor, because protecting one
               | sensitive person's tribal political identity is more
               | important than solving the problem.
        
             | belter wrote:
             | https://www.enisa.europa.eu/topics/vulnerability-disclosure
        
             | ta1243 wrote:
             | I thought exactly the same until
             | 
             | https://euvd.enisa.europa.eu/
             | 
             | Appeared on the front page, with (c) 2005-2024 by the
             | European Union Agency for Cybersecurity.
             | 
             | This is just an example of US cultural defaultism.
        
           | belter wrote:
           | This should be work for the ENISA:
           | https://www.enisa.europa.eu/
           | 
           | https://www.enisa.europa.eu/topics/vulnerability-disclosure
           | 
           | They have a tender going on tracking best practices:
           | https://www.enisa.europa.eu/procurement/vulnerability-
           | disclo...
           | 
           | So they will take 12 months to select for the tender...18
           | months pondering on the report...and in 3 years they make a
           | tender out for a solution...
        
             | Xelbair wrote:
             | oh but you forgot the mandatory time before they even start
             | considering the tender.
             | 
             | looking at average speed of bureaucracy in EU it will take
             | roughly a year to set date for a meeting that will set the
             | date for actual meeting which will decide if this will go
             | forward or not....
             | 
             | (if you think i'm joking - i'm basing this on proposed EU
             | initiative for nuclear power which started with setting a
             | date of meeting to setup a meeting to draft an agenda)
        
               | _joel wrote:
               | 100% - I wonder if this is partly by design.
        
               | nottorp wrote:
               | I'm kind of thinking of Frank Herbert's BuSab here...
        
               | mvandermeulen wrote:
               | Sir Humphrey ran that meeting if I recall correctly
        
               | belter wrote:
               | The five stages of creative inertia:
               | https://youtu.be/PcghKtd-yP0?t=23
        
         | juicyyy wrote:
         | Im also interested in helping
        
         | JimBlackwood wrote:
         | I'm interested to help! I added you on LinkedIn, so will
         | message there after you accept. :)
        
         | anontrot wrote:
         | Try if you can find some help here https://openssf.org/
        
         | wustus wrote:
         | Depending on deployment strategy I could help with Kubernetes
         | stuff.
        
         | sneak wrote:
         | The AGPL is a nonfree (and nonsensical) license.
         | 
         | There's nothing wrong with normal GPL.
        
           | lifthrasiir wrote:
           | Is there a non-free license approved by FSF and OSI and
           | compatible with DFSG?
        
         | goodpoint wrote:
         | There are already many security trackers, why writing a new
         | one? The issue is paying people to handle the advisories.
        
           | cookiengineer wrote:
           | I agree with you there. Before CISA got sacked / taken down,
           | they were working together with the BSI and other CERT
           | agencies on a vulnerability exchange format.
           | 
           | This might be the optimum time to implement CSAF and to lead
           | by example when it comes to vulnerability disclosures.
        
         | harrisi wrote:
         | I'm not European but I'd love to help.
        
         | mwe-dfn wrote:
         | The European, GDPR compliant subnet of the Internet Computer
         | could suit your needs. The app would be decentralized out of
         | the box and it can't be shut down by a single entity like a
         | traditional cloud provider or nation state. Hosting 100GB costs
         | about 500$ per year [0]. This is not a traditional hosting
         | provider, it's a decentralized cloud. Reach out on the forum
         | [1] or to me if this sounds like a good fit to you (I think it
         | does, from your list of requirements).
         | 
         | [0] https://internetcomputer.org/docs/building-
         | apps/essentials/c... [1] https://forum.dfinity.org/
        
           | immibis wrote:
           | Or just use a normal host where hosting 100GB costs about
           | $60.00 per year.
        
             | vachina wrote:
             | My 4TiB seedbox at home costs $5 in electricity.
        
             | mwe-dfn wrote:
             | As mentioned in the response to the sibling, I am not just
             | talking about hosting the data, but also running the app.
             | Ofc, with a lot of traffic the running costs would
             | increase.
             | 
             | The reason for the higher price is that both data and
             | running software is redundant and decentralized by design -
             | no need to configure anything.
        
           | f_devd wrote:
           | Seems way overkill & unnecessary. Wouldn't the e.V.
           | (foundation) especially with FOSS backend/frontend already
           | ensure continued operation? Also if it's about
           | redudancy/resilience it seems like good ol' torrent/ipfs or
           | even a dedicated dht (if you really want to have fast updated
           | content) would be much more efficient.
        
             | mwe-dfn wrote:
             | >FOSS backend/frontend
             | 
             | That phrase does not address where and how to host data and
             | run software, and while I think an e.V. would be a great
             | idea, it also does doesn't address it. So these concerns
             | seem orthogonal to my input.
             | 
             | The IC Protocol is indeed about redundancy and resilience,
             | but also about sovereignty and security, and it does not
             | just host data (like torrents) but also runs software in a
             | verifiable way (in particular, for every message you get
             | from a dapp on the ICP, you get a certificate that proves
             | that the majority of nodes in the subnet agree on the
             | result).
             | 
             | In a nutshell, it's a platform that gives you many
             | guarantees (security, redundancy, sovereignty) out of the
             | box - as opposed to classical solutions which have to be
             | composed of many different building blocks that need to be
             | orchestrated to work together.
        
         | tecleandor wrote:
         | (Spain, doing storage and web hosting) What usually worries me
         | the most is the administrative or management part, which I
         | don't know how big would be for this project...
        
         | senda wrote:
         | messaged on linkedin fyi
        
         | lars_francke wrote:
         | Honest question: Does this not already exist?
         | 
         | - https://vulnerability.circl.lu/
         | 
         | - https://osv.dev/
         | 
         | - https://vuldb.com/
         | 
         | And a few others?
        
           | cookiengineer wrote:
           | OSV is made by Google/Alphabet and therefore also prone to
           | Trump intervention (see Gulf of Mexico executive order).
           | 
           | The circl.lu might be actually a potential cooperation
           | partner.
           | 
           | (Vuldb is down right now)
        
             | SSLy wrote:
             | you've slept just 3 hours? Go back to bed..
        
               | kiru_io wrote:
               | Maybe just a toilet break (see the bio): > Fun fact: All
               | my comments have been written on the toilet. I don't use
               | social media anywhere else.
        
               | biorach wrote:
               | https://xkcd.com/1369/
        
               | cookiengineer wrote:
               | Yep, toilet and now back to bed :D
        
               | ljm wrote:
               | Taking TDD to a level it's never been before
        
               | JCharante wrote:
               | hmm? it's already daytime in Europe where he's located
        
           | croes wrote:
           | https://www.enisa.europa.eu/news/another-step-forward-
           | toward...
        
             | belter wrote:
             | Other authorities:
             | https://www.cve.org/programorganization/cnas
             | 
             | The CVE program is really important. This Administration is
             | truly the example of the D.O.G.E. - Department Of Gaffes
             | and Errors
        
             | cookiengineer wrote:
             | > https://euvd.enisa.europa.eu/
             | 
             | They already did it. Great!
             | 
             | Maybe we can ask them how to contribute to their software,
             | as it seems to be proprietary at the moment?
             | 
             | edit: lol, their manifest.json is still the React
             | boilerplate: https://euvd.enisa.europa.eu/manifest.json
             | 
             | Their database seems to also only contain fairly recent
             | CVEs (up until 2019? some CVEs are missing...) and not
             | before that
        
               | numpad0 wrote:
               | All major powers have at least one each, some few for
               | different parts of bureaucracy. Most of them are probably
               | minimum budget operations just rsync-ing US CVD but they
               | exist.
        
               | ozim wrote:
               | We can only hope they will get enough exposure now so
               | they can get funding to fix stuff.
        
               | rickdeckard wrote:
               | To quote the article                 "Fourth, national
               | vulnerability databases like China's and Russia's, among
               | others, will largely dry up (Russia more than China)."
               | "Fourth [sic], hundreds, if not thousands, of National /
               | Regional CERTs around the world, no longer have that
               | source of free vulnerability intelligence."
               | "Fifth [sic], every company in the world that relied on
               | CVE/NVD for vulnerability intelligence is going to
               | experience swift and sharp pains to their vulnerability
               | management program."
        
             | BrandoElFollito wrote:
             | This is (without any irony) the first useful thing I see
             | from ENISA.
        
         | mitjam wrote:
         | The main costs definitely not hosting and can be quite
         | significant. MITRE had $2.37B revenue in 2023, most if it
         | contributions. I don't know how much of it can be attributed to
         | the CVE, but I assume it's not an insignificant part of it:
         | https://projects.propublica.org/nonprofits/organizations/422...
        
         | hypercube33 wrote:
         | I would email someone like Patch My PC they seem good stewards
         | of stuff open source from my vague looking and they are good
         | people. They may just host a clone of it that's open.
        
         | newsclues wrote:
         | Why EU?
         | 
         | Canada may be another friendly option
        
           | com wrote:
           | Canada's been described as the Ukraine of North America.
           | 
           | Let's not site global critical infrastructure within 150km of
           | US land borders for a generation, please.
        
             | jetster735180 wrote:
             | I don't believe I've heard that before.
             | 
             | As a Canadian, I can confirm it's nothing like what's
             | happening in Ukraine.
        
         | sberder wrote:
         | Looks like some people are already getting things moving:
         | https://www.thecvefoundation.org/
        
         | worthless-trash wrote:
         | Some cnas may also submit. Is this something you are open to?
        
         | dev_l1x_be wrote:
         | We should host it and collect membership fee from people who
         | need this data. This way we can make it resilient against lack
         | of government support. I would love to pay 5-10EUR/month to use
         | such a service.
        
       | delusional wrote:
       | Meh. It's not like I was going to ask the facist autocracy about
       | my software vulnerabilities.
        
       | nelox wrote:
       | Just what is needed with an adversary during and asymmetrical
       | trade war.
        
       | insane_dreamer wrote:
       | CVE was anti-American woke.
       | 
       | No, more seriously, just like with shutting down NOAA services,
       | it seems the goal is to:
       | 
       | 1. cut services (we saved taxpayer money!!)
       | 
       | 2. at some point later: oh, we actually need those services
       | 
       | 3. pay <insert your favorite vendor here, preferably one
       | connected to Musk> to provide the service (see! we don't need to
       | pay gov employees!!) (fine print: the vendor costs 2-3x the
       | original cost). But by then no one is looking at the spending
       | numbers anymore.
       | 
       | Slick moves.
        
         | SirHumphrey wrote:
         | And here lies the problem. Even from a libertarian perspective
         | DOGE is counterproductive because maintaining a system is much
         | more cost effective than starting it anew.
         | 
         | Especially when you cut something recklessly, figure out in
         | month that you need back that capability right now and have
         | very little leverage to negotiate with private providers.
         | 
         | When you look at the last cutting effort in the Clinton
         | administration the difference in jarring.
         | 
         | Combine that with the fact that with a few exceptions DOGE has
         | been cutting the most cost effective programs (i can't think of
         | a better bang for buck science program than NOAA) it's saved
         | very little vs the amount of pain it has caused.
        
           | darkwater wrote:
           | Heeeeey but he runs Tesla like this and it's an hyper-valued
           | company!!!1! He cannot be wrong, he is a genius!!
        
       | JackYoustra wrote:
       | There are quite a few threads on hackernews that were cautiously
       | optimistic about doge with, frankly, pretty naive libertarian
       | takes about how the government works.
       | 
       | The government is not particular (in the sense of particularism)
       | and cannot be easily tuned to fix particular problems; rather,
       | its best solutions come through institutional procedure and
       | design, such as the tension between the FAA and the NTSB that, at
       | a first glance, would seem like obviously needless duplication
       | and waste.
       | 
       | It is a broad, blunt, wasteful instrument to solve broad, blunt
       | problems in a way that may not be the best but that work far, far
       | better than alternatives that have been tried.
       | 
       | That the effort to treat government like a personal budget has
       | ended up destroying important things is a sad inevitability of
       | such efforts. I hope it goes remembered.
        
         | simpaticoder wrote:
         | _> I hope it goes remembered._
         | 
         | It won't be. Willful ignorance is a cornerstone of the
         | movement. You can't lie about what you don't know. You can't
         | have a bad take if you don't know. Upton Sinclaire said in the
         | 1930's: "It is difficult to get a man to understand something,
         | when his salary depends on his not understanding it." Now add
         | to "salary" "identity", "relationships", "sense of belonging to
         | the group". This is why critical, independent thinking,
         | speaking truth to power, must be separately honored and
         | encouraged by a healthy culture, because these attributes are
         | by default mercilessly punished. (Physical courage and heroism
         | are honored by a healthy culture for similar reasons.)
        
           | JackYoustra wrote:
           | I mostly agree, although I really disagree with 'speaking
           | truth to power' -- I feel like the outsized reverence for
           | this is exactly what got us into this mess. For YEARS,
           | there's been a culture of celebrating opposition for
           | opposition's sake, a performative stance of always
           | positioning oneself against the perceived holders of power,
           | rather than critically evaluating the actual accuracy or
           | value of what's being said.
           | 
           | Democrats are repeatedly pilloried simply because they govern
           | while the Republicans cosplay as a permanent opposition, and
           | therefore became 'the power' to speak against. Governing
           | inherently involves trade-offs, compromises, and complex
           | realities that never match ideological purity. Thus, an
           | atmosphere developed where people who engaged in governance--
           | and therefore took responsibility for difficult, real-world
           | outcomes--became easy targets for criticism that was more
           | interested in the aesthetics of "truth to power" than in
           | providing accurate analyses or constructive solutions.
           | 
           | As a result, "speaking truth to power" became a performance,
           | disconnected from accountability or genuine insight. The
           | loudest critics weren't necessarily those with the most
           | accurate or useful truths, just those who most visibly
           | positioned themselves as opposing power structures. This
           | reinforced public cynicism and undermined nuanced
           | understanding of governance and policy, further obscuring
           | genuine critique and necessary reforms.
        
       | 1970-01-01 wrote:
       | Root cause: Layer 8 failure
       | 
       | https://www.computerhope.com/jargon/l/layer8.htm
        
       | apexalpha wrote:
       | Why is this sponsored by such an American gov entity?
       | 
       | I guess it's one of those things you never think about until it
       | goes wrong.
       | 
       | The world would do well to move this kind of stuff out of the US
       | quickly, just like ICANN and stuff.
        
         | kbumsik wrote:
         | Because gov infra also relies on CVE?
        
       | porridgeraisin wrote:
       | Good. CVEs were the poster boy of goodharts law for the longest
       | time. Most security vulnerabilities behind CVEs are utterly
       | meaningless.
        
         | goku12 wrote:
         | Ah! Another one to add to the following list:
         | 
         | - What disease did the CDC ever prevent?
         | 
         | - What improvement did the NHTSA ever bring to full self
         | driving?
         | 
         | - What improvement in airline safety did the FAA bring?
         | 
         | - What good did FEMA do in any disasters?
         | 
         | I don't want to quip about how their achievements are invisible
         | because they prevented the disasters that would have brought
         | the spotlight on them, even when they were too underfunded to
         | properly do their jobs. But I sure would like to see the people
         | making these smart comments to give it a try and see how that
         | goes. Then again, I have no complaints - at this rate, we'll
         | get that chance soon.
        
       | 4ndrewl wrote:
       | To the "I wish HN would stay out of politics" crew.
       | 
       | You can stay out of politics, but politics will always come and
       | find you.
        
         | t0lo wrote:
         | Everything is political now by design. It's meant to reach into
         | every facet of society and community and restructure it.
        
           | Braxton1980 wrote:
           | Everything was always political. Laws, the economy, conflcit.
           | How is any person not affected by these? The government is
           | responsible for all or a large part of how a country
           | functions.
           | 
           | People who say "I'm not political" are deflecting to avoid
           | conflict
        
             | t0lo wrote:
             | I mean I think The Republican Incumbent was chosen
             | specifically as a tool because he is so extreme, pervasive
             | and demoralising and creeps into everything. Definitely by
             | Russia, maybe also by our "friend" in the ME. Although it's
             | not that reported on they are on friendly terms.
             | 
             | Disaffection lends itself easily to creating a Russia-style
             | society. This all feels pretty Dugin-esque, and his
             | proposition (return to values, reject interest/hope in
             | politics because it is always flawed anyway, bind together
             | under the state) fits perfectly, and is finding prominence
             | at the perfect time.
             | 
             | Just my opinion, but to me this seems far more akin to
             | Dugin than whatever Curtis Yavin is pushing
        
               | ndr42 wrote:
               | What is "ME" referring to?
        
               | NikkiA wrote:
               | "Middle East" is the usual expansion, and fits in context
               | here.
        
               | HelloNurse wrote:
               | The "friend" could be Israel or some person like Mohammed
               | bin Salman.
        
               | NikkiA wrote:
               | Given the treatment for supporters of gaza, almost
               | certainly Netting-yahoo
        
             | darkwater wrote:
             | > People who say "I'm not political" are deflecting to
             | avoid conflict
             | 
             | A great truth. Even isolating yourself from society like a
             | hermit is still a political decision: you are rejecting
             | society as it is, and prefer to live in your own solo
             | society. That's politics.
        
               | dcow wrote:
               | I don't think that's totally accurate. If I live as a
               | hermit but perform my civic duties like voting and paying
               | any taxes, I don't see how choosing to live in solitude
               | is anything more than a lifestyle choice.
        
             | perching_aix wrote:
             | When this is discussed, what's being meant is that everday
             | party politics are spilling out and overwhelming a
             | project's or industry's individual, internal politics,
             | which are often a completely disconnected meta.
             | 
             | Appealing to "well everything is connected" I'm not sure is
             | useful. It's interesting from a semantics perspective the
             | first few times you come across it maybe, then swaps around
             | into being plain frustrating, then lands on just missing
             | the point.
             | 
             | Finally, I think people who want to stay out of said party
             | political meta I think are doing a pretty big favor to
             | their mental health, and I really can't fault them one bit
             | for it. No coincidence either.
        
               | noelwelsh wrote:
               | Two things:
               | 
               | "Party politics" is ill-defined, and so a "no politics"
               | rule becomes an arbitrary hammer that bosses can use to
               | smash employees. If I say "I'm going to get a COVID
               | vaccine this afternoon" is that discussing party
               | politics? In the UK, where I live, the vaccine was
               | provided by the government, so I'm implicitly discussing
               | the actions of the government. That is under any
               | reasonable definition a discussion of politics.
               | 
               | "everyday party politics are spilling out and
               | overwhelming a project's or industry's individual,
               | internal politics" is how "no politics" rules are usually
               | justified, but this was not what happened in the poster
               | child cases of implementing "no politics" rules
               | (37signals, Coinbase). 37signals in particular tried to
               | spin it this way, but it was the actions of a group
               | within the company approved by the founders that caused
               | the problem. (Coinbase was just completely incoherent
               | from the start. Their mission is something like "End
               | economic inequality" which a reasonable person could take
               | to mean anarchist or communist discussion is on topic.)
        
               | graemep wrote:
               | The covid vaccine example is a good one in terms of
               | something in everyday life that is politicised.
               | 
               | It is also illustrates the problem with discussing
               | politics in an international forum. The KCL study of
               | covid conspiracy theories (carried out during the
               | pandemic) found that in the UK young people and those who
               | identified as left wing were more likely to believe
               | conspiracy theories. I am pretty sure this is
               | significantly different from the US. Also matches things
               | I have heard (e.g. my daughter met people at university
               | who refused the vaccine because "we don't trust the
               | Tories".
               | 
               | It is pretty common for Americans to assume that the
               | Conservatives are equivalent to Republicans, and Labour
               | are like the Democrats, which is very far from the truth.
               | It has always been far from the truth but the reasons why
               | change - e.g. in the 80s Thatcher and Reagan were not far
               | apart, but that that time Labour were far to the left of
               | the Democrats (actual socialists).
        
               | perching_aix wrote:
               | There's no way to define any modality of politics such
               | that someone like you won't come around and start going
               | off about how it's a leaky segmentation, and is actually
               | just an excuse for censorship.
               | 
               | Every artificial segmentation of the real world is leaky.
               | Just like the recognition that politics is everywhere,
               | this too is not actually inquisitive. It's like arguing
               | that stairsteps are chairs. They can be, but that doesn't
               | make the word "chair" _ill-defined_.
               | 
               | > but this was not what happened in the _poster child
               | cases_ of implementing  "no politics" rules
               | 
               | There is no such thing. These may be notable cases in
               | your cohort, for me it's the first time I heard of these.
               | And I've seen my fair share of these rules.
        
               | Braxton1980 wrote:
               | > I think are doing a pretty big favor to their mental
               | health, and
               | 
               | It your mental health is harmed while defending your
               | political views it's possible your views are the issue.
               | 
               | For example if my view was that "domestic animals
               | shouldn't be abused and penalties increased for such
               | crimes" I wouldn't have mental health issues discussing
               | this.
        
               | concordDance wrote:
               | The vast majority of people will get stressed talking to
               | people they think are evil or against their values.
               | Someone breaking down in tears because another person
               | says they "don't give a fuck about the bloody Gazans" is
               | not behaving particularly unusually.
               | 
               | The views don't matter as much as how strongly they are
               | held.
        
               | graemep wrote:
               | > Someone breaking down in tears because another person
               | says they "don't give a fuck about the bloody Gazans" is
               | not behaving particularly unusually.
               | 
               | it might be reasonable if you have personal close links
               | to Gaza (e.g. you are worried about family who live
               | there), but otherwise it OUGHT to be very unusual.
        
               | saagarjha wrote:
               | Why?
        
               | AlexandrB wrote:
               | > it might be reasonable if you have personal close links
               | to Gaza (e.g. you are worried about family who live
               | there)
               | 
               | That's _another_ problem with political discussions at
               | work - you 're often not sure _why_ someone has a
               | particular beliefs and so it 's hard to know whether
               | disagreement will be taken as an abstract difference of
               | opinion or as an attack on their family, friends, or
               | homeland.
        
               | pjc50 wrote:
               | Funnily enough, one of the UK's odder, more intense, and
               | probably mentally ill domestic terror campaigns was
               | carried out by anti-vivisectionists.
               | 
               | (https://en.wikipedia.org/wiki/Stop_Huntingdon_Animal_Cru
               | elty)
        
               | pseudalopex wrote:
               | Were they anti vivisectionists? Or animal testing
               | opponents who called animal testing vivisection?
        
               | perching_aix wrote:
               | So if I now said some intentionally asinine garbage, e.g.
               | about how dogs need to be disciplined, shown who the pack
               | leader is, and sometimes that necessarily involves a
               | beating, and how if you disagree you're woke, that
               | wouldn't make you very understandably very distraught?
               | 
               | Because it would make me pretty distraught, and I don't
               | think that it's because anything is wrong with the idea
               | of not abusing animals.
               | 
               | Even doing this mental exercise for the sake of this
               | conversation is already extremely frustrating for me. And
               | I don't think this should surprise you, or is anything
               | strange or unusual.
        
             | juliendorra wrote:
             | Alternatively people who say "I'm not political" are
             | benefiting from the status quo and political direction of
             | things (long term, not necessarily short term). They frame
             | inaction as apolitical.
        
             | InsideOutSanta wrote:
             | One of the benefits a working democracy conveys to its
             | citizens is that they largely don't have to care about
             | politics. They can trust that government action is
             | relatively consistent over time, that laws will be enforced
             | fairly enough, that their property will be protected to a
             | reasonable degree, that the currency will be reasonably
             | stable, that the roads will be maintained, that some public
             | transport will be available, that sudden wars won't erupt
             | around them, and so on.
             | 
             | That's what makes working democracies successful. But it
             | seems that it also makes democracies vulnerable because
             | people don't realize they have these benefits _because they
             | live in a working democracy._ They start to think these
             | benefits have nothing to do with politics and are just the
             | way things are, like the laws of nature.
        
               | demosito666 wrote:
               | Interestingly, I believe that the reality is exactly the
               | opposite: on the political regimes' spectrum of
               | democratic -> authoritarian -> totalitarian only the
               | middle one doesn't require people's participation. Both
               | democracy and totalitarism need to be actively maintained
               | by significant part of the population, otherwise they
               | converge to the "natural" state of things - authoritarian
               | order. None of the stuff you listed (fair laws, property
               | rights, etc.) occur naturally once it has been set up at
               | some point in past. That's why they talk about "checks
               | and balances" all the time, and they are impossible
               | without active participation.
        
               | pjc50 wrote:
               | What distinction are you making between authoritarian and
               | totalitarian here?
        
               | demosito666 wrote:
               | I think the most significant distinction is exactly that:
               | 
               | Authoritarian - leaves people alone in general as long as
               | they stay out of politics. Examples: 90% of regimes
               | throughout human history. Almost all post-soviet
               | countries, almost all of Middle East and Africa,
               | Singapore, etc.
               | 
               | Totalitarian - forces people into actively participating
               | in leader's political goals and penetrates the daily
               | life. North Korea, USSR, Nazi Germany, Fascist Italy.
        
               | Braxton1980 wrote:
               | >Authoritarian - leaves people alone in general as long
               | as they stay out of politics.
               | 
               | Directly, yes, but their policies still affect people.
               | 
               | For example, if an authoritarian leaders enacts economic
               | decisions that damage the economy everyone is affected.
               | 
               | If I pay more for goods and services due to Tariffs
               | aren't I being forced to participate in the leader's
               | political goals?
        
               | jowea wrote:
               | The distinction is fuzzy, but I think what is meant here
               | is more directly political. In a totalitarian system, it
               | is considered important for everyone to know and openly
               | and regularly support state ideology with words and
               | deeds. In the least totalitarian but authoritarian
               | system, the state just wants apathy and obedience from
               | its citizenry.
               | 
               | So it would be totalitarian leaning for a leader to make
               | a speech (watching is mandatory btw) saying that buying
               | foreign is anti-patriotic and generating social censure,
               | in addition to the tariffs, for people seen with foreign
               | goods.
        
               | InsideOutSanta wrote:
               | Yeah, I should have phrased this better. When I said that
               | 
               |  _> citizens (...) largely don't have to care about
               | politics_
               | 
               | I didn't mean that it wasn't harmful if they didn't care;
               | I meant that there was no clear, immediate incentive.
        
               | Braxton1980 wrote:
               | >One of the benefits a working democracy conveys to its
               | citizens is that they largely don't have to care about
               | politics
               | 
               | The citizens elect the government so how can you not care
               | about poltiics?
        
               | InsideOutSanta wrote:
               | _> The citizens elect the government so how can you not
               | care about poltiics?_
               | 
               | I don't think there's a direct correlation between the
               | ability to vote and caring about politics. People usually
               | care about politics when it affects them negatively. I
               | would guess that most people in most democratic systems
               | don't have strong negative experiences with their
               | governments and, thus, are not incentivized to care about
               | politics.
               | 
               | Note that I'm not making an argument that they _should_
               | not care. I think they should, but the very system that
               | allows participation probably also decreases the
               | incentive for most people to participate.
        
               | Braxton1980 wrote:
               | >. I would guess that most people in most democratic
               | systems don't have strong negative experiences with their
               | governments
               | 
               | Opinion polls about political parties and leaders seem to
               | always hover near the bottom end, at least in the US [1]
               | 
               | [1] there are always bumps after elections (change), war
               | (nationalism), and tragedy (group sympathy)
        
               | jowea wrote:
               | Well, a bit. A part of liberal democracy is that
               | elections don't matter that much. The losers can trust
               | that they aren't going to be arrested, have their
               | property confiscated etc. The established system like the
               | courts, constitutions separation of powers and other
               | anti-majoritarian things will prevent most extreme
               | measures. And in at least some political systems, it is
               | expect that no matter what some minimally competent
               | people will win and govern not that differently from what
               | the election loser was going to do.
               | 
               | And remember voting is not mandatory and a lot of people
               | don't vote. Those people are ultimately letting others
               | decide, and a lot of them are hoping the voters are going
               | to pick well, or at least decently.
        
               | silverquiet wrote:
               | And yet the Republicans have campaigned on tearing down
               | government for my entire life. And people treated me like
               | a fool for believing them.
        
           | Cthulhu_ wrote:
           | Everything already was, you just didn't recognize it because
           | it was to your benefit / in your interests.
        
           | paganel wrote:
           | Agree, but it goes both ways, with technology (that many of
           | us here have helped create and maintain) also reaching out
           | into every facet of society and community, many times in
           | close symbiosis with the political powers that be, to the
           | detriment of said society and community.
           | 
           | Not 100% sure what I wanted to say, maybe that said politics
           | (and the political as a whole) wouldn't have invaded almost
           | our entire lives without the help of technology.
        
           | po1nt wrote:
           | That's because we got reliant on the funds from government.
           | Maybe it's time to break the dependency.
        
             | jocaal wrote:
             | > That's because we got reliant on the funds from
             | government
             | 
             | Not we, some people got reliant on the funds from
             | government. It is always at the cost of someone else. The
             | tax the rich and bourgeoisie mentality is what led to Mao
             | Zedong and Stalin, but no-one wants to learn about history
             | anymore.
        
               | Moomoomoo309 wrote:
               | Tax the rich mentality also led to the "golden age of
               | capitalism" of the 1940s, 50s, and 60s. The tax rates on
               | the wealthiest in the US at that time were huge, and that
               | money went into job programs, housing assistance
               | programs, construction projects, etc.
        
         | okeuro49 wrote:
         | "You can stay out of politics, but politics will always come
         | and find you."
         | 
         | No, it's just recognising that it is silly to talk about
         | politics, as certain views are just downvoted.
        
           | spookie wrote:
           | Of all places I find this one the most shielded from this
           | behavior as long as you're civil.
        
             | goku12 wrote:
             | It's true that HN insists on and respects civil behavior.
             | But HN doesn't always remain impartial in terms of
             | downvotes, flagging and removal of comments when it comes
             | to some topics that are inherently political. There was one
             | such overtly political thread recently where some of the
             | opposing comments were flagged and removed. Those comments
             | were not even as inflammatory as the news article itself.
             | It indicates that HN does have a majority political bias
             | that they're not hesitant to impose up on the discourse.
             | 
             | I'm not going to go into specifics of the topic because I
             | don't want to start another episode, though I do have the
             | complaint that such actions distort the discourse unfairly
             | to one side. And I also understand that political biases
             | are human nature and that they can never be fully
             | eliminated. But at the same time, it would be harmful to
             | pretend that the discourse on HN is apolitical, balanced or
             | that it shields you from that sort of censorship. Imagine
             | making a good-faith counterargument, only to have it
             | flagged and removed because the opposition doesn't like it.
             | And when asked, you get cited a point in the CoC, except
             | that it's not applied uniformly and impartially in that
             | thread. Makes you wonder what the purpose of flagging is at
             | all! That will just put certain groups at an undisclosed
             | disadvantage and lets harmful stereotypes flourish without
             | any challenge. All we can do is to be forthright about this
             | fact and try our best to have a civil debate.
        
         | dmckeon wrote:
         | People trying to ignore politics are like fish trying to ignore
         | water.
        
           | strogonoff wrote:
           | Not talking about politics is itself a political position (in
           | favor of status quo).
        
             | stingraycharles wrote:
             | Depends. We're a small, very international startup and have
             | a super strict "no politics" policy. Politics and work are
             | not a good combination when you're employing people from
             | all over the world.
             | 
             | But I would not consider it a political statement to adopt
             | this policy.
        
               | noelwelsh wrote:
               | Your statements are incoherent. Politics is decision
               | making and power relationships within groups of people.
               | It is 100% a political statement to adopt this policy as
               | it exercises power over a group. You cannot function as a
               | group without politics. "Where do y'all want to go for
               | lunch" is also politics, as it involves group decision
               | making and power relationships (Do you go to the
               | vegetarian place? Do you avoid the spicy place?) It's a
               | completely banal decision but it is still politics.
               | 
               | If what you want is a "don't piss off your coworkers by
               | discussing topics unrelated to work that you know will
               | annoy people" policy, that is fine, but don't pretend you
               | are not engaging in politics.
        
               | concordDance wrote:
               | "Politics" is a stupid word because everyone has a
               | different idea about what it means and so they all talk
               | past each other.
        
               | strogonoff wrote:
               | The word "politics" is vague, and that only makes banning
               | political discussions worse if it only becomes political
               | when the higher-ups don't like it.
               | 
               | Say your company has a possibility of working with some
               | client company who is directly or indirectly involved
               | with cause X. If it is "political" to talk about _not_
               | working with them because of X, but it is "not political"
               | to talk about working with them, then you see what I
               | mean.
               | 
               | It doesn't have to be a destructive conversation: one
               | employee might say we should avoid them, but you might
               | say we need to work with them because we need the money
               | now and can drop them later when we are in a better
               | place. Other employees could talk how cause X is not that
               | unethical for reasons. If someone balks at a point of
               | view incompatible with theirs and is incapable of
               | expressing a viewpoint in a way that respects other
               | views, maybe that someone is not mature enough and next
               | time your HR can avoid that type.
        
               | pixl97 wrote:
               | Many people that ban political discussions miss the irony
               | that it's a political decision.
        
               | gedy wrote:
               | Yeah exactly, the same people who shout the loudest about
               | "everything is politics" and want to talk about it at
               | work would go apeshit if someone at work said "I'm not
               | comfortable with abortion", etc. HR would quickly be
               | called and shut them down.
        
               | def13 wrote:
               | The politics of saying "no politics" is that you are
               | drawing some line that separates some political issues
               | into "politics" and others into "not politics". Because
               | to truly avoid all politics is impossible; even if you
               | believe banal, purely intra-personal politics are not
               | political so much of the basic organization of a business
               | & capitalism are politics. "Should we allow remote work"
               | for example is a deeply political question that ties
               | deeply into discussions about the rights/value of
               | neurodivergent & disabled people in the workplace. To say
               | 'I don't believe in God' is a deeply political and
               | dangerous statement in some parts of the world, but
               | fairly banal where I live. To contrast, in Indonesia, it
               | is technically _unconstitutional_ to not believe in a
               | "one and almighty God"
               | 
               | I wish people were at least honest about "no politics" to
               | mean "lets avoid to unsafe, potentially divisive issues
               | relative to our geographic location, and take the basic
               | tenets of neoliberal, capitalistic society to be
               | assumed". And yeah, that is a more than reasonable
               | policy. Its a difficult policy in international spaces,
               | because its very hard to not trespass that line when
               | political contexts differ so strongly across the globe
        
               | lou1306 wrote:
               | > take the basic tenets of neoliberal, capitalistic
               | society to be assumed
               | 
               | Well, then any discussion about an illiberal oclocratic
               | executive (such as 47's) should be fair game...
        
               | DrillShopper wrote:
               | > The politics of saying "no politics" is that you are
               | drawing some line that separates some political issues
               | into "politics" and others into "not politics".
               | 
               | I find someone's heuristics for deciding which category a
               | statement falls into chiefly turns on if they agree with
               | the statement. If they agree with the statement then it
               | is not political, and if they disagree, it's political.
        
               | rini17 wrote:
               | I am torn.com player which is a MMORPG as far removed
               | from politics as can be. But when large part of dev team
               | are ukrainians that were suddenly unable to work from
               | clearly political reasons you can't ignore it.
        
               | squigz wrote:
               | One might argue that it's even more important to discuss
               | international politics these days, considering how
               | interconnected the world is and how so many countries
               | seem to be facing many of the same issues.
        
               | orwin wrote:
               | I think it exists two different general ideas of what
               | politic mean.
               | 
               | For some (including me), politics are, following the
               | oldest definition: 'how do I and fellow humans organize
               | ourselves to live together' this often leads to a belief
               | that everything is politics (for me it's true, but it's a
               | belief, not a fact).
               | 
               | For other, I think that when they say politics, they
               | think of geopolitics and partisanship, which is fair,
               | because it's how politicians and political journalists
               | themselves define politics. For this group, hopefully,
               | not everything is politics.
               | 
               | So to me, this disagreement about wether or not all is
               | political is often semantic rather than ideologic.
        
               | pseudalopex wrote:
               | The disagreement is semantic and irrelevant in the sense
               | the question at hand usually is which topics and opinions
               | are forbidden at work.
               | 
               | The disagreement is semantic and relevant in the sense
               | people who say no politics at work believe their
               | categories of politics and not politics are obvious.
               | 
               | The disagreement is ideological in the sense ethical
               | concerns about products or customers are designated
               | political often.
               | 
               | Politicians, political journalists, and people who say no
               | politics at work do not define politics as geopolitics
               | and partisanship.
        
               | tobr wrote:
               | How do you define politics? For example, are employees
               | allowed to be LGBTQ? Are they allowed to mention their
               | relationships to colleagues?
        
               | pxoe wrote:
               | Being straight is also pretty much political at this
               | point. With the way it's being slipped into the culture
               | (all that trad stuff, images of lifestyle to aspire to,
               | etc.) and has become (has always been perhaps) a part of
               | political messaging and campaigning, heterosexuality is
               | political. Even within the heterosexuality itself and its
               | expressions, there's still politics - "what's the right
               | way to do it" and such. (not saying this like 'oh those
               | poor straight people' but just that, it is all, all
               | political)
        
               | tobr wrote:
               | For what it's worth, I completely agree, I just thought
               | LGBTQ was a clearer example because of how different it
               | is seen in different parts of the world, and how it is at
               | the same time an inescapable part of many people's
               | identity.
        
               | criddell wrote:
               | For a lot of people on HN, a ban on politics discussions
               | in the office is impossible because we have to deal with
               | software licenses.
        
               | strogonoff wrote:
               | First, "no politics" is not a political statement to me,
               | more of an implicitly adopted political position.
               | 
               | Personally, if I have a personal political position and
               | my colleague has an opposite one, I don't see why we
               | can't talk about it. If you have a workplace rule about
               | no politics during working hours, you better have this
               | rule for all non-work discussions at work, or I
               | personally would feel uncomfortable.
               | 
               | -- If politics talk happens at work too much and affects
               | productivity, then it is a problem, but then it is a
               | problem with any non-work topic.
               | 
               | -- If it causes heated debate, ruins morale, and makes
               | people dislike each other, then it is a problem, but then
               | it is a problem with any topic that causes heated debate.
               | For some people it's golf, for some philosophy, for some
               | music. How many topics should be banned?
        
               | dcow wrote:
               | Are you from the US? In the last 15 years it has become
               | impossible for two people to reasonably disagree over
               | political positions because of how much vitriol is thrown
               | around on the attention markets--even if both individuals
               | themselves are rather tame. When having an otherwise
               | normal political opinion makes you a racist bigot or a
               | beta cuck because the opposition is so determined to get
               | their way at any cost, no, you can't just talk politics
               | at work and have a cohesive team. Someone will feel
               | oppressed.
               | 
               | Work is about making money. Politics is a distraction
               | unless there's an issue that directly affects the
               | business. Then it's fair game. Like this one. Many teams
               | of individuals will have to figure out how to navigate
               | this situation so discussing it in context is apropos and
               | can be done objectively.
        
               | strogonoff wrote:
               | > When having an otherwise normal political opinion makes
               | you a racist bigot or a beta cuck because the opposition
               | is so determined to get their way at any cost
               | 
               | If someone calls me a racist bigot or a beta cuck, that
               | is a problem. That problem also has nothing to do with
               | politics. It has to do with someone not being emotionally
               | mature enough or equipped to handle a discussion with
               | someone who has different views, or someone having a
               | mental breakdown.
               | 
               | I am not from the US, but I had enjoyed some reasonable
               | conversations with people from the US (among other
               | countries) with very different views, and I was never
               | called names. There are awkward moments when you have to
               | hear something you don't agree with, but that is most of
               | life if you ever interact with people.
               | 
               | The key is to be like an HTTP server: liberal in terms of
               | what you can accept, but strict with what you put out
               | there.
               | 
               | > Work is about making money.
               | 
               | You have _just_ thrown another political position into
               | the mix, I hope you realize that?
        
               | AlexandrB wrote:
               | > It has to do with someone not being emotionally mature
               | enough or equipped to handle a discussion with someone
               | who has different views, or someone having a mental
               | breakdown.
               | 
               | Any moderately sized company is practically guaranteed to
               | have a few people like this. So getting into these
               | discussions has a high risk of becoming an HR issue as
               | tempers flare and conversations become vitriolic.
               | 
               | There's also the issue that the company founders and
               | leadership have political opinions of their own that
               | might inform company policy and any political opinion to
               | the contrary may be perceived as pushback from a
               | "troublemaker".
        
               | strogonoff wrote:
               | > getting into these discussions has a high risk of
               | becoming an HR issue as tempers flare and conversations
               | become vitriolic.
               | 
               | Here we can forget that IRL face to face people are much
               | less likely to be offensive to each other. If they get to
               | literal name calling and aggression, sure, that's an HR
               | issue, HR gets paid to sort this out, doesn't it? I don't
               | see how politics is different from any other topic on
               | which people can have strong opinions.
               | 
               | > There's also the issue that the company founders and
               | leadership have political opinions of their own that
               | might inform company policy and any political opinion to
               | the contrary may be perceived as pushback from a
               | "troublemaker".
               | 
               | That is why "no politics" is somewhat dishonest. In my
               | view, either blanket forbid all off-topic talks, or don't
               | censor by topic and handle fights if they arise. There
               | can also be softer guidelines about how to behave at work
               | without an actual ban of any topic.
        
               | pseudalopex wrote:
               | Or censor by topic specifically and honestly.
        
               | dcow wrote:
               | I agree with your ideal. I used to be one of those people
               | who would just talk about whatever in any context
               | assuming everyone was mature enough to have academic
               | discussions and not get personal. Political viewpoint is
               | a protected class in the US. But we all saw what happened
               | to James Dramore. Real consequences for holding a
               | political opinion that allegedly made him "unemployable
               | at Google" where his politics were so threatening to the
               | established order that Google just couldn't operate with
               | him in the mix. You'd think G has the most mature
               | employees... and either they do but humans are just
               | toxically unable to hold differing opinions, or they
               | don't and therefore have to maintain a safe space for the
               | comfort of their sensitive workers.
               | 
               | The silliest part: what was his thesis? Well that using
               | race and gender based quotas during hiring and leveling
               | made Google less competitive. Certainly not a privileged
               | white male tech bro just barreling through the company on
               | a racist bigoted spree leaving tears in his wake. There
               | is more interesting discussion to be had here about how
               | the Civil Rights Act has been weaponized in the US and
               | companies feel they have a legal obligation now to prove
               | that their systems don't yield "unfair distribution of
               | protected classes", or whatever the actual wording is.
               | And how that is at odds with a world where you can openly
               | discuss politics at a company without fear of falling
               | afoul of the Chief Diversity Officer (ffs, there are
               | executives installed to maintain the order now). And
               | related: just look at how pockets of people respond to
               | Trump's second term insisting that he's a fascist
               | dictator and anybody who doesn't see it is a de facto
               | fascist. But I digress.
               | 
               | Nobody wants to bet their job on being on the losing end
               | of a kafka traps and thought terminating cliches.
        
               | ksec wrote:
               | You would have been cancelled if you said this between
               | 2014 - 2019 at the peak of it all.
               | 
               | At least now you can say it out now without being
               | downvoted into oblivion.
        
             | concordDance wrote:
             | It's in favor of not having relationships break down in
             | your community/company.
             | 
             | Only a small percentage of people are able to handle
             | fundamental disagreements calmly and without it bleeding
             | over to other interactions.
             | 
             | Will the SE and sales guy work as well together if the
             | former knows the latter donates half his commission money
             | to organizations that help kill babies?
        
               | eMPee584 wrote:
               | but letting > the SE and sales guy
               | 
               | never find out about their shared passion is kind of
               | cruel, too?
        
               | j45 wrote:
               | It's not uncommon for one side to come out with their
               | position/interpretation/belief whether it's passion or
               | not.
               | 
               | Maybe at a work function, team party, conference, etc.
        
               | strogonoff wrote:
               | I have friendly relationships with a few people who have
               | political opinions some of which are opposite to mine.
               | 
               | > Will the SE and sales guy work as well together if the
               | former knows the latter donates half his commission money
               | to organizations that help kill babies?
               | 
               | A friend of mine is a vegan. Anywhere he works, to him,
               | most of his coworkers not just help kill conscious beings
               | that have self-awareness and feel pain, they literally
               | eat them. Does this mean talking about what you have for
               | lunch should be banned? Does this mean he should throw a
               | fit any time he talks to a non-vegan?
               | 
               | Incidentally, we sometimes have good debates about the
               | nature of consciousness, the effectiveness of individual
               | veganism on reducing suffering, utilitarianism and
               | deontology, vegan food options, etc. I feel being
               | converted and I don't mind it.
        
               | AlexandrB wrote:
               | > Anywhere he works, to him, most of his coworkers not
               | just help kill conscious beings that have self-awareness
               | and feel pain, they literally eat them. Does this mean
               | talking about what you have for lunch should be banned?
               | 
               | You're making the opposite case of what you think. Your
               | Vegan friend is avoiding taking about politics
               | _constantly_ because they 're not bringing up the fact
               | that everyone is consuming the flesh of innocent animals
               | every time they go for lunch. If they started talking
               | about the politics and beliefs of veganism at every meal
               | shared with coworkers, I think it would have a negative
               | impact on those relationships.
        
               | strogonoff wrote:
               | He does not bring up consuming products of animal
               | suffering (including egg and milk products) directly, but
               | he does order vegan food, which is enough to make a point
               | (for me at least).
               | 
               | What he is doing by expressing his philosophical position
               | simply through his order is turning me subsequently
               | ordering something with eggs into a philosophically
               | loaded action as well. That, of course, shifts my opinion
               | on the question.
               | 
               | I am making the point I am making: if we worked together,
               | we should be free to discuss veganism or paleo diet
               | (which I have discussed with a coworker previously)
               | whenever either of us wanted, and he demonstrated being
               | an adult about it when we do. If he asked to not talk
               | about it because it made him uncomfortable, then we
               | wouldn't. I do not see why political discussions have to
               | be different.
        
               | pjmlp wrote:
               | Turning the question around, will the SE and sales guy
               | work as well together if the former knows the latter
               | donates half his commission money to FSF while the other
               | is hard advocate for commercial software?
               | 
               | Politics are across all layers, including at technology
               | decisions.
        
             | kortilla wrote:
             | No it's not. It's having discipline to not pollute
             | unrelated conversations with your politics. I am very
             | against the status quo but I don't complain about it to a
             | bunch of anonymous usernames on a forum focused on
             | technology.
             | 
             | You can believe something without proselytizing.
        
               | MiguelX413 wrote:
               | Things are often inherently political.
        
               | johannes1234321 wrote:
               | Technology and the consequences of using technology are
               | inherently highly political.
               | 
               | New or improved technologies shape communities.
               | 
               | Ignoring that is a political statement as well.
               | 
               | Just see how online media has changed discourse, how
               | Amazon changed retail business, how business analytics
               | change the way businesses work, how always being
               | connected changes relations, ...
               | 
               | When developing technologies one can be Wernher von Braun
               | "(where the rockets land and whether they contain
               | explosives is) not my department" or one can consider
               | consequences.Both are a political position, with
               | consequences.
        
               | drstewart wrote:
               | >Technology and the consequences of using technology are
               | inherently highly political.
               | 
               | So what stance does The Art of Computer Programming take
               | on communism?
        
               | egoisticalgoat wrote:
               | Is communism the only political topic? Or does whether or
               | not The Art of Computer Programming talk about
               | accessibility in software not constitute a political
               | opinion?
        
               | acdha wrote:
               | That's a very narrow redefinition of both technology and
               | politics, and even there it's only a step away from
               | discussions about how automation affects millions of
               | jobs, how daily lives are shaped by what's allowed by the
               | software which large companies or governments build, or
               | how amassed data can be misused in ways which wouldn't be
               | possible without efficient algorithms.
        
               | johannes1234321 wrote:
               | Between the four books there is a lot of paper being
               | printed, with chemicals which have to be sources
               | somewhere.
               | 
               | But a bit more serious there are different angles to
               | this:
               | 
               | One is that the formalization Knuth did, is basis for the
               | way other research on computer science has been setup.
               | 
               | His work on TeX as part of writing the books has great
               | impact on how scientific reports are being written, which
               | themselves have consequences.
               | 
               | And then there is all the consequence while implementing
               | technology. How optimisations by better algorithms enable
               | data mining, replacing manual labor, ...
               | 
               | Now of course impact differs. Not everybody is building
               | V2 rockets (as well as Saturn rockets) like von Braun
               | did, but there are many wheels in the machinery.
               | 
               | I myself am a small wheel in building database engines.
               | The software is used by sports clubs to manage their
               | members, shop owners to manage their inventory, companies
               | to run their ads and air craft carriers to replicate
               | strategic data across the ship, so that if one part is
               | damaged, the other can still operate. If I were to leave,
               | the organisation would continue developing, but the work
               | has impact.
        
               | ttepasse wrote:
               | Knuth in the wake of the Iraq war and the Abu Ghraid
               | crimes asked some "Infrequently Asked Questions" which
               | are of course highly political. He kept this page linked
               | on top of his home page. And in 2022 he wrote a
               | postscript with more political questions.
               | 
               | https://www-cs-faculty.stanford.edu/~knuth/iaq.html
        
               | drstewart wrote:
               | I didn't ask about Knuth.
               | 
               | I asked about the book. Everything is inherently HIGHLY
               | political, thus this should be an easy question.
        
               | strogonoff wrote:
               | > You can believe something without proselytizing.
               | 
               | You can _talk about politics_ without proselytising. Why
               | should discussing a topic even invoke the words like
               | "belief" and "proselytising"?
               | 
               | Not only stating an opinion is compatible with a
               | constructive discussion that could lead to a mutual
               | adjustment of opinions--in fact, stating your opinion is
               | often a pre-requisite to having a discussion that could
               | lead to it being changed.
               | 
               | The magic happens when person A realizes that another,
               | equally sane person B can think very differently about
               | topic X. At that point, the person A has to either 1)
               | write the person B off as crazy (not so easy when that
               | person is obviously sane in every other way), or 2)
               | realize that there may be _something_ to it and ever so
               | slightly adjust own opinion on topic X, or at least
               | become more tolerant.
               | 
               | Not being able or willing to freely exchange and converge
               | on opinions with people whom you routinely meet in real
               | life, only discussing them online in your respective
               | bubbles, is a sure way to having only more and more
               | wildly incompatible and divisive opinions, and I suspect
               | it is exactly what has been happening in recent years.
        
               | JumpCrisscross wrote:
               | > _having discipline to not pollute unrelated
               | conversations with your politics_
               | 
               | Discipline isn't found in hiding. Someone who cannot
               | discuss politics without polluting conversations isn't
               | disciplined, they're unpracticed in conversing and
               | thinking through their views.
        
             | iteratethis wrote:
             | Incorrect, not talking about politics does not signal any
             | political affiliation.
             | 
             | I think the "everything is political" statement is
             | technically correct but practically useless. In the
             | workplace the discussion is mostly about allowing or
             | disallowing politics that are irrelevant to the business.
        
             | brightball wrote:
             | No it's not. It's a position that comes from experience of
             | knowing that it's a complete waste of time because nobody's
             | mind is being changed.
             | 
             | Further, there are entire segments of political groups who
             | just want to assume your beliefs like a political straw man
             | so they can denigrate you.
             | 
             | It's an unhealthy waste of time and that doesn't truly hit
             | you until you invest the time in talking to an otherwise
             | rational person, provide the closest thing to proof of your
             | perspective in a situation and then watch them deny it
             | anyway.
        
               | strogonoff wrote:
               | > it's a complete waste of time because nobody's mind is
               | being changed.
               | 
               | What you said can be true if you approach the discussion
               | with an attitude of "I want to change everybody's mind"
               | instead of trying to get to some agreement and truth.
               | 
               | Not only stating an opinion is compatible with a
               | constructive discussion that could lead to a mutual
               | adjustment of opinions--in fact, stating your opinion is
               | a precursor to having a discussion that can change it.
               | 
               | > It's an unhealthy waste of time and that doesn't truly
               | hit you until you invest the time in talking to an
               | otherwise rational person, provide the closest thing to
               | proof of your perspective in a situation and then watch
               | them deny it anyway.
               | 
               | The magic happens when one person realizes that another,
               | obviously sane in every other way person can think very
               | differently about topic X. Repeated exposure to
               | alternative views from other people in your circles
               | leaves no alternative except to adjust your own opinion
               | on topic X.
               | 
               | Thing is, it's tricky or impossible online. Aside from a
               | handful of well-known people with some reputation or
               | infamy, most of us only know each other as handles with
               | no context. On the Internet, no one knows you are a dog
               | or a basement dweller who lives with his parents and
               | could never hold a job. Meanwhile, access to a group of
               | like-minded people is always at your fingertips when you
               | are online. However, when you are in a company of people
               | who clearly are similar enough in what they achieved, in
               | their choice to work for the same company, maybe good in
               | their software engineering skill, etc., it makes their
               | opinion something that may count.
               | 
               | Not being able or willing to freely exchange and
               | consequently converge on opinions with people whom you
               | routinely meet in real life, and only discussing said
               | opinions in your respective online bubbles, strikes me as
               | a path to having more and more divergent, incompatible,
               | extreme opinions (which I rather suspect might have been
               | happening a lot in recent years).
        
               | brightball wrote:
               | > Repeated exposure to alternative views from other
               | people in your circles leaves no alternative except to
               | adjust your own opinion on topic X.
               | 
               | I have not found this to be true when it comes to
               | politically aligned beliefs.
        
               | strogonoff wrote:
               | Maybe don't always just take their word for it. Some
               | (most?) people will continue to express their view
               | vocally, but the fact of encountering an opinion from
               | someone they otherwise find a reasonable and sane person
               | will cause introspection and adjustment, and maybe in a
               | different group they would express an adjusted opinion.
               | Most people are always affected by others (excluding
               | sociopaths or other unusual cases).
        
               | brightball wrote:
               | In person when you can communicate tone and know there is
               | a level of mutual trust, I would generally agree.
               | 
               | Over the past few years I've even begun to wonder about
               | that though.
        
               | enraged_camel wrote:
               | >> No it's not. It's a position that comes from
               | experience of knowing that it's a complete waste of time
               | because nobody's mind is being changed.
               | 
               | I think the issue is that when people debate someone,
               | they want to "win" by having the other side accept
               | defeat. You are right, that rarely happens, especially in
               | politics.
               | 
               | However, as someone who has participated in countless
               | formal debates, I'll share a secret: your goal in a
               | debate isn't to convince the person you're debating. It's
               | to convince the audience. And that happens quite
               | frequently, even if it's not immediately visible to the
               | debate participants.
        
               | brightball wrote:
               | That is certainly a valid point, especially in formal
               | debates.
        
               | jowea wrote:
               | You don't need to completely change someone's positions
               | for it to be worthwhile. This is a thread about something
               | that has directly to do with HN's usual tech topics, and
               | it would be hard to not talk at least a bit about the
               | political aspects.
        
           | anon373839 wrote:
           | It's really a question of time and place. There are many
           | foundational topics in life, such as politics, religion, and
           | philosophy. But it's not always helpful or appropriate to
           | discuss them in a particular setting.
           | 
           | That said, HN already has an extremely wide range of subject
           | matter, so I wouldn't say politics should be out of place
           | here. It can, though, become a divisive distraction that
           | disrupts other conversations, so I can appreciate that some
           | limits are needed.
        
           | starspangled wrote:
           | Ignore politics entirely maybe, but people who are tired of
           | hearing the exact same extremist reductive opinions over and
           | over again everywhere aren't necessarily ignoring politics.
           | Yes we know it's all because conservatives are fascists and
           | corrupt and Russian agents and liberals are communists and in
           | bed with the Chinese, etc., not caring to hear about it again
           | is not surrendering the battle of good vs evil.
           | 
           | For me, ironically, the worst casualty of "politics"
           | infiltrating everything is... politics. I mean the respectful
           | and reasoned discussion of politics. Not that it was ever in
           | great supply, but now it is non-existent.
        
           | mr_toad wrote:
           | > People trying to ignore politics are like fish trying to
           | ignore water.
           | 
           | Like fish, most people do ignore it until it turns foul.
        
         | cantrecallmypwd wrote:
         | Yep. It's also true of people who think they can simply move
         | out of the US and that "solves" the problem too. America's
         | problems are still (almost) everyone's problems too.
        
           | goku12 wrote:
           | True. But it's much less of a problem outside. For example,
           | does the gun culture in the US affect the rest of the world?
           | It sure does. You can guess where most of the illegal weapons
           | come from. But we rarely even think about getting shot while
           | at school or on our way to the groceries.
        
         | blueflow wrote:
         | The problem is not political topics, it is how people discuss
         | them.
        
           | titaphraz wrote:
           | That's a massive issue. Every topic is so polarized that it's
           | as if it's evil vs. good.
           | 
           | But I think people are waking up, because things they took as
           | non-political god given right is being made political and
           | taken away.
        
           | titaphraz wrote:
           | It's exhausting because of
           | https://en.wikipedia.org/wiki/Firehose_of_falsehood
        
         | h1fra wrote:
         | HN and founders will say "no politics here" on the regulated
         | internet, drinking regulated water, eating regulated food,
         | breathing regulated air.
        
           | pjc50 wrote:
           | Apart from the few maniacs On Here who seek out the
           | unregulated intentionally. Raw milk (all those tasty
           | diseases). "Research chemicals" (don't hear so much about
           | that lately, but there were whole microdosing fads).
        
             | franktankbank wrote:
             | Raw milk is delicious, my ancestors have been drinking it
             | for millennia.
        
               | chillingeffect wrote:
               | And we enjoyed our milkborne tuberculosis, typhoid,
               | scarlet fever, diphtheria, and septic sore throat
               | thoroughly, too. The risks actually doubled the joys. Why
               | does a supposedly enlightened society step all over my
               | right to choose which eliminated diseases to bring back?
        
               | pixl97 wrote:
               | Oooh, ooh, oh, don't forget the brucellosis either.
               | 
               | But hey, I only get to enjoy this if the measles here in
               | Texas don't get me first.
        
               | user_7832 wrote:
               | Isn't this literally survivorship bias? Those who died
               | early wouldn't have had offspring.
               | 
               | 1 - https://en.wikipedia.org/wiki/Survivorship_bias
        
               | franktankbank wrote:
               | Not saying its a good choice for those whose ancestors
               | didn't go through the selection process.
        
               | JumpCrisscross wrote:
               | Your ancestors didn't face bird flu.
               | 
               | That said, I'm for people being idiots. I'm just done
               | paying for it. If you're chugging raw milk during a bird
               | flu epidemic and your family gets sick because of it,
               | basic insurance and the public should only pick up the
               | cost after you've declared bankruptcy.
        
               | franktankbank wrote:
               | Similarly I wish I could enact carveouts so I wasn't
               | supporting peoples health problems related to commenting
               | way too much on the internet, hackernews in particular.
        
               | numpad0 wrote:
               | not everyone's ancestors
        
               | bluGill wrote:
               | Only about 1/3rd of the world. However by coincidence
               | fluency in English correlates high with ability to drink
               | milk as an adult.
        
               | skywhopper wrote:
               | And many of them died from doing so.
        
               | nindalf wrote:
               | Milk is my main drink. I don't drink beer or wine, it's
               | mostly just plain milk for me. And while there is a
               | substantial taste difference based on the % of fat, I
               | have never seen a difference in taste between pasteurised
               | and non-pasteurised. I actually bought a bottle of raw
               | milk from a farmer just to try it. No negative effects,
               | but it just tasted insipid compared to 5.4% fat milk I
               | can get at the supermarket.
               | 
               | People who claim a taste difference between raw and
               | pasteurised, I'd very much like to see someone taste the
               | difference on the _same_ cow 's milk blind, before and
               | after pasteurisation. I just don't think it affects the
               | taste much, and certainly not as much as fat %.
               | 
               | And for people who claim health benefits, I would like to
               | see a double blind study demonstrating those benefits.
        
               | franktankbank wrote:
               | You may be onto something about the different cows. This
               | was while I lived in France temporarily. I had no idea
               | that I was drinking raw milk. I was commenting how
               | delicious it was and a coworker said "oh is that the
               | stuff you have to boil". Me "wut". It was much better
               | than the supermarket milk I could get.
        
               | ceejayoz wrote:
               | It isn't raw if it's been boiled.
               | 
               | That's pasteurized. At a higher temp than the supermarket
               | stuff, even.
        
               | franktankbank wrote:
               | Might not have been clear. I wasn't boiling it because I
               | couldn't read the french instructions.
        
               | AlexandrB wrote:
               | The confounding factor is milk fat. In my experience
               | higher fat milk just tastes better regardless of any
               | other factor and milk straight from the cow will have up
               | to 5% milk fat compared to 3.25% for "whole" milk. Try
               | drinking a shot glass of 10% cream sometime, it's
               | amazing.
        
               | bitexploder wrote:
               | What the cows eat matters for how milk tastes too. Cows
               | can get sick. Udders can get infections. Milking
               | processes (machinery) and its ease of cleaning can vary.
               | Bacteria is everywhere. Pasteurization is a cheap,
               | effective and has no real drawbacks. This whole raw milk
               | thing is just silly and has become political for some
               | silly reason.
        
               | bluGill wrote:
               | I think the main difference is fresh. When I was in high
               | school I stayed with a dairy farmer who brought in a jug
               | of milk from the tank for breakfast after milking the
               | cows. After that I can't drink regular milk.
               | 
               | Pasteurization does affect taste though. Around me there
               | are two different dairies, one does regular
               | pasteurization and one does vat pasteurization and I can
               | tell the difference. There is ultra pasteurization which
               | is just gross. I've never put unpasteurized head to head
               | against equally fresh pasteurized though, and given what
               | I now know I'm not going to.
        
               | AlexandrB wrote:
               | I _love_ ultra pasteurization. I 'm lactose intolerant so
               | I have to drink "lactose free"[1] milk and in Canada such
               | milk is often UHT pasteurized since it has to stay on the
               | store shelf longer (lower inventory turnover). It's
               | amazing that we can, non-chemically, disinfect a dairy
               | product in such a way that it will stay good for months
               | even without refrigeration.
               | 
               | In Mexico I suspect that almost all milk is ultra
               | pasteurized since it's not refrigerated in stores and has
               | wicked-long expiration dates. It's also some of the best-
               | tasting milk I've had so I think that flavour has more to
               | do with some of the other milk processes (like skimming)
               | and the livelihood of the cows rather than with how it's
               | pasteurized.
               | 
               | [1] In practice this is just milk with the lactase enzyme
               | added at some point during production.
        
               | nindalf wrote:
               | I have no doubt that milk that is 15 minutes old tastes
               | great. My question is if that jug of milk was divided in
               | two and one half was pasteurised, would people be able to
               | tell the difference? You're saying yes, I'm saying I'd
               | like to see blind tests of people tasting both.
        
               | bluGill wrote:
               | IF you read close you will see that I didn't say yes. I
               | said that I don't know and am not willing to be part of
               | such a blind test. I will state clearly that all the
               | unpasteurized milk I had was less than an hour old and
               | tasted great, while all the pasteurized milk was unknown
               | age but likely at least a day old and tasted worse. Is it
               | fresh or pasteurization that makes a difference is not
               | something I know.
        
               | numpad0 wrote:
               | There is ultra pasteurization which is just gross.
               | 
               | Are you referring to 120C 3-second ultra high temperature
               | pasteurization? I don't see what would be so gross about
               | it.
        
               | bluGill wrote:
               | I don't know the details about ultra pasteurization. I
               | just know anything labeled ultra pasteurized states
               | gross.
               | 
               | Of course the above is subjective. Others have stated
               | they prefer it. To each their own, but I will continue to
               | maintain it makes milk taste gross.
        
               | Nihilartikel wrote:
               | I'd consider drinking raw milk only if I was on a first
               | name basis with the cow that produced it.
               | 
               | Otherwise I would at least demand it be fermented into
               | kefir so the food microbes can muscle out the bad.
        
               | bluGill wrote:
               | That won't make a difference. Bacteria is something you
               | cannot see and so you have no idea what is on/in the cow.
        
               | xolox wrote:
               | It sure can make a difference.
               | 
               | Sickness caused by bacteria doesn't happen as soon as one
               | bad bacteria (bacterium?) enters your body, a certain
               | critical mass is usually required. This is very similar
               | to the concept of "viral load" where a certain amount of
               | viral genetic material needs to be exchanged before the
               | viral infection can take hold.
               | 
               | The "beneficial bacteria" on your skin and in your gut
               | make it harder for bad bacteria to take root in many
               | different ways, one of them simply being they provide
               | competition, "crowding out the bad guys".
               | 
               | Another way is that many, many, many types of antibiotics
               | were originally discovered as metabolites produced by
               | bacteria and fungi (examples include penicillin,
               | streptomycin, chloramphenicol, and tetracycline).
               | 
               | And for completeness sake, milk kefir contains many
               | Lactobacillus species that are also a natural part of the
               | mammal microbiome (which makes sense when you think about
               | it; Lactobacillus are named for consuming lactose, an
               | ingredient of mammal milk).
        
               | mr_toad wrote:
               | > Raw milk is delicious, my ancestors have been drinking
               | it for millennia.
               | 
               | Before refrigeration most milk was made into butter,
               | cheese and other products. Unless your ancestors actually
               | herded the animals themselves they probably didn't drink
               | much raw milk.
        
             | avisser wrote:
             | Banning raw milk is for health. Banning research chemicals
             | is mostly an extension of the war on drugs. They aren't the
             | same.
        
           | bbarnett wrote:
           | Will all of these things be free of micro plastics and other
           | contaminants?
           | 
           | If so, is there a signup page?
        
             | mulnz wrote:
             | Wait these regulations haven't created total perfection?
             | Better burn the whole thing down.
        
           | fnord77 wrote:
           | > regulated ...
           | 
           | not for long
        
         | scandox wrote:
         | What people mean when they say this is that they don't want to
         | engage in party political and/or tribal political discussions.
         | They don't want to do this because it just means rehearsing
         | talking points.
         | 
         | People are not dumb. They know that politics is everywhere but
         | they want to live and love and talk about things that are
         | interesting.
        
           | gedy wrote:
           | Exactly, and on the flip side many people who want to "talk
           | politics" mainly want to shout at the outgroup and pick
           | public fights.
        
         | belorn wrote:
         | I view the archive.org, Wikipedia, CVE program, and Linux
         | Kernel to all have had discussions on HN about how to they
         | should be funded. Is that kind of politics the kind that people
         | wish that HN stayed out from?
        
           | diogocp wrote:
           | No, but the "everything is political" people are not capable
           | of making that distinction. Which is probably why everything
           | seems political to them.
        
             | lcnPylGDnU4H9OF wrote:
             | > that distinction
             | 
             | What is the distinction?
        
         | atmosx wrote:
         | This quote is essentially unworkable. Everything you say, or
         | choose not to say, inevitably advances some political
         | perspective over another.
         | 
         | What we should really aim for is thoughtful, civilized, and
         | maybe even aesthetically pleasing discourse. That's what
         | educated people strive for.
         | 
         | Trying to "avoid politics" is like collecting seashells while a
         | tsunami is rolling in.
        
           | surgical_fire wrote:
           | Agreed. Those who don't care about politics are doomed to be
           | ruled by those who care.
           | 
           | Moreover, avoiding politics is impossible. It's all around
           | you. Labor, entertainment, food, housing. Burying your head
           | in the sand will only get you to have your ass in the air.
           | 
           | Maybe "be polite" should be a better rule than "avoid
           | politics".
        
           | cjs_ac wrote:
           | It's scary how widely this varies between different
           | communities. On Reddit, /r/politics is mostly people acting
           | like they're auditioning for the writers' room on one of
           | those late-night talk shows, whereas /r/ukpolitics and
           | /r/australianpolitics are almost exclusively people making
           | insightful, analytic comments.
        
         | elcritch wrote:
         | > The ancient Greek understanding of an "idiot" referred to
         | someone who was a private citizen or a person who did not
         | actively participate in public life or politics.
        
         | spacebanana7 wrote:
         | To play devil's advocate - it's horrible when gaming,
         | programming, business or even porn forums get overrun by
         | politics.
         | 
         | It's not that the political topics are unimportant but all my
         | feeds just end up looking the same as each other and the same
         | as a newspaper app. I hate election nights because of this.
        
           | Titan2189 wrote:
           | "porn forums" is a thing?
        
             | 7bit wrote:
             | Absolutely
        
             | amarcheschi wrote:
             | i would be surprised otherwise
        
             | numpad0 wrote:
             | http://twitter.com
        
             | intuitionist wrote:
             | They're so much a thing that they came back the other way
             | and overran politics itself in the North Carolina
             | governor's race last year
        
             | nindalf wrote:
             | Porn forums are a thing. For example, this politician lost
             | what should have been an easy election because someone
             | found his old comments on a porn forum - https://en.wikiped
             | ia.org/wiki/2024_North_Carolina_gubernator.... Among other
             | things he commented on the forum that he'd like to bring
             | slavery back.
             | 
             | Honestly did not believe that people commented on porn
             | forums before this incident.
        
           | acdha wrote:
           | I miss that, too, but the way we get there is by re-
           | establishing democratic norms and boundaries. The United
           | States is flirting with fascism, and globally we are seeing
           | the fallout from that and the cascading effects of climate
           | change, not to mention the impacts of AI on employment,
           | surveillance and censorship, social media, etc. Keeping
           | politics out of forums like the ones you mentioned is like
           | keeping oxygen out of a space station.
        
             | jzb wrote:
             | Flirting? That was years ago. Fascism has its shit in
             | U-Haul and is ready to move in.
        
               | pixl97 wrote:
               | Ready to move in, are we sure it's wallet isn't on the
               | nightstand and the keys are hanging beside the door?
        
               | thfuran wrote:
               | Nah, it's already almost done moving its stuff in.
        
           | ivolimmen wrote:
           | If you are American and you voted for this guy ->
           | https://www.reddit.com/r/leapoardsatemyface/
        
           | scoresomefeed wrote:
           | Inverse devils advocate:
           | 
           | But look at it this way: I see the us political spectrum
           | melting down into authoritarianism and you're complaining you
           | don't need to be reminded of it.
           | 
           | A similar analogy would be if we are at your house, and it
           | catches fire, and you complain that it is interfering with
           | watching Netflix while I'm trying to call 911 for help.
           | 
           | From my perspective you are ignoring your own demise and from
           | your perspective I'm just being annoying.
        
           | SkyBelow wrote:
           | Politics are also never discussed with any level of depth. At
           | best, it each side throwing in their opening arguments and
           | nothing more. More often you don't even get that and instead
           | have attacking people directly, stereotyping, straw manning,
           | and all sorts of logical fallacies. Discussion in such a
           | situation does not happens, so either it is an ongoing war or
           | some side wins and pushes out the rest. None of these
           | outcomes would seem beneficial for here, and while I do think
           | there would be some slightly longer form discussions here
           | compared to most places, I don't think it would be enough to
           | avoid the eventual decay.
        
         | keybored wrote:
         | Apolitical person: Ugh politics is so dumb
         | 
         | Same person: Why is the world organized in such a dumb way?
        
         | pjmlp wrote:
         | Technology without politics is a pipe dream, even the FOSS
         | licenses depend on politics.
        
         | bamboozled wrote:
         | 100% agree, staying out of politics has been a luxury not
         | everyone has, it's totally unavoidable now.
        
         | pif wrote:
         | There's politics and there are facts.
         | 
         | Trump voters are stupid. This is a fact.
         | 
         | Right or left leaning, that's politics.
        
         | mrtksn wrote:
         | The problem with discussing politics is that it gives you the
         | kicks. Its very easy to get into a feedback loop and take
         | things quite far off civility. I am also guilty of it, many
         | times.
         | 
         | IMHO there needs to be a mechanism for breaking the loop and
         | then we can have civil online political discussions.
         | Unfortunately most places just ban it or ban those who got into
         | the loop, either way its ugly.
         | 
         | IRL when discussing politics and things don't go badly its
         | thanks to 3rd party who will moderate or calm down the heated
         | debaters.
        
           | kelsey98765431 wrote:
           | No thank you. I am absolutely uninterested in civil
           | discussions with people who literally want to kill me and
           | deport my good friends to guantanamo bay cuba. When you
           | accept nazism you throw the concept of civil discourse out
           | the window.
        
             | mrtksn wrote:
             | See, its unlikely that its those people that you meet
             | online and you won't be able to do anything to them anyway.
             | 
             | %99.999 of the time its usually trolls or people with good
             | intentions(with wrong solutions based on wrong information
             | or understanding of the situation). Trolls can be fun when
             | they play with hypothetical scenarios and edge cases,
             | conducting thought experiments.
             | 
             | You are also unlikely to change the views of the people
             | with good intentions through discussion but they are very
             | useful to understand what their motives so you can develop
             | beter arguments or solutions. Also, you might find out that
             | on some issues you are one of those with good
             | intentions(but misguided understanding of the situation).
        
             | bluGill wrote:
             | Case in point: you have decided that those who disagree
             | with you want to kill you, deport your friend, and are
             | otherwise nazis. While a minority do, that isn't the
             | majority.
        
               | mulnz wrote:
               | I am (un)lucky enough to live in an area where I don't
               | have to decide this. People are willing to say it out
               | loud.
        
               | citizenkeen wrote:
               | One the one hand, yes.
               | 
               | On the other hand:
               | 
               | "Historians have a word for Germans who joined the Nazi
               | party, not because they hated Jews, but out of a hope for
               | restored patriotism, or a sense of economic anxiety, or a
               | hope to preserve their religious values, or dislike of
               | their opponents, or raw political opportunism, or
               | convenience, or ignorance, or greed.
               | 
               | That word is 'Nazi.' Nobody cares about their motives
               | anymore."
               | 
               | - Julius Goat
        
               | thrance wrote:
               | We had a word for people that voted for Nazis, agreed
               | with Nazis, talked like Nazis but claimed they weren't
               | Nazis themselves in the 40s. It was "Nazi".
               | 
               | What matters is that the current administration is
               | disappearing people with no legal reasons, due process or
               | possible recourse. Either you agree with them in which
               | case fuck you, or you don't and you condemn them. There
               | can be no compromise or civility when one side is so
               | aggressive and dangerous.
        
               | vultour wrote:
               | This argument went out the window long ago. You're not
               | absolved of responsibility just because you voted for
               | someone who wants to hurt people instead of hurting them
               | yourself.
        
               | bluGill wrote:
               | Quit turning the argument around. forget about "them" -
               | what does it say about you when you cannot talk nice
               | about people you disagree with?
               | 
               | People who voted for Trump are not stupid. They have real
               | concerns that they do not see being met and so they are
               | turning to something that while maybe not ideal is at
               | least a promise of maybe better. Maybe it will be worse,
               | but they don't see things on the right track as they were
               | either.
        
               | crawsome wrote:
               | Why can't we talk plainly to each other anymore? Can we
               | not talk in loaded statements and projection?
               | 
               | They have valid concerns, and taking steps to minimizing
               | those concerns is just muddying the water in favor of
               | those using political violence against people who don't
               | deserve it.
               | 
               | There's a lot of counter-intel campaigns flying around
               | all at once, and a lot of them are curated to infect
               | brains of people who are willing to accept fascism.
               | 
               | "Well, they're not completely nazis... so you're wrong
               | for likening them to nazis!"
               | 
               | "Well, you've decided to shut off discussion to people
               | opening your mind about the impending fascism. That must
               | mean you're not fit for discussion"
        
             | AlexandrB wrote:
             | No thank you. I am absolutely uninterested in civil
             | discussions with people who literally want to control
             | everything I say and put my good friends into reeducation
             | camps. When you accept communism you throw the concept of
             | civil discourse out the window.
        
               | btucker wrote:
               | I understand you're trying to "both sides" an argument.
               | What have you found that has achieved for you in the
               | past? Do you change people's opinions with this?
        
               | AlexandrB wrote:
               | I have found that no amount of online discussion has ever
               | changed anyone's mind on larger issues. We're all pissing
               | in the wind here.
        
               | btucker wrote:
               | Then why did you post that?
        
               | abvdasker wrote:
               | Democrats haven't put anyone into a reeducation camp as
               | far as I'm aware. Your enemies are imaginary while the
               | parent comment's enemies are all too real.
        
               | AlexandrB wrote:
               | Yes, but the Republicans literally want to kill some
               | minority groups. /s
               | 
               | Do you know how crazy this all sounds once you're outside
               | of a specific left echo chamber? How is the hyperbole I
               | employed any more unbelievable than that of the poster I
               | was replying to? Another sibling comment to yours says
               | that Trump is rounding up political opponents for a
               | gulag. Nevermind that he has only rounded up non-citizen
               | (most of them in the US illegally) because that's all he
               | _can_ do.
               | 
               | If you look at my posting history, it's wildly left-wing
               | as little as 2 years ago. I've become completely
               | disillusioned with the left after noticing how self-
               | contradictory some of those ideas are and how the
               | language of crisis is deployed to constantly smear their
               | political opponents. Everyone the left doesn't like is
               | Hitler and every policy they don't like is fascism. Give
               | me break.
               | 
               | Edit:
               | 
               | For a little more elaboration, look at the speech codes
               | and compelled "DEI pledges" that American universities
               | have employed in the last few years[1]. How is this not
               | speech policing? You might argue that these are private
               | institutions, and maybe that's fair enough, but when the
               | government pulls funding for crap like this the hyperbole
               | and outrage persist.
               | 
               | Or look at Canada's bill C-63[2]. This bill aims to allow
               | the possibility of life sentences for "hate speech"[3].
               | To _me_ this is authoritarian. To many left wing
               | commentators, it 's another day at the office, I guess -
               | meanwhile the Canadian right wing party is regularly
               | called fascist[4][5] despite being basically in line with
               | US Democrats on many issues.
               | 
               | [1] https://unsafescience.substack.com/p/the-last-four-
               | years-wer...
               | 
               | [2] https://www.parl.ca/DocumentViewer/en/44-1/bill/C-63/
               | first-r...
               | 
               | [3] https://bccla.org/2024/09/whats-in-bill-c-63-why-are-
               | we-alar...
               | 
               | [4] https://medium.com/pigeons-peculiarities/pierre-
               | poilievres-p...
               | 
               | [5] https://cultmtl.com/2025/02/pierre-poilievre-has-
               | racked-up-e...
        
               | thrance wrote:
               | Oh good, "it's only non-citizens". Nevermind that they're
               | still supposed to be protected by the constitution, then.
               | Also, Trump said two days ago that he wishes to send
               | citizens to El Salvador too [1]. Are we allowed to call
               | them fascist or should we wait for that to be made
               | illegal too?
               | 
               | Trump does not care about the law. SCOTUS, in a historic
               | 9-0 ruling, commanded him to bring back Kilmar Abrego
               | Garcia from El Salvador. He unsurprisingly did not
               | comply. Yet you're still insisting he can't legally do X
               | or Y so everything is fine. When has that stopped him,
               | like ever?
               | 
               | If that's not fascism, then what is? What would it take
               | for you to say "OK that's too much"?
               | 
               | [1] https://apnews.com/article/trump-citizens-prison-el-
               | salvador...
        
               | frob wrote:
               | What you are saying is the fantastical kool-aid Fox News
               | and alt-right media spin to you.
               | 
               | In the meantime, Trump is actually deporting people
               | without due process to inhumane torture camps run by a
               | dictator while openly bragging about it and defying court
               | orders.
               | 
               | These two things are not the same.
        
               | AlexandrB wrote:
               | > What you are saying is the fantastical kool-aid Fox
               | News and alt-right media spin to you.
               | 
               | What I'm replying to is the fantastical Kool-aid MSNBC
               | and alt-left media spin. I'm pretty sure the Republicans
               | are not going to be rounding up and killing minorities
               | despite hyperbolic descriptions like "people who
               | literally want to kill me and deport my good friends to
               | guantanamo bay cuba".
               | 
               | Wait, you're saying El Salvador is a dictatorship? From
               | briefly glancing at Wikipedia I don't see any evidence of
               | that. Why the need to smear another country just to make
               | Trump look worse?
        
               | miningape wrote:
               | Any argument where you can change a few words and it
               | suddenly makes the opposite point was never a good
               | argument to begin with.
               | 
               | In short: it doesn't convince you of anything, it merely
               | reinforces your existing biases.
        
               | thrance wrote:
               | Insane talk. Where is that communist political force
               | seeking to open gulags? The Democrats? Hahahahah
               | 
               | Trump _has_ a gulag in El Salvador, _right now_ , that he
               | uses to send his political opponents to. And you people
               | are still making up fantasies to play the victim.
               | Absolutely disgusting.
        
               | DrillShopper wrote:
               | > people who literally want to control everything I say
               | and put my good friends into reeducation camps
               | 
               | Then you shouldn't talk to Trump supporters as that's
               | exactly what they want to do for anyone that disagrees
               | with them, and last I checked, they're capitalists.
               | 
               | They are planning on abducting people off the street,
               | completely ignoring the courts and denying due process,
               | and sending them to another country where they're being
               | deprived of their rights, again, with no due process and
               | no (effective) judicial review.
               | 
               | I'd expect most right wingers would be against this, but
               | the Orange in Charge's supporters seem to hew to the
               | "well if you didn't do anything wrong you've got nothing
               | to worry about" angle because it's something happening to
               | people they think deserve it.
        
               | AlexandrB wrote:
               | > but the Orange in Charge's supporters seem to hew to
               | the "well if you didn't do anything wrong you've got
               | nothing to worry about" angle because it's something
               | happening to people they think deserve it.
               | 
               | This is _literally_ the left wing reply when people
               | complain about losing their job or their family for
               | voicing the wrong political belief.  "They deserve it,
               | they should 'do better'."
        
               | DrillShopper wrote:
               | There is a huge difference between losing your job and
               | being black bagged, sent to El Salvador, and possibly
               | killed.
               | 
               | Let's keep that in perspective.
        
               | enraged_camel wrote:
               | I don't think any Democrat has ever put anyone into
               | reeducation camps. I may be mistaken though - can you
               | cite some examples?
        
               | AlexandrB wrote:
               | I don't think any Republican has advocated for a policy
               | of killing minorities. The hyperbole of my post is the
               | point.
        
             | galangalalgol wrote:
             | Having civil discussions with people who disagree isn't
             | about politeness or acquiescence. Having political
             | discussions per the same rules we use for technical
             | debates, like steel manning, allows information to actually
             | flow both ways. I'm up to four people now that I changed
             | parties between 2020 and 2024. That doesn't seem like a
             | lot, but if everyone was doing it it would make a
             | difference. It took time. I had to non judgementally listen
             | to their concerns and intuit the fears underneath. They
             | were reasonable intelligent people operating off of
             | propaganda mostly. The emotional hook had been set and used
             | draw them further and further into false narratives that
             | fed their fears and hopes. To think I am immune isn't
             | realistic either. My triggers are getting used to pull me
             | the other direction, to make me uncompromising, and to view
             | those who disagree as inhuman. Some of that is game theory
             | polarizing us, but some of it is the intentional result of
             | the Kremlin's standard divide and conquer they have been
             | using on us for over half a century. The antidote is calm
             | conversations with voters who have been made scared about
             | irrational things, and looking to see what fears we are
             | being manipulated with as well.
        
               | DrillShopper wrote:
               | > Having civil discussions with people who disagree isn't
               | about politeness or acquiescence. Having political
               | discussions per the same rules we use for technical
               | debates, like steel manning, allows information to
               | actually flow both ways.
               | 
               | What additional information do they need to get out there
               | other than they want me and people like me dead? What
               | additional information do I need to get out there other
               | than I don't want them to do that?
        
               | wins32767 wrote:
               | The logical end state of this belief is a civil war. I
               | assume that in lieu of trying to change minds you're
               | buying guns and ammo and trying to organize like minded
               | people into a militia to protect your safety? Cause if
               | not, I don't really think you really believe that a
               | significant fraction of the country wants people like you
               | dead.
        
               | DrillShopper wrote:
               | I'm in the process of emigrating to Europe since it's not
               | safe for me and my family here.
        
               | galangalalgol wrote:
               | Not sure which hated demographic you fall in, but I have
               | friends that are suddenly being threatened by individuals
               | who now feel free to expose their true selves. I can't
               | believe almost half the population are like that though.
               | Escape may be the best option for a lot of people at this
               | point. My friend doesn't realistically have that option
               | due to finances and skillset. I do think people who
               | aren't in immediate danger can pull a lot of people
               | supporting those fueled by hate away from their positions
               | with calm dialogue.
        
               | mrtksn wrote:
               | In my experience as a chronic immigrant, most people are
               | nice but there are some a-holes who would want to harm
               | you or see you get harmed but they would not act unless
               | they feel in power.
               | 
               | Therefore, most of the time you can just ignore them and
               | your experience wouldn't any different than the natives
               | who would also encounter a-holes for different reasons.
               | The problem starts when someone in power to affect your
               | life is one of those but in normal times you still can
               | push back by questioning their actions as they still seek
               | approval from the larger society.
               | 
               | The case with Trump seems to be the same with the case
               | with Brexit: Those a-holes(not everyone who support those
               | but a subset of them who are a-holes) start believing
               | that they are in power and the society approves them
               | therefore they can act on their instincts or plans.
               | 
               | I was working in London on the Brexit referendum day,
               | some of our Spanish developers had trouble with people
               | from their neighborhood right after the referandum.
        
           | crawsome wrote:
           | The loop is intentionally being closed and sped-up by enemies
           | of the USA who want to exhaust the USA in every way possible.
           | 
           | After the infekktion of 2015, moderators of Right-leaning
           | discussion boards started amping up their censorship. Left
           | leaning and moderate discussion boards still tend to be more
           | moderate, letting most discussions in and censoring less.
           | 
           | Most of the time, one side is trying to play an equal field,
           | while the other shits all over it and just yells "Winning!"
        
         | deadbabe wrote:
         | Not keeping politics out of our lives is the reason we've ended
         | up with a totalitarian fascist dictatorship. If politics is
         | forbidden, people have to just make up their own minds and vote
         | for what makes sense to them, instead of banding together and
         | slowly intensifying to the most radical extremes in bids to
         | outdo each other.
         | 
         | Everytime you discuss politics on the internet, you entrench
         | the current administration.
        
           | timacles wrote:
           | Fascinating logic. The victims are at fault. If only they did
           | something different the abusers would have never had to abuse
           | them.
        
         | Pxtl wrote:
         | > the "I wish HN would stay out of politics" crew.
         | 
         | Sadly, this crew includes the site's moderation.
        
         | mardifoufs wrote:
         | ah yes, losing the... CVE database is truly the wake up call to
         | get engaged in politics.
         | 
         | I mean sorry but I'm not sure if you're being ironic. It sounds
         | like something you'd read on ngate
        
         | orblivion wrote:
         | HN can stay out of politics just fine for the most part. If a
         | political topic comes into tech we can talk about it then, and
         | stay out of other crap that insufferable people drag in because
         | "there's no such thing as being neutral" or whatever.
        
       | nodesocket wrote:
       | I'm betting CVE will get sponsored by a security company or
       | Cloudflare.
        
       | gm3dmo wrote:
       | Anyone feel confident that the companies who benefit massively
       | from MITRE are even now planning to step in and provide
       | significant funding?
        
       | gabesullice wrote:
       | As a newly minted cynic, this seems like a cynical play to save
       | someone's budget.
       | 
       | Step 1: Post discreetly to a forum with minimal information and
       | an absurdly short deadline
       | 
       | Step 2: Phone your friend, the former board member, to make your
       | case on LinkedIn
       | 
       | Step 3: Ring up a friendly journalist and give them a tip
       | 
       | Step 4: Reference the insuing chaos as justification for keeping
       | your project funded
       | 
       | Note that the article carefully avoids pinning the blame on DOGE
       | or the Whitehouse while heavily implying it. MITRE is technically
       | a private entity, albeit a non-profit. And the very last
       | paragraph of the article states:
       | 
       | > A CISA spokesperson told CSO, "CISA is the primary sponsor for
       | the Common Vulnerabilities and Exposure (CVE) program... Although
       | CISA's contract with the MITRE Corporation will lapse after April
       | 16, we are urgently working to mitigate impact and to maintain
       | CVE services on which global stakeholders rely."
       | 
       | To be clear, the point isn't to say that the CVE program isn't
       | valuable, nor is it to say that it's _good_ for a shenanigan like
       | this to be necessary.
       | 
       | The point is that, unless you're directly involved in this
       | subject (not impacted--involved), it's probably best to maintain
       | a "wait and see" attitude rather than succumb to catastrophizing
       | this news.
        
         | girvo wrote:
         | Have you seen proof that this is what has been happening? Your
         | explanation is much more convoluted than "DHS cut funding, like
         | the administration has said it is going to do".
        
           | gabesullice wrote:
           | These explanations are not mutually exclusive.
        
       | jl6 wrote:
       | So is this going to instantly break a bunch of tools like Trivy?
        
       | wengo314 wrote:
       | vibe coding could not have come at a worse moment.
        
         | sgt wrote:
         | Just tell the AI: "Make this code secure" /s
        
         | redleader55 wrote:
         | I see this as the perfect moment to get into consulting -
         | either development, or security. People were not sure what jobs
         | AI will create: "GenAI babysitting" is one of them.
        
       | skirge wrote:
       | only one country pays but all benefit from it. It should be
       | funded by all who benefit like UN.
        
         | goku12 wrote:
         | I'm sure that a hundred other countries will step up to fund
         | it. But have you given any thought about why the US was so
         | willing to sponsor it alone in the past?
        
         | jowea wrote:
         | I thought most people in the US wanted the UN to have less
         | control over this stuff? Remember the talk about moving control
         | of the Internet to the ITU (International Telecommunication
         | Union)?
        
       | hubabuba44 wrote:
       | The real irony here is that a lot of ycombinator founders and the
       | people reading HN were exactly the ones making this possible and
       | now start to wonder why the snake eats its own tail.
        
         | cantrecallmypwd wrote:
         | Sorry, I made the mistake of installing PyPy.
        
           | hubabuba44 wrote:
           | I assume that this comment should go somewhere else or I'm
           | not able to decipher the message ;)
        
             | jampekka wrote:
             | PyPy's logo is a snake eating its tail.
        
               | hubabuba44 wrote:
               | Cool thanks!
        
               | cantrecallmypwd wrote:
               | Sorry and thanks GP. ;o)
               | 
               | Your nerd card had been validated for today. Go forth,
               | ethically.* :D
               | 
               | * Oops, I introduced 2 more programming languages, my
               | bad.
        
         | this15testingg wrote:
         | exactly; I hope ycombinator and its proponents can enjoy living
         | in the ancap fantasy land where you have to pay to be alerted
         | for a climate change fueled mega hurricane (also caused by this
         | _exact same_ reckless, unregulated greed) because NOAA was
         | disbanded. Billionaires shouldn 't exist, but neither should
         | millionaires.
        
           | sebstefan wrote:
           | You don't need MITRE
           | 
           | For-profit private journaling is working really well for
           | academia!
        
           | ourmandave wrote:
           | Will they have a free tier where I can sit through 30 second
           | ads? =(
        
         | j-krieger wrote:
         | The missing funding is something like 2 million dollars. Any US
         | company could make this issue go away in an instant.
        
           | hubabuba44 wrote:
           | We will see. I understand that money shouldn't be an issue
           | but trust might be, no?
        
           | Sonnigeszeug wrote:
           | Its not a money problem, its a understanding problem.
           | 
           | Shouldn't the most powerful country has something like this?
           | Being even in the forefront of it?
           | 
           | The USA was doing cyberprotection against Russia and
           | cyberattacks across the world.
           | 
           | Now suddenly it doesn't need it anymore?
           | 
           | Like just did Russia go away (or has russia won and sits now
           | in the white house)?
        
             | drstewart wrote:
             | You're right.
             | 
             | I don't understand why the EU wasn't funding it and isn't
             | funding it now. I thought they're united against Russia?
        
               | lentil_soup wrote:
               | because they already do? https://euvd.enisa.europa.eu/
               | 
               | please, stop spreading your weird anti-europe views
        
               | drstewart wrote:
               | Great. Then there's no loss here. What's the big deal?
        
               | sweezyjeezy wrote:
               | Your comments feel a bit incoherent - just extend your
               | reasoning for why you think Europe should want to fund
               | this back to the US again.
        
               | drstewart wrote:
               | Can you extend your reasoning for why you think the US
               | should want to continue to fund this for the EU?
        
               | sweezyjeezy wrote:
               | "for"? You realise this is a homeland security matter for
               | the US as well as the EU?
        
               | testbjjl wrote:
               | The GP sounds like one of these people who describe
               | themselves as self made, or libertarian, where history
               | begins where you like it and coalitions are only worthy
               | when you're the biggest benefactor. Best to ignore and
               | let the leopards find them.
        
               | sweezyjeezy wrote:
               | haha, sage advice
        
         | nosianu wrote:
         | Or they wanted this, because this could be part of the
         | privatization of many government functions. They, or at least
         | some of them, could see this as controlling this function for
         | money. It's a regular stream too, the valuable subscription
         | model and customers who really need the service (and if they
         | don't, just add a new law in the name of IT security forcing
         | firms to sign up).
        
           | hubabuba44 wrote:
           | To me it looks too chaotic to be a planned privatization plan
           | but who knows.
        
             | voxic11 wrote:
             | I think its part of the tried and true strategy of causing
             | chaos then blaming the government for it and presenting
             | privatization as the solution.
        
             | testbjjl wrote:
             | Move fast and break things as we say.
        
       | rcarmo wrote:
       | Now would be a great time for a major tech company to support
       | them (or, even better, a consortium).
        
       | basemi wrote:
       | For now, historical CVE records will be available at GitHub:
       | 
       | https://github.com/CVEProject
        
       | InsideOutSanta wrote:
       | This makes me wonder what other stuff most people don't know
       | exists but is important to our society has quietly disappeared in
       | the last few weeks. We know about this one because we know it's
       | important. What are the things we don't know about?
        
         | jeroenhd wrote:
         | https://www.project2025.observer/ lists a few. Of course, those
         | are only the agencies the Trump people know about and
         | explicitly want to destroy, but it's a start.
        
         | knowaveragejoe wrote:
         | The cheerleaders don't care. Americans' relative certainty and
         | quality of life is backstopped by institutions they either
         | barely understand or have never heard of. Let them touch the
         | stove, I guess.
        
       | jl6 wrote:
       | It's a reckless move to cut funding so abruptly, but taking a
       | step back from the short-term chaos, it probably _is_ an anomaly
       | that this was government funded. All of private tech relies on
       | it, and private tech is big enough to pay for it. I hope that the
       | trillion dollar babies consider this an opportunity to pool
       | together to form a foundation that funds this, and a bunch of
       | other open source projects run by one random person in Nebraska.
        
         | kbumsik wrote:
         | > it probably is an anomaly that this was government funded
         | 
         | Companies can definitely fund it. But to be fair the gov,
         | including NIST, also relies on CVE.
        
         | chasontherobot wrote:
         | ah yes, let private entities pay for it. then when there is a
         | vulnerability with one of those entities' software, they can
         | pay a bit more to bury it!
        
         | padjo wrote:
         | Ah yes the old "well can't concerned citizens band together,
         | form a committee, collect revenue and fund things that are in
         | the common interest" answer you hear from small government
         | types that makes me think you lot don't really understand what
         | government actually is.
        
         | JCharante wrote:
         | > it probably is an anomaly that this was government funded.
         | All of private tech relies on it, and private tech is big
         | enough to pay for it.
         | 
         | I mean doesn't big tech and the people they give salary money
         | to pay taxes? Ground transportation companies rely on public
         | roads and but we fund it because having the infrastructure is
         | an economic multiplier.
         | 
         | I'm not arguing in favor of funding the CVE program, I just
         | don't think that's a good reason.
        
           | jl6 wrote:
           | Opinions vary on what the purpose of government is, but if
           | you take the view that the government's priorities should be
           | providing services that are impossible, inefficient, or
           | unethical to provide privately, then I don't see the CVE
           | program making the cut, when the tech industry is
           | collectively flush with resources and has every incentive to
           | form an industry consortium to take it over.
           | 
           | A modern Open Group, perhaps?
        
         | bspammer wrote:
         | The US government itself uses the database, so there is a
         | strong national security interest in it not being in private
         | hands.
        
         | phillipcarter wrote:
         | Considering the large number of government agencies that have
         | sponsored the program, no, I don't think it was an anomaly:
         | https://www.cve.org/About/History
        
       | bslanej wrote:
       | Just seeing HN mad like this makes things like these so much
       | worth it.
        
         | goku12 wrote:
         | Oh! It will be even more fun when the entire infotech and
         | infosec industry starts seething soon. Then the rest of the
         | world will just make alternative arrangements and move on,
         | leaving the US behind because they can't be trusted anymore.
         | HN's reaction is just a small taste of things to come.
        
       | karel-3d wrote:
       | Phew, no new annoying CVE reports in my Docker images from today
        
       | dhx wrote:
       | The latest contract[1] (I hope this is the right one) for MITRE's
       | involvement with CVE and CWE programs was USD$29.1m for the
       | period 2024-04-17 to 2025-04-16 with optional extension of
       | expenditure up to USD$57.8m and to an end date of 2026-04-16.
       | 
       | Seemingly MITRE hasn't been advised yet whether the option to
       | extend the contract from 2025-04-16 to 2026-04-16 will be
       | executed. And there doesn't appear to be any other publicly
       | listed approach to market for a replacement contract.
       | 
       | [1]
       | https://www.fpds.gov/ezsearch/jsp/viewLinkController.jsp?age...
        
         | gwd wrote:
         | I can't figure out why the hue and cry wasn't raised until the
         | very last minute. Did they not know a month ago that they were
         | running out of time? Is it standard practice for the government
         | not to say they're going to extend the contract until the day
         | beforehand or something?
        
           | sq_ wrote:
           | Right now, yes. You can pretty easily have a scenario where
           | you're talking to the agency you're working with and they're
           | saying "we want to renew this, but we don't know if they'll
           | give us the money in the end".
           | 
           | So you'll get a bunch of "hopefully this week" up until it
           | expires.
        
           | pjmorris wrote:
           | I was at VulnCon last week, and an NIST representative said
           | that there were no plans to cut CVE funding.
        
       | Brosper wrote:
       | Europe needs to save the world!
        
       | kesor wrote:
       | Good, less government involvement is better for everyone.
        
       | NilayK wrote:
       | > A coalition of CVE Board members launched a new CVE Foundation
       | "to ensure the long-term viability, stability, and independence
       | of the Common Vulnerabilities and Exposures (CVE) Program."
       | 
       | > https://www.thecvefoundation.org
       | 
       | https://mastodon.social/@serghei/114346660986059236
        
         | hahajk wrote:
         | So if the govt stops paying them they'll continue to do the
         | work for free?
        
           | lou1306 wrote:
           | More likely they will seek funding from companies and other
           | organizations, as every other foundation/consortium of this
           | kind does.
        
           | pantropy wrote:
           | The way their letter is worded it seems that they have a
           | rainy day fund constituted to ride out the stormy next few
           | week and I'm fairly certain they'll come back with more
           | details as to how they'll be acquiring funding from now on in
           | the next few days. Maybe paid access to an API, maybe
           | donations from large companies that use the system, maybe
           | something else ::shrug:: Hopefully a project as important as
           | this doesn't just dissapear completely because of government
           | pressure.
        
           | jmcgough wrote:
           | They're converting to a nonprofit, so instead of federal
           | funding they will need funding from big tech companies.
        
             | panzagl wrote:
             | MITRE is already a not-for-profit.
        
           | delfinom wrote:
           | How else will they continue burning out open source
           | maintainers with bullshit?
        
         | gnfargbl wrote:
         | This kind of a consortium needs to explicitly avoid being
         | captured by both the product vendors (who could be incentivised
         | to manipulate the CVE issuance process to support their own
         | remediation timescales), and by security companies (who could
         | be incentivised to obtain a competitive advantage via
         | preferential access to the CVE database).
         | 
         | It isn't impossible for a commercially-funded organisation to
         | avoid this kind of capture, but it isn't easy either. My mind
         | immediately jumps to the relationship between the Mozilla
         | Foundation and Google.
        
           | transpute wrote:
           | Then there were two: https://gcve.eu
           | 
           | Plus the proposed "Foundation for Standards and Metrology
           | (FSM)" to build on NIST, https://democrats-
           | science.house.gov/bills/the-expanding-part...
        
           | tbrownaw wrote:
           | Don't some projects already issue their own CVEs?
        
             | detaro wrote:
             | yes, but it's a hierarchy. If you disagreed with their
             | judgement you could always go up the chain, and MITRE can
             | take the privilege away again if they think a vendor is
             | misusing it.
        
             | gnfargbl wrote:
             | CNAs [1] are assigned blocks of CVEs and then assign from
             | within that block, but the system only works if there is
             | overall administration of the CVE Program [2].
             | 
             | My concern is that a capture of the administration would
             | become a capture of the entire programme. Looking at the
             | structure, it seems possible that CISA are in a position to
             | prevent any such capture but, given some of the recent
             | positions taken by the US government, we'll need to wait
             | and see how that plays out.
             | 
             | [1] https://www.cve.org/ProgramOrganization/CNAs
             | 
             | [2] https://www.cve.org/ProgramOrganization/Structure
        
         | pama wrote:
         | This smells like a quick attempt to enable phishing for
         | vulnerabilities, and not a legit way to make progress. The
         | comment is from a person that runs a security startup and the
         | site is a google site that people can report to google as a
         | scam. (Edit: downvote as you like it-- perhaps my language was
         | too harsh to help make the point clear. It is interesting how
         | easy non-sec people fall for names and quotes and authority..
         | building trust does not come overnight, in fact it is never
         | fully there, and infosec experts would not fall for such supply
         | chain redirections with questionable future. Hopefully we will
         | not have to test this idea soon, though some level of
         | reliability and long-term automation would be welcome. We need
         | technical, generally agreed upon systems, not a "foundation").
        
       | londons_explore wrote:
       | How much was this contract worth?
       | 
       | If it was $5000/yr it's very different to if it's $5M/year for
       | what amounts to little more than an instance of mediawiki.
        
         | harisec wrote:
         | $44M/year?
         | 
         | https://www.usaspending.gov/award/CONT_AWD_70RCSJ23FR0000015...
        
           | londons_explore wrote:
           | Totally worth cancelling then.
           | 
           | Some volunteer will set up a GitHub pages and mailing list to
           | fulfill the same duties.
        
             | Peanuts99 wrote:
             | Or 10 people will create that list and nobody will use any
             | of them. The whole point here is that the CVE program had
             | the network effect of being the defacto list of issues but
             | now that's been pissed away.
        
       | anilakar wrote:
       | Let me guess: Trump is going to make China pay for it.
        
       | jibal wrote:
       | Bad guys helping out bad guys--it's what mobsters do.
        
       | mzhaase wrote:
       | Long term its probably good to have a less US-centric world.
        
         | jeroenhd wrote:
         | This is a chance for the EU to step up and take over. If the US
         | government won't pay for the CVE program, the EU surely could.
         | Many EU countries already run a program like this to server
         | their own interests, and I believe the EU does as well.
         | 
         | If the US is willing to give up influence and control over the
         | cybersecurity sector, we should accept that gift and use it to
         | our advantage.
        
       | moomin wrote:
       | I'm sure a much better private sector alternative will appear any
       | day, in line with conservative dogma.
        
       | rvba wrote:
       | Why cant wikipedia foundation step in? They have millions of
       | dollars.
        
       | drdrek wrote:
       | LOL this is Amazing... Holy shit
        
       | gorbachev wrote:
       | I wonder what would happen to CVE program funding if Tesla and
       | SpaceX would be zero-dayed to hell and back.
        
         | redleader55 wrote:
         | We will soon find out, probably.
        
           | phtrivier wrote:
           | I'm really curious about the "soon" part, though. What is the
           | timeline for something very visible to happen, and still be
           | directly relatable to DOGE ?
           | 
           | Just imagine if it happens in three years, after the midterms
           | - someone will be able to blame the Dems for it :) !
        
       | dools wrote:
       | Uh oh did someone CVE grok or twitter?
        
       | WillAdams wrote:
       | FWIW, I've never understood why this sort of thing wasn't just
       | directly handled by the NSA --- aren't they the group which
       | should be tasked with cybersecurity?
       | 
       | I always suspected that "Department of Homeland Security" would
       | lead to Banana-republic-like shenanigans --- could we defund
       | them?
        
         | donohoe wrote:
         | I don't think anyone trusts the NSA to run a program like this.
        
         | dfedbeef wrote:
         | "National Security" doesn't mean you personally. It's the
         | government only. There's a conflict of interest that
         | immediately arises if a part of the DoD (who owns cyberwarafe,
         | which uses vulns) maintains a public vuln database.
         | 
         | (Edited to be less salty, sorry)
        
       | thih9 wrote:
       | I can't see any long term benefits for the US. It looks like the
       | current administration is fine with chaos and disruption on an
       | unprecedented scale.
        
       | donatj wrote:
       | Practically speaking, how much could it cost to maintain the CVE
       | database?
       | 
       | Given its enormous value, isn't this something that the
       | community, especially FAANG (MAANA?) could step up and fund as a
       | nonprofit?
        
       | uptownfunk wrote:
       | Seems like a big miss on the part of DOGE?
        
       | i_love_retros wrote:
       | At this point it's not crazy to believe Russia is running the
       | country
        
         | dfedbeef wrote:
         | This level of stupidity seems pretty American to me
        
       | paulmendoza wrote:
       | Anyone who voted for Trump voted for this type of dumb action.
       | This is a major loss for society and safety.
        
       | jnovacho wrote:
       | It looks like the decision has been reverted, for now at least:
       | https://www.forbes.com/sites/kateoflahertyuk/2025/04/16/cve-...
        
       | jeff_carr wrote:
       | The contract with MITRE has been extended.
       | 
       | https://www.forbes.com/sites/kateoflahertyuk/2025/04/16/cve-...
       | 
       | My guess indefinitely.
       | 
       | DOGE might be a bunch of idiots, but in the entire DOD, there are
       | non-idiots.
        
         | metalliqaz wrote:
         | not just idiots... _malicious idiots_
        
           | lenerdenator wrote:
           | Malicious idiots surrounded by sheepish intelligent people.
        
             | fennecfoxy wrote:
             | Hasn't that always been the case for society at large? From
             | Wernher Von Braun to Oppenheimer.
        
             | xpe wrote:
             | > Malicious idiots surrounded by sheepish intelligent
             | people.
             | 
             | Prefixing people with "sheepish intelligent" is bound to
             | oversimplify this. Many of the non-DOGE employees who
             | directly see wrongdoing are likely making calculated
             | decisions on what to do. It depends on many factors,
             | including the law and whistleblower protections.
             | 
             | Many of them are responding in various ways that they hope
             | will have an impact. Some resign in protest. Others file
             | lawsuits. Others leak to the press.
             | 
             | Could they do more? Yes. So let's help them.
             | 
             | What can we do? Just to give two relatively middle-of-the-
             | ground recommendations: First, donate to legal-protection
             | funds for whistleblowers. Second, call your representatives
             | and demand reinstatement of the inspectors general.
        
           | tomrod wrote:
           | Per news reporting, not just malicious idiots but foreign
           | agents.
        
         | tlogan wrote:
         | My guess is that they'll be phased out next year. The long-term
         | goal seems to be transitioning the CVE program into something
         | more like an industry-led consortium. (If you did not notice
         | they operate zero budgeting approach: cut everything and if
         | something is very important reverse it. But you cut first and
         | then ask questions.)
         | 
         | It's worth noting that MITRE is a DoD contractor (with minor
         | contracts from other agencies like this one). Having the CVE
         | program operated by a company funded by the U.S. military
         | raises valid concerns about conflicts of interest--especially
         | in an ecosystem that depends on neutrality and global trust.
        
           | nxobject wrote:
           | I'm a little hesitant to trust a CVE database operated by
           | private industry on the grounds of conflict of interest for
           | that reason, too.
        
             | ThinkBeat wrote:
             | I am quite hesitant to trust the DOD to keep track of
             | software vulnerabilities. Some parts are developing and
             | exploiting vulnerabilities. And given a fresh feed of what
             | people find, and usually a delay from notification until
             | publication, which may sometimes just be a bit longer of a
             | delay, would allow the DOD to weaponize the vulnerability
             | for their own use as well.
        
               | j16sdiz wrote:
               | CVE Numbering Authorities (CNA) have lots of control over
               | those.
        
               | derektank wrote:
               | This contract is funded by CISA, which is an agency
               | within the Department of Homeland Security, not DoD. As
               | far as I'm aware, there are no components of DHS with
               | Title 10 or Title 50 authorities to conduct cyber
               | operations, unless you count the Coast Guard but they
               | normally operate under Title 14. So there really should
               | be no conflicts of interest as no one in the DHS is
               | authorized to exploit vulnerabilities as part of cyber
               | operations.
        
             | tylermw wrote:
             | MITRE is a Federally Funded Research and Development Center
             | (FFRDC), which is a distinct type of federal contractor
             | with strict conflict of interest regulations. They are
             | owned by the federal government, but operated by
             | contractors and are specifically structured and regulated
             | to minimize conflicts of interest, so are distinct from
             | "private industry" in many regards.
             | 
             | You can read a congressional report by the CRS describing
             | FFRDCs and their role here: https://www.congress.gov/crs-
             | product/R44629.
        
               | guerrilla wrote:
               | They were talking about AFTER that when it is privatized.
               | That's what the comment they're responding to was talking
               | about, not it's current state.
        
               | stonogo wrote:
               | MITRE is absolutely not an FFRDC. It's a regular old
               | 501(c)(3) which happens to _manage_ FFRDCs.
        
             | derefr wrote:
             | I'm the opposite -- and I think this might be the "4D
             | chess"+ interpretation of this move as well.
             | 
             | In peacetime, I think everyone is generally alright with
             | something centralized like the CVE database.
             | 
             | But in what increasingly seems like _the lead-up to
             | wartime_... I 'm hesitant to trust a CVE database operated
             | _or funded_ unilaterally by a single government -- or even
             | multilaterally, if the governments are all ones that all
             | would end up on the same side of a hot war.
             | 
             | (Why? Strategic censorship of reports while the DB's patron
             | takes advantage of the exploit, for one. Such a database
             | becoming a high-priority cyberwar target, for another.
             | Strategic wasting of enemy cybersecurity resources with
             | false announcements, for a third.)
             | 
             | IMHO, the ideal form for the organization managing CVE, is
             | one analogous to IANA and its Regional Internet Registries
             | (RIRs).
             | 
             | IANA slices up the keyspace of IPs to assign to RIRs, and
             | arbitrates disputes -- but both at such a high level that
             | their work is effectively in a de-facto state of "done
             | until something comes up". The RIRs do all the actual
             | everyday work.
             | 
             | This means that in a hot war that different RIRs end up on
             | opposing sides of, where at least some of the RIRs can no
             | longer trust the ownership of IANA to act in their best
             | interests, the RIRs can just ignore IANA for a while, and
             | keep on doing their own thing (managing allocations from
             | their previously-agreed parts of the IP keyspace), and
             | everything will still work.
             | 
             | And RIRs that control parts of IP space contended over by
             | opposed states? They can just be split up, under obvious
             | rules (every current allocation goes to the sub-RIR
             | associated with the state that controls the
             | gov/mil/corp/org entity currently holding that allocation.)
             | 
             | That's not the case with the CVE database under its current
             | ownership. There's no established way to namespace it, no
             | obvious way to split it up and keep it all working.
             | 
             | And I think that this problem would be obvious to the DoD.
             | Which is precisely why paying to host a single-source-of-
             | truth CVE database loses its lustre when that same DoD is
             | aware that such a split _might_ soon have to happen.
             | 
             | ---
             | 
             | + I dislike the term "4D chess", because it implies one
             | chess master who's really good at predicting non-obvious
             | outcomes -- rather than an entire military-industrial-
             | complex acting as "see something, say something" inputs to
             | an intelligence apparatus that does a lot of hard work and
             | simulation analyzing potential outcomes, to produce easily-
             | digested suggestions and action items. There just needs to
             | be _one guy_ in the Pentagon  / the military / wherever,
             | who realized this and sent a (classified MILNET) email
             | about it.
        
           | numbsafari wrote:
           | ... and that industry led consortium will have a board all
           | paid princely sums, and an executive leadership team that is
           | conflicted to the hilt and paid kingly sums, and they will
           | charge exorbitant rents in order to keep the lighthouse lit.
           | 
           | There's flaws with every approach, but I much prefer the
           | approach where this sort of thing is treated as a public
           | good, rather than as yet another soon-to-be walled garden.
        
             | bunderbunder wrote:
             | I keep thinking of that time Wisconsin's state government
             | privatized a bunch of IT stuff in the interest of
             | "government efficiency", and the cost taxpayers paid for
             | those specific functions increased by several hundred
             | percent while quality of service went down.
             | 
             | At that same time, though, I worked for a contractor that I
             | do believe saved states money compared to doing things in-
             | house. The work we did really required specialists. But no
             | one state had enough of the work to keep one busy all year.
             | So sharing a pool of people to do the work among many
             | states meant there was room for both saving the states
             | money and allowing some profit for the company.
             | 
             | The idea that you can just blanket assume that private
             | industry is inherently more efficient than public works
             | really needs to die. There doesn't seem to be any more
             | evidence to support it than there is to support the idea
             | that it's inherently _less_ efficient. Life just isn 't
             | that simple. It's all case by case.
        
               | dimitrios1 wrote:
               | For every example of privatization going wrong, there's
               | least one example (if not two) of it going right.
               | 
               | But serious question -- what is the difference these days
               | anyways? Our entire government is effectively privatized
               | anyways from the local level up to the federal. We rely
               | on contractors for almost everything that matters. We
               | just maintain this facade that they are not privatized.
        
               | sollewitt wrote:
               | I've never seen one that worked long term. The basic
               | premise is "what was done for $X dollars with no profit
               | motive can be done for <$X dollars with profit motive
               | doesn't hold up - you make something private, it wants to
               | make more profit.
               | 
               | Just for the most ready to hand example for me, PG&E in
               | SF vs public electricity utilities on the peninsula - the
               | privatized electricity costs twice as much per kWh - and
               | of course it does because the PG&E CEO needs to make $17M
               | from somewhere, the share price needs to go up etc. the
               | rich need to skim from the top, that makes the cost
               | higher.
               | 
               | If you have an essential industry the cynical play is to
               | privatize to save cost, then do a bad job and then
               | effectively make your losses public through bail-outs
               | while still making profit.
        
               | derektank wrote:
               | >The basic premise is "what was done for $X dollars with
               | no profit motive can be done for <$X dollars with profit
               | motive doesn't hold up - you make something private, it
               | wants to make more profit.
               | 
               | No, the basic premise of privatization is that, assuming
               | the product or service has multiple potential customers,
               | private industry can operate at scale which, alongside
               | competition from other companies, drives down the price
               | and the government can purchase it "off the shelf" at the
               | prevailing commercial rate. Those assumptions don't
               | always hold, utilities being a great example of this, but
               | it's not inherently blind or naive to consider
               | privatizing some components of government function. We
               | don't expect the government to operate its own vehicle
               | assembly lines even if the government needs cars; they
               | just go buy one from Ford or GM.
        
               | bunderbunder wrote:
               | I'd add that that, for this calculus to work out in a
               | straightforward way, a competitive market is necessary
               | but not sufficient. You also need other factors that help
               | drive economies of scale, such as the thing in question
               | being a manufactured good that can be sold to many
               | people, or the production requiring expensive and
               | specialized equipment that can be used for more than just
               | that one thing.
               | 
               | I'm no expert, but I'd guess that these factors are more
               | likely to line up in manufacturing and construction, or
               | even R&D, than they are for things like maintenance of
               | specialized IT systems or administration of services.
        
               | sollewitt wrote:
               | Answer for your serious question: hiring contractors
               | isn't "privatized" - that's outsourcing. The thing you're
               | saving on is the ongoing cost of having permanent staff.
               | 
               | The difference is the government and public entities like
               | mayoral offices or parliaments get to decide how the
               | entity (doing the contracting) is run and approve costs,
               | and the entity is under no obligation to return a profit.
        
               | taeric wrote:
               | Would love to see a list on both sides. It is easy to win
               | an argument when you get to gesture at evidence without
               | being specific.
               | 
               | For your question, the difference is if a government
               | spend succeeds, it should lead to more things that the
               | people can do. If a private company succeeds, it largely
               | funds just the company.
               | 
               | And, ideally, it should be fine that both the
               | government/nation gets benefits while rewarding
               | successful contractors. Nothing wrong with that.
               | 
               | This is hilariously viewable with Musk. People love to
               | point out how he risked so much on Tesla. Ignoring all of
               | the capital that the government risked in the same
               | venture.
        
               | dimitrios1 wrote:
               | I am not here to argue for a "side", to win an argument,
               | nor provide a thesis defense with citation and references
               | -- this is an answer you can easily get from ChatGPT.
               | There's quite literally hundreds.
               | 
               | To add a wrench to both "sides" some of the most
               | effective have been state/federal-owned /state/federal
               | controlled corporations -- or generally, arrangements
               | where you still maintain capitalistic economic incentives
               | and drivers, but have government oversight and
               | (effective) regulation. I think everyone would that is
               | good, but sometimes it takes different forms.
        
           | jmull wrote:
           | > The long-term goal seems to be...
           | 
           | Where do you get that from?
           | 
           | I've seen no sign of long-term goals, much less any
           | mechanisms being put in place for follow-through on those
           | goals.
           | 
           | It seems like people keep making the mistake of believing
           | there's a detailed plan, while all evidence tells us there
           | isn't. I guess it's the normal human tendency to see order in
           | the chaos.
        
             | tlogan wrote:
             | Project 2025 lays out a clear vision for the privatization
             | and decentralization of federal functions. It's not subtle
             | --it explicitly calls for it.
             | 
             | Separate from whether we support this or not:
             | 
             | Trump is doing--or promising to do--exactly what he said he
             | would. We can disagree with the policies, but it's not
             | accurate to say he or his team are directionless or
             | incompetent. They have a coherent (if controversial)
             | agenda.
             | 
             | So rather than dismissing them as clueless or idiots, it's
             | more productive to debate this:
             | 
             | - Why is outsourcing CVE program to private consortia a bad
             | idea?
             | 
             | - Could a model exist where a private consortium is
             | supported by federal grants, but maintains accountability
             | and public interest safeguards?
        
               | chowchowchow wrote:
               | Actually Trump repeatedly said he didn't know about
               | project 2025. He's so scattered in his campaigning that
               | it's possible to pretty much justify any action as "what
               | he said he would do." But saying executing project 2025
               | is exactly what he SAID he would do defies all reality.
               | It may be what intelligent observers expected him to do
               | but it is not what he said.
               | 
               | Edit: good lord people I'm not defending Trump I'm saying
               | he lies about everything including that he lied and said
               | he wasn't going to do project 2025. Read the post I'm
               | responding to!
        
               | pstuart wrote:
               | > Actually Trump repeatedly said he didn't know about
               | project 2025                 * He said he'd end the war
               | in a day.       * He said he had a better health care
               | plan.       * He said he'd drop the price of eggs.
               | * ...       * He said lots of things that were not true.
        
               | chowchowchow wrote:
               | That's exactly right and what I said. The guy above said
               | Trump is doing what he said he would. He isn't.
        
               | sigzero wrote:
               | Which doesn't mean Trump saying he has nothing to do with
               | Project 2025 a lie.
        
               | pstuart wrote:
               | I've never been in the room, but it's a safe assumption
               | that he was lying.
        
               | ranger_danger wrote:
               | _Someone_ is clearly pushing that agenda whether it 's
               | (knowingly) Trump or not.
               | 
               | Project 2025 is 42% complete, 3 months in.
               | 
               | https://www.project2025.observer/
        
               | SlightlyLeftPad wrote:
               | People have got to learn how to read between the lines
               | with Trump and those around him. When the things he says
               | he is going to do and the things he's actually doing are
               | exactly the things laid out in project 2025, the
               | connection to the project is immediately clear and
               | establishes that he was lying about knowing nothing about
               | it.
        
               | chowchowchow wrote:
               | Obviously
        
               | jmull wrote:
               | Trump said he was _not_ going to follow the project 2025
               | plan.
               | 
               | So you're making two immediately contradictory claims
               | that Trump is doing what he said he would, and is
               | following the project 2025 plan. That's not coherent.
               | 
               | You're suggesting a privatization plan exists, and want
               | to debate its merits, but I see no sign such a plan is
               | being adopted. E.g. who is enacting the plan? When is the
               | comment period? Who do we send our feedback to? _You_ may
               | have a plan, but what does that have to do with the
               | people in charge? If it 's not their plan it doesn't
               | matter one bit. Despite your assurances, I see no sign
               | they aren't acting without a plan (or, as you put, as
               | clueless idiots).
        
               | acdha wrote:
               | > Trump said he was not going to follow the project 2025
               | plan.
               | 
               | He didn't convincingly reject it, though, and his
               | distancing was only convincing to people who were looking
               | for an excuse to ignore it with the way he pretended not
               | to know the people behind it when 31 of the 38 authors
               | were members of his first administration, his campaign
               | was in close contact throughout, and he certainly didn't
               | put much effort into rejecting specific policy proposals.
               | 
               | I think this is a case where different audiences got
               | different messages. The hardcore base knew he was lying
               | since it had all of their red meat issues, informed
               | Democrats knew he was lying because actions speak louder
               | than vague denials (e.g. if you don't agree with
               | someone's policies, you wouldn't let them have a role in
               | your campaign and you'd be able to say what you'd do
               | differently), but he gave the media and casual voters
               | just enough to make it harder for Biden/Harris to land
               | attacks which we now know were fully accurate.
        
               | jmull wrote:
               | Yes, he was obviously lying, as he has done about so many
               | things.
               | 
               | Well, it's obvious to some us, anyway.
        
               | danaris wrote:
               | There seems to be a lot of hay being made over whether
               | Trump is
               | 
               | - deliberately following Project 2025 to the letter, or
               | 
               | - completely ignorant of Project 2025 and not doing what
               | it says
               | 
               | ...when it seems _very_ likely that the truth is
               | somewhere between.
               | 
               | Trump himself is doing things the way he always does: in
               | a mixture of long-standing bigotry and idiocy, his own
               | whims, and whatever someone said to him 10 minutes ago
               | (or he saw on Fox & Friends, or whatever).
               | 
               | His _administration_ is heavily populated with people who
               | either helped write Project 2025 or are close with those
               | who did.
               | 
               | DOGE is only loosely connected with the latter, and it's
               | DOGE that has been instrumental in wrecking federal
               | agencies--and while that destruction largely aligns with
               | Project 2025's goals, it's not clear to me that they're
               | _specifically_ following its playbook. Rather, I think
               | they 're doing things their own way with high-level
               | guidance from the people who care about Project 2025.
               | It's very possible that their goals could end up
               | conflicting, depending on what Musk wants.
               | 
               | Edit to add: It's also true that Trump said he knew
               | nothing about Project 2025. Whether or not this is true,
               | he said it _during the campaign_ , when Project 2025 had
               | just been widely reported on as a negative thing. I don't
               | think we can read much into Trump's campaign statements
               | intended to publicly distance himself from something he
               | sees as unpopular.
        
               | nrdvana wrote:
               | In most of the video clips I saw, he was saying "I don't
               | know anything about that", which could be entirely true.
               | Often I see hints that he's attempting to play the Aes
               | Sedai game of "speak no word that is untrue" but he's too
               | dumb to do it well. Anyway, as an extension, both
               | comments can be true, that Trump himself has no plan and
               | is an idiot, but that his administration is enacting
               | Project 2025.
        
           | agloe_dreams wrote:
           | > Having the CVE program operated by a company funded by the
           | U.S. military
           | 
           | ...Yep, we're done as a democracy. Pack it up, boys.
           | 
           | Edit: I know it is doom and gloom but the CVE program could
           | easily delay information and leave holes on purpose.
        
           | absker wrote:
           | MITRE is a non-profit company that operates Federally Funded
           | Research and Development Centers (FFRDCs), which are owned
           | and funded by the federal government and contracted out to
           | companies like MITRE to operate them.
           | 
           | While MITRE does have contracts with DoD (and many other
           | agencies across the federal government as part of the FFRDCs
           | they operate), they are not the same as a stereotypical DoD
           | contractor as their non-profit status motivates them to work
           | in the public interest.
        
           | jhelps wrote:
           | I can see how govt funding was needed to help bootstrap the
           | CVE program before people saw the value of it.
           | 
           | But now that CVEs form the basis of a very lucrative
           | ~$16b/year industry[0], wouldn't it make sense to let those
           | companies take over?
           | 
           | Privatizing the Internet enabled much more innovation than if
           | it had stayed govt-funded.
           | 
           | 0: https://www.grandviewresearch.com/industry-
           | analysis/security...
        
           | butterlover wrote:
           | It's probably more accurate to describe mitre as a publicly
           | funded non profit operating for public benefit like the post
           | office or PBS.
           | 
           | It's a stretch to describe it as an arm of the government.
        
         | lynndotpy wrote:
         | This is good news, but in general. We can not rely on the DoD
         | to make smart decisions.
         | 
         | Ultimately, Pete Hegseth, with a career as a Fox News
         | character, calls the shot.
        
           | EgregiousCube wrote:
           | A bit disingenuous; he also had a career as a soldier.
        
             | lynndotpy wrote:
             | Ok, and he is not someone you should rely on to make
             | exclusively good decisions.
        
             | bclemens wrote:
             | Of course! It's easy to forget he was a guard at one of
             | America's most notorious concentration camps, Guantanamo
             | Bay. It's foolish to think of him only as a Fox News
             | personality.
        
               | typesarecool wrote:
               | Not defending him as a person, but he earned a bronze
               | star serving in Iraq.
        
               | boston_clone wrote:
               | Bronze stars without a V device are automatically awarded
               | to O3s / O4s for a deployment. Knowing that, it sounds
               | like you're defending him as a person.
        
               | SV_BubbleTime wrote:
               | If you are interested in facts, as a uniformed officer,
               | Hegseth held a higher rank than anyone in Obama's
               | cabinet.
        
               | boston_clone wrote:
               | can you image that? people will just go on the internet
               | and _lie_?
               | 
               | https://en.wikipedia.org/wiki/Eric_Shinseki
        
             | KineticLensman wrote:
             | There is a massive difference between having a career as a
             | soldier and knowing how to lead one of the world's largest
             | organisations (the DOD)
        
           | plasma_beam wrote:
           | This is DHS, not DOD.
        
             | lynndotpy wrote:
             | Yes, I was responding to someone who was talking about the
             | DoD. Noem is likewise not someone I would depend on to make
             | good decisions.
        
         | plasma_beam wrote:
         | It doesn't appear to have posted to FPDS yet:
         | https://www.fpds.gov/ezsearch/fpdsportal?q=PIID%3A%2270RCSJ2...
         | 
         | The contract expired today, but had an option period through
         | March of 2026. DHS just needed to exercise the option.
         | 
         | Edit: Note the contract ended today April 16 - so performance
         | would stop midnight tonight if the option wasn't exercised.
         | Government contracts routinely go down to the wire like this,
         | and often are late getting exercised. Why the uproar over this
         | one? Did CISA signal to MITRE that they weren't going to
         | exercise the option?
        
           | marcusb wrote:
           | > Did CISA signal to MITRE that they weren't going to
           | exercise the option?
           | 
           | An internal letter sent to CVE board members was making the
           | rounds yesterday warning the current contract ("contracting
           | pathway") would expire. The letter was authenticated by Brian
           | Krebs[0]. Once Krebs authenticated the letter, people more or
           | less assumed CISA was pulling funding, at least based on the
           | infosec social media posts I saw.
           | 
           | CISA officials responded to multiple media inquiries
           | (including the OP) with a statement that more directly said
           | the contract _would expire_ :                 Although CISA's
           | contract with the MITRE Corporation will lapse after April
           | 16, we are urgently working to mitigate impact and to
           | maintain CVE services on which global stakeholders rely.[1]
           | 
           | 0 - https://krebsonsecurity.com/2025/04/funding-expires-for-
           | key-...
           | 
           | 1 - https://www.csoonline.com/article/3963190/cve-program-
           | faces-...
        
         | andreygrehov wrote:
         | But the article says, quote:
         | 
         | > It's unclear what led to DHS's decision to end the contract
         | after 25 years
         | 
         | and then suddenly it gets extended. What does it have to do
         | with DOGE?
        
           | marcusb wrote:
           | MITRE has been hit with DOGE-branded cuts[0] earlier this
           | month. CISA has been impacted[1]. It seems reasonable to
           | assume they were involved in this.
           | 
           | 0 - https://virginiabusiness.com/nova-govcon-firm-mitre-to-
           | lay-o...
           | 
           | 1 - https://techcrunch.com/2025/03/11/doge-axes-cisa-red-
           | team-st...
        
             | andreygrehov wrote:
             | That's a pretty big leap. Ending a 25-year contract and
             | laying off ~600 employees are two very different scales of
             | impact. While DOGE-related cuts might have influenced some
             | decisions, assuming they directly caused DHS to initially
             | let the CVE contract lapse seems like a stretch. Just
             | because two things happen near each other doesn't mean one
             | caused the other - this feels more like another chance to
             | take a swing at DOGE, since that's the bandwagon everyone's
             | riding right now.
        
       | hatly22 wrote:
       | Maybe Europe should charge the US for access to their CVE
       | databases.
        
       | jovial_cavalier wrote:
       | I didn't realize that CVE was funded by the DHS. Isn't it better
       | for it to be independent and not funded by an intelligence
       | agency?
       | 
       | It's enough of a public good to have a common advisory for
       | vulnerabilities that FAANG should just kick it a few million a
       | year. How much can it possibly cost to run this anyway?
        
       | trothamel wrote:
       | Does anyone know what the CVE program was costing per year? I
       | searched around a bit, but wasn't able to find the number.
        
       | m4r71n wrote:
       | The title of this article is simply false. The CVE Program is a
       | separate entity from MITRE and is most definitely not ending. The
       | CVE Program has been acquiring assets from MITRE for years now.
       | That is why the main site shifted from cve.mitre.org to cve.org.
       | MITRE has always simply been the workhorse of the program, and
       | now that is being shifted to others (CVE foundation, which has
       | global representation).
        
       | gcollard- wrote:
       | Forget everything you know and consider that it might be a
       | misguided and risky negotiation tactic.
       | 
       | Disclaimer: This is not business advice and should be read using
       | Cartman's voice.
       | 
       | Step 1: Announce publicly that you are not renewing your
       | contract.
       | 
       | Step 2: If the market has viable alternatives or the service you
       | are negotiating isn't that hard to replicate, other actors will
       | manifest to fill in the gaps, especially if your business is
       | attractive. (E.g., The top comment is building an alternative;
       | other comments point to alternative services.)
       | 
       | Step 3: Congratulations, you now have leverage for a significant
       | discount with your previous provider because they face the real
       | prospect of losing your business entirely to a competitor. If the
       | competitor is private, you can even double dip by investing in
       | their company before attributing them the contract.
        
         | Aperocky wrote:
         | There's always a cost even if there doesn't seem to be one,
         | credibility is measurable in markets and when it bite I think
         | we'll all be in rough times.
        
       | ThinkBeat wrote:
       | There seems to be little reason for the US government to pay for
       | this since it is vital information that a lot of companies rely
       | upon.
       | 
       | Some form of a foundation or NGO could be given a reasonable
       | endowment from the industry to operate the CVE program.
       | 
       | O am quite hesitant to trust the DOD to keep track of software
       | vulnerabilities. Some parts are developing and exploiting
       | vulnerabilities. And given a fresh feed of what people find, and
       | usually a delay from notification until publication, which may
       | sometimes just be a bit longer of a delay, would allow the DOD to
       | weaponize the vulnerability for their own use as well.
        
       | froggertoaster wrote:
       | Believe me when I say that DOGE is filled with smart people (I
       | know a few of them).
       | 
       | Just because they're scattershot cutting doesn't mean they're
       | stupid.
        
         | raegis wrote:
         | I guess I'm naive, but given the current situation, wouldn't a
         | smart person resign from DOGE? If I were smart and highly
         | employable, like these guys, I would not want to be associated
         | with all the indiscriminate firings of DOGE.
        
           | froggertoaster wrote:
           | I guess it depends on what you value.
           | 
           | I think it speaks a lot about a person who assumes "a smart
           | person would resign from DOGE".
        
       | p0w3n3d wrote:
       | One man appears at one position and so many things stop working
       | in so little time
        
         | Alifatisk wrote:
         | Yet, he is still praised and cherished. I can't comprehend how.
        
       | RKFADU_UOFCCLEL wrote:
       | Including this as a prime example, the overall trend seems to be
       | that we're going back to the bad old days where a kid gets to
       | code the entire security infrastructure because the CEO thinks
       | he's smart and then the bugs are covered up with legal threats
       | (because they were able to mislead the courts), obfuscation,
       | while being easily discoverable by 3rd parties. Another example
       | is the way the bug bounty gimmick is run and most researchers
       | never disclose their findings nor are they patched in any
       | consistent manner, plus the companies threaten to sue you for
       | disclosing even if it's 100 years later.
        
       | blindriver wrote:
       | How much does CVE cost to maintain and why must the US fund the
       | entire thing?
        
         | manmal wrote:
         | The bureaucracy of internationalizing it would likely be more
         | expensive than the current cost.
        
       | andrehacker wrote:
       | Maybe change the headline now ? As-is the headline is click-
       | baity. (spoiler alert: the contract has been extended)
        
       | rbolla wrote:
       | Important update April 16, 2025: Since this story was first
       | published, CISA signed a contract extension that averts a
       | shutdown of the MITRE CVE program.
        
       ___________________________________________________________________
       (page generated 2025-04-16 17:01 UTC)