[HN Gopher] CVE program faces swift end after DHS fails to renew...
___________________________________________________________________
CVE program faces swift end after DHS fails to renew contract
Author : healsdata
Score : 1815 points
Date : 2025-04-16 01:57 UTC (15 hours ago)
(HTM) web link (www.csoonline.com)
(TXT) w3m dump (www.csoonline.com)
| bytematic wrote:
| What are the implications of this? No more centralized store of
| vulnerability information?
| neuronexmachina wrote:
| According to Brian Krebs:
| https://infosec.exchange/@briankrebs/114343835430587973
|
| > Hearing a bit more on this. Apparently it's up to the CVE
| board to decide what to do, but for now no new CVEs will be
| added after tomorrow. the CVE website will still be up.
| Incipient wrote:
| Basically when any software/library/whatever has a
| vulnerability, they have to communicate that out themselves, in
| some format.
|
| If I'm developing a product built on 20 libraries, it won't
| just be a matter of scanning CVEs for major vulnerabilities any
| more, so I'm more likely to miss one.
|
| "always update" doesn't always work, when to manage a product
| you realistically have to version pin.
| cantrecallmypwd wrote:
| They surprise is: they won't. This will weaken the West.
|
| This is dangerously stupid.
| t0lo wrote:
| This is deliberate. I just want to figure out the avenues
| of communication and coordination between trump admin and
| moscow so we can pin them down better.
| worthless-trash wrote:
| So, while arguably true, there wont be a single source of
| truth of new cve's. It doesn't however mean there wont be.
|
| I would imagine the only SANE option would be some kind of
| git repository where CNA's can collaborate. Probably run some
| code across to make the website that people can easily
| access.
|
| It's going to be a mess.
| joshuanapoli wrote:
| Is MITRE's CVE program redundant with NIST's National
| Vulnerability Database? I'm having a hard time telling how the
| two are related, or if NVD is simply performing the same service
| as MITRE.
| detaro wrote:
| NIST NVE relies on the CVE program. (vulnerabilities get
| reported, MITRE assigns CVEs and publishes them, NIST then
| copies that list and adds their own scoring etc to it)
| Spooky23 wrote:
| Once they fire everyone at NIST, they'll have that in common.
| Rebelgecko wrote:
| I'm trying to steelman but I really can't think of a non-
| nefarious justification for this
| sneak wrote:
| We don't need to spend tax dollars to increment sequential
| integers.
|
| The "CVE program" can be done by a volunteer or two in spare
| time. It's not some major operation, it's just a registry of
| integers that can live on GitHub.
| viraptor wrote:
| Yet so far no volunteer has emerged and people who do run CNA
| are pretty busy with it.
| _zer0 wrote:
| I think sneak would volunteer to do it since it is pretty
| simple according to them.
| mlinhares wrote:
| Any work people don't understand must be easy and
| replaceable by chatgpt. Just look at how easy people here
| think farming is.
| johnnyjeans wrote:
| Grok becoming an artificial nepobaby running the entire
| CVE program with zero oversight sounds so fucking funny I
| don't even care, PLEASE god make this real holy shit I
| can't breathe at the thought
| stevekemp wrote:
| There were some, short-lived, projects/groups trying to run
| their own processes. DWF is one that I recall, though it is
| dead again:
|
| https://lwn.net/Articles/851849/
| Rebelgecko wrote:
| How do you get your volunteers in the first place and manage
| them so you know it's time to get a new one if the quality of
| their work is slipping?
| skeledrew wrote:
| Who needs volunteers? Let AI handle it!
| fnordpiglet wrote:
| This is like saying the patent system is just an incrementing
| counter.
| sneak wrote:
| Have you seen the patents they have been giving out lately?
| gessha wrote:
| Found the blackhat
| _carbyau_ wrote:
| Thanks for volunteering to manage the "300-600 CVEs each
| month"!
|
| The world needs more volunteers like you.
| charcircuit wrote:
| You manage the system and not the CVEs themselves. The
| simplist thing would be a list of numbers that correspond
| to Google docs. The owner of the Google doc can share it
| with the needed parties and eventually set it as public.
| goku12 wrote:
| You truly believe that the CVE database (and others like
| CWE) are only about assigning serial numbers to random
| reports, don't you? I see people underestimating and
| understanding the work of others in matters like this. Is
| that a trend now?
| charcircuit wrote:
| No I don't believe that, but it might as well operate
| like that. The extra stuff isn't truly needed and was
| being outsourced to the companies that own the products
| since it wasn't providing much value. Take a look at
| Daniel's blog posts about CVEs for curl for what happens
| when you let them handle it.
| worthless-trash wrote:
| I saw this same behavior quite a while back. While I'm
| out of the CVE game these days, it seems that there is a
| forever rotating new group of people who simply don't and
| can never see the complexities on the process.
|
| I think it's a testament to the previous stewardship that
| it appears so simple.
| techky wrote:
| Make that 3,000-4,000 on average per month, according to
| NISTs stats on CVEs for last year. ~40,000 for 2024.
| JCharante wrote:
| I imagine most of those CVEs not being anything meaningful
| and just script kiddies trying to put something on their
| portfolio
|
| all the meaningful ones will show up on HN
| duxup wrote:
| The process seems to be to dismantle anything not nailed down
| in government.
|
| Now if you want that (even just funding) to be a thing ... you
| have to go through Trump & Co and pay your bribe to get it back
| up.
| esafak wrote:
| Privatize all teh things?
| benfortuna wrote:
| This neo-liberal approach has no place for soft diplomacy,
| which is what US hegemoney relies on.
|
| This isn't just a rapid disassembly of economic structures,
| any trust and goodwill is completely obliterated as well.
| tart-lemonade wrote:
| For decades, the US could be counted upon to fund things
| with little immediate benefit but massive long-term
| positive externalities. I don't think its likely that the
| republican party will "go back to normal" post-Trump, so we
| can all kiss the long-term reputation building that
| American hegemony relied upon goodbye. Short of a great
| depression-esque political reset, I do not see things
| changing for the better.
| transpute wrote:
| April 2024 article on the result of NVD funding cutbacks,
| with comments by Linux Foundation OpenSSF, security startups
| like ChainGuard and commercial vendors,
| https://www.securityweek.com/cve-and-nvd-a-weak-and-
| fracture... Threat intelligence firm
| Flashpoint noted in March 2024 it was aware of 100,000
| vulnerabilities with no CVE number and consequently no
| inclusion in NVD. More worryingly, it said that 330 of these
| vulnerabilities (with no CVE number) had been exploited in
| the wild.. Since the start of 2024 there have been a total of
| 6,171 total CVE IDs with only 3,625 being enriched by NVD.
| That leaves a gap of 2,546 (42%!) IDs.
|
| Despite all those private companies and various OSS projects
| being willing to contribute ideas, infrastructure and code,
| they have somehow failed to coalesce into a decentralized
| replacement for NVD, built on CC0 data and OSS tooling.
| cma wrote:
| I tried to look over the history and I only see a funding
| increase, CISA cut $3.7 million at the end of 2023 for the
| next year and in response NIST reallocated extra funding to
| NVD: $8.5 million in 2024
|
| A funding shortfall and strain isn't a funding cut. And
| from what I see there was a funding increase.
| transpute wrote:
| Would appreciate a pointer to the source, thank you.
|
| 2025 article claims 30% increase in 2024 workload,
| https://www.securityweek.com/mitre-signals-potential-cve-
| pro...
|
| _> According to NIST, while the National Vulnerability
| Database (NVD) is processing incoming CVEs at the same
| rate as before the slowdown in spring and early summer
| 2024, a 32 percent jump in submissions last year means
| that the backlog continues to grow._
| cma wrote:
| Can search these for the links
|
| 2023
|
| > CISA had previously been supporting the NIST NVD
| program with approximately $3.7 million per year in
| interagency funding, which they have discontinued
|
| 2024
|
| > While NIST has since reallocated $8.5 million to NVD
| for fiscal years 2024 and 2025
|
| Assuming that's spread over both years it wasn't as big
| of an increase as I said, but is still an increase even
| inflation adjusted.
|
| > 2025 article claims 30% increase in 2024 workload
|
| Underfunding in the face of more workload isn't itself a
| funding cut.
| transpute wrote:
| Thanks for the pointer. Is this a lobbying org? https://w
| ww.fdd.org/analysis/policy_briefs/2025/03/21/delaye...
|
| _> While NIST has since reallocated $8.5 million to NVD
| for fiscal years 2024 and 2025, this funding remains a
| fraction of the $300 million to $400 million estimated to
| be needed annually to fully restore capacity, with an
| additional $120 million to $150 million required to
| prevent further system "deterioration."_
|
| Did NVD receive 300MM annual funding pre-2024? That would
| be a 98% funding cut.
| formerly_proven wrote:
| 300 million would've been a quarter of the NIST budget.
| Doubt.
| transpute wrote:
| Yeah, bizarre site.
|
| MITRE CVE/CWE budget is more transparent than NVD since
| it's a contract, listed on USAspending.gov.
| giraffe_lady wrote:
| > I'm trying to steelman
|
| Why? This administration is not acting in good faith, you don't
| have to act as if they are. People and institutions doing that
| is part of how we got here in the first place.
| jfengel wrote:
| Force of habit. We don't have a framework for talking under
| these circumstances, so we apply our outdated ones.
|
| As you say, that's exactly what got us here. But the
| alternatives are very unclear, and seem deeply unpleasant.
| MiguelX413 wrote:
| People should suck it up and not do it again.
| jfengel wrote:
| The question is what they should do instead.
|
| They could attack the non-steelmanned version, but that
| just opens them up to having their own comments attacked.
| You quickly get derailed. (It's sometimes called
| "sealioning".)
|
| They could propose alternatives, but that too is subject
| to sealioning. Real alternatives are always subject to
| tradeoffs, and the answer to "how about you do X instead
| of attacking me?" is always "no".
|
| They could refrain from discussing it, but that just
| allows the offenses to continue.
|
| So what often happens is that people persist in acting as
| if this were a sincere discussion, and hope that a
| majority will recognize the quality of your argument.
| It's a lousy plan but I don't have much else to suggest.
| King-Aaron wrote:
| I still find it wild that so many people are trying to frame
| these decisions through a political lens. This is the actions
| of a foreign bad actor dismantling critical institutions from
| within, not "bad policy".
|
| Surely there's an antibody response.
| inejge wrote:
| > I still find it wild that so many people are trying to
| frame these decisions through a political lens.
|
| Why? The decisions are pretty well politically aligned with
| the ideology which detests the size and scope of the
| government (realistically, those aspects which the
| ideologues feel are not in their interest). What _is_
| unexpected is the swiftness and the brutality of action,
| but revolutions tend to be messy, and make no mistake, this
| is a revolution.
|
| > This is the actions of a foreign bad actor
|
| Now _this_ sounds like a coping strategy: everything is so
| preposterous it couldn 't possibly be homegrown. Foreign
| influence and underhanded actions are as old as human
| interactions, but IMO outright plants can't succeed without
| a massive economic and power asymmetry between the
| adversaries.
| King-Aaron wrote:
| lol, coping strategy? I'm not American and have no reason
| to 'cope' with anything. There is enough evidence to make
| a strong allegation about Trump being a Russian asset.
|
| The entire world seems to be able to 'cope' with that
| assessment.
| rat87 wrote:
| They are not. Trump is no libertarian or small government
| guy. The build the wall guy is the opposite of that. Even
| with stuff like social security he usually at least
| rhetorically claimed to be for more benifits (as long as
| it goes to "real Americans") and he is all for increasing
| police and military spending. And generally spending more
| on stuff that gives him money. Plus giant tax increases
| (tarrifs). He doesn't care much if government is
| dismembered as long as it owns the libs and gets rid of
| the public corruption prosecutors/others who might stand
| up to him
|
| Trump's actions towards Putin are highly irrational.
| Maybe he's being blackmailed, maybe he's being bought,
| maybe he just has likes Putins style but there is a
| reason people suspect him despite it being unlikely in
| the general case.
| King-Aaron wrote:
| > He doesn't care much if government is dismembered
|
| This is exactly the process that conservatives take to
| privatise services into their own friends pockets.
| Destroy services until they're ineffective and use it as
| an excuse to privatise it.
|
| There's no such thing as small government, only large
| sprawling private services that the government hands
| money to.
| almostgotcaught wrote:
| Imagine being eaten alive by a cackling hyena that ambushed
| you and all the while being like "hmm what is the appropriate
| steelman here? why do I deserve this? why is this just?"
|
| In reality this would never happen so all these people
| playing steelman are just detached/insulated.
| petesergeant wrote:
| >> I'm trying to steelman
|
| > Why?
|
| It's a sensible practice and good practice
| giraffe_lady wrote:
| I just don't see how it is _universally_ so, frankly. As a
| general guideline sure but some discernment is necessary
| nothing is gained from steelmanning apartheid or the third
| reich or torture prisons or or you see my point I hope.
| petesergeant wrote:
| How can you argue effectively against something if you
| don't understand the strongest version of the argument
| _for_ it?
| giraffe_lady wrote:
| We're way past the point of policy disagreements the
| relevant question right now is _how do you stop them_. It
| 's certainly not by reimagining your adversary's actions
| in the most charitable light.
| emmelaich wrote:
| It is the belief that it is not in good faith that makes it
| _more_ important that you try to steelman it.
|
| If the steelmanning fails then you can you can be even more
| confident that it is in bad faith.
| rqtwteye wrote:
| I think it's ignorance and arrogance. The US seems to be on a
| path to lose technological and science leadership. The current
| leadership doesn't seem to understand things that aren't
| flashy. I wonder when they'll dial back on food safety. I am
| sure RFK knows some vitamins that protect against salmonella
| johnnyjeans wrote:
| important to note: the US's food safety is already really
| bad. salmonella isn't a thing you have to worry about in
| first world countries. can't wait to see what plague demon
| spawns out of a food industry running amok after the FDA gets
| gutted.
| ac29 wrote:
| > important to note: the US's food safety is already really
| bad. salmonella isn't a thing you have to worry about in
| first world countries.
|
| There were 65,000 cases of salmonellosis in the EU in the
| most recent data I could find (2022). Thats a lower per
| capita rate than the US, but definitely not zero.
| rickard wrote:
| I agree that it's not zero, but according to CDC, the US
| sees about 1.35 million cases per year in a population of
| about 346 million, which is about 390 cases per 100,000
| people. Your figure for the EU over a population of 447
| million in 2022 gives 14.5 cases per 100,000 people, or
| more than a factor of 26 less.
|
| Being 26 times less worried about something translates,
| at least for most things, for me, to not being worried
| about it any more.
| WrongAssumption wrote:
| That's just not true.
|
| https://www.npr.org/sections/shots-health-
| news/2025/04/15/nx...
| jjmarr wrote:
| At least American chicken is chlorinated:
|
| https://www.npr.org/sections/shots-health-
| news/2025/04/15/nx...
| WrongAssumption wrote:
| From the the very article you linked
|
| "The vast majority of chicken processed in the United
| States is not chilled in chlorine and hasn't been for
| quite a few years," says Dianna Bourassa, an applied
| poultry microbiologist at Auburn University, "So that's
| not the issue."
| buzer wrote:
| Salmonella and it causes are very regional in EU. Places
| like Finland have basically 0 cases of salmonella caused by
| domestic poultry products per year. If there salmonella is
| found from any chicken in the flock, the whole flock will
| be quarantined and generally fully slaughtered (meat & eggs
| must be pasteurized after the slaughter if they are sold).
| In 2023 0.1% of the tested flocks had salmonella.
|
| According to
| https://pmc.ncbi.nlm.nih.gov/articles/PMC11945640/ most of
| the outbreaks in humans (where exact cause was found) were
| caused by foreign vegetables.
|
| On other hand countries like Italy find positive samples
| from 27% of their flocks ( https://efsa.onlinelibrary.wiley
| .com/doi/epdf/10.2903/j.efsa... ). USA doesn't do testing
| at that level as far I understand, I only found that 8% of
| the tested chicken parts have salmonella
| (https://www.propublica.org/article/salmonella-chicken-
| usda-f...).
| senectus1 wrote:
| the guy is ultimate small gov. he wants to rip it out by the
| roots.
| dmix wrote:
| I don't think he's considered a small gov conservative. He
| increased spending last time and has continued so far this
| term. His tariffs are one of the biggest expansions in gov
| interference in modern history. They are also attempting to
| significantly expand executive power beyond even 9/11
| terrorism days.
| 01HNNWZ0MV43FF wrote:
| Small enough to fit in a uterus, big enough to kidnap and
| shoot citizens
| parrellel wrote:
| According to the radio this morning, they're currently
| working to close all the FDA branches that do food safety
| testing, so, good guess?
| polski-g wrote:
| We have a 2tn deficit. If Congress wants to fund this, they
| need to make it mandatory spending and raise taxes.
| toomuchtodo wrote:
| Or cut from $877B in defense spending instead?
|
| https://usafacts.org/government-spending/
| xphos wrote:
| Listen, I hate the debt, but we have an income problem, not
| a spending problem. The military looks like a waste, but it
| does more than build bombs i.e research etc.
|
| The issue we have is that republican every chance they get
| since the 1970s have cut taxes. And then blamed democrats
| for causing the deficits. We don't need smaller
| governments. We need a reasonable tax system that taxes
| people. It can be progressive like it was before we decided
| rich people just need it easier than poor people.
|
| Yes, I will pay more taxes sign me up, especially if they
| can finally fix the roads and fund research. The problem is
| my taxes as a middle-class person go up and rich people get
| a tax cut. It's stupid. I like water provided by government
| utilities, I like planes that don't crash into stuff
| because there are air traffic controllers. These things
| used to work because we paid for them. When you buy cheap
| you get cheap.
| dboreham wrote:
| Military also employs a bunch of people who otherwise
| would be poor. Also provides a gentrification path for a
| bunch of previously poor people extending throughout
| their lives.
| LPisGood wrote:
| Yes, a big part of the size is because the military is a
| massive and horrendously inefficient jobs, education,
| housing, and healthcare program.
| throitallaway wrote:
| Don't forget all the beak-wetting that happens along the
| way when signing contracts etc. That's where an actual
| difference could be made.
| matteotom wrote:
| Yeah republicans claim to want to run the government like
| a business, but the first thing a business should do when
| they have a deficit is raise revenue! And especially in
| the case of the US government, the the only barriers to
| doing that are self-imposed.
| viraptor wrote:
| That's a good idea to raise during the budget time or with
| some warning ahead of time. But even discussing the cost of
| CVE program itself is likely a waste of time and money. When
| trying to deal with 2tn deficit, looking at things that
| historically got ~$5M is just a distraction. And the lack of
| it may cost even more given how many existing
| agreements/contracts rely on cve to be a thing - maybe just
| in gov lawyers having to rewrite things.
| rgreek42 wrote:
| Selling bonds is not the same thing as a family budget being
| in the red. Either you know this and you're making this
| argument in bad faith, or you don't and, well...
| chris_wot wrote:
| Dear god, you don't just stop running government completely
| because you have a deficit.
| tootie wrote:
| This is an absolute pittance compared to the total budget.
| And considering the current administration wants a $4T tax
| cut they are not interested in trimming the deficit at all.
| throitallaway wrote:
| Yep, DOGE is a song and dance distraction. If they were
| serious about lowering the deficit they wouldn't have laid
| off ~12K IRS workers (whom show a 7x ROI per head.) They
| also wouldn't be asking to increase the military budget to
| $1 trillion per year. Trump has spent 1/3 of his days in
| office so far golfing; $30 million+ so far paid to Trump
| properties for the privilege of that. This is the biggest
| capture in US history and it's all out in the open.
| 01HNNWZ0MV43FF wrote:
| Republicans control Congress, this is bait
| alephnerd wrote:
| > I really can't think of a non- nefarious justification for
| this
|
| Tragedy of the commons - NVD and the CVE project havr been
| backlogged and facing funding issues for a couple years now,
| and most security vendors are either cagey about providing
| vulns in a timely manner (as it can reduce their own
| comparative advantage), or try upsell their own alternative
| risk prioritization scores.
|
| Every company will gladly use NVD and CVE data, but no one
| wants to subsidize it and help a competitor, especially in an
| industry as competitive as cybersecurity.
| WesternWind wrote:
| It's incredibly foolish. Whatever the justification is, it
| doesn't matter as much as the horrible outcome.
|
| This is one of those things the government does for the benefit
| of the whole.
| ajross wrote:
| _Probably_ the thinking goes that someone in the international
| community will step in. CVE is in practice a global registry
| for all, thus "Why should the USA Department of Homeland
| Security pay for all the freeloaders".
|
| Still shortsighted and stupid, but it's plausible this is
| intended as leverage to get someone else to pony up.
| Cthulhu_ wrote:
| Reduce government spending; since it's not actually a
| government organization (as far as I can tell, I never looked
| into it before), other organizations can fund it. How much goes
| into this organization a year anyway? I'm seeing a Mitre
| corporation that does lots of other stuff too that has a
| revenue of 2.2 billion a year.
|
| Multi-trillion-dollar companies benefit from and contribute to
| this system, surely they can spare 0.01% of their revenue to
| this bit of critical infrastruture?
| bert-ye wrote:
| > surely they can spare 0.01% of their revenue
|
| They would, if we made companies pay their taxes.
|
| Yes, you can also run such a system based on donations. But I
| personally think that such a system is important enough to be
| paid for by the government. When you run on donations, there
| will always be conflicts of interest and the risk of running
| out of funds.
|
| But yeah, Mitre being a private organization that was paid
| for by the government was a problem.
| terribleperson wrote:
| Yes, I'm sure corporations funding the CVE system would go
| wonderfully. "It would be best if we don't see any severe
| CVEs for our products this quarter, if you want our funding
| next quarter."
| kesor wrote:
| MITRE is a non-profit, it receives about $1.5B from the
| federal government, and another almost $2B from Virginia.
| karel-3d wrote:
| Reduce spending. Steelmanning (not actually believing this): it
| probably cost a lot for what is essentially a database, and can
| be done cheaply by private sector (Google, Microsoft).
| myko wrote:
| It's a dying empire, really nothing else to say. The USA led
| world order is over, we've voted ourselves out of it, and now
| need to learn how to deal with that.
| drstewart wrote:
| Wow! So who is leading the world order now (aka who is
| funding MITRE)?
| throw4847285 wrote:
| I'll admit this is a bugbear of mine, but I think this is the
| reason "steelmanning" is counterproductive.
|
| Steelmanning is a neologism that serves no purpose other than
| in-group signaling. There was already a perfectly acceptable
| term for the same concept, one with more nuance and a rich
| history: Charitability.
|
| The major difference is that charitability is about treating
| your interlocutor with respect. Steelmanning is about using
| one's own intellect to make your interlocutor's argument better
| than them. Because charitability is based on a concept of
| mutual respect, if somebody clearly doesn't respect you one
| iota, then why would you be charitable? Steelmanning tries to
| divorce the person from the argument, and is ironically both
| arrogant and naive.
| transpute wrote:
| If you work on OSS software on CVE management, then you already
| know that NVD funding reductions have been ongoing for more than
| a year.
|
| April 2024, https://nvd.nist.gov/general/news/nvd-program-
| transition-ann... NIST maintains the National
| Vulnerability Database (NVD).. This is a key piece of the
| nation's cybersecurity infrastructure. There is a growing backlog
| of vulnerabilities.. based on.. an increase in software and,
| therefore, vulnerabilities, as well as a change in interagency
| support.. We are also looking into longer-term solutions to this
| challenge, including the establishment of a consortium of
| industry, government, and other stakeholder organizations that
| can collaborate on research to improve the NVD.
|
| Sep 2024, Yocto Project, "An open letter to the CVE Project and
| CNAs", https://github.com/yoctoproject/cve-cna-open-
| letter/blob/mai...
|
| _> Security and vulnerability handling in software is of ever
| increasing importance. Recent events have adversely affected many
| project 's ability to identify and ensure these issues are
| addressed in a timely manner. This is extremely worrying.. Until
| recently many of us were relying not on the CVE project's data
| but on the NVD data that added that information._
|
| Five years ago (2019), I helped to organize a presentation by the
| CERT Director from Carnegie Mellon, who covered the CVE backlog
| and lack of resources, e.g. many reported vulnerabilities never
| even receive a CVE number. It has since averaged < 100 views per
| year, even as the queue increased and funding decreased,
| https://www.youtube.com/watch?v=WmC65VrnBPI
| kulahan wrote:
| What has been ongoing for more than a year?
|
| The funding appears to have been cut off today, and both of
| these comments seem to talk about continuing work and how
| important it is.
|
| Do you mean to say that some form of threat to the NVD has been
| around for over a year now? Just want to be sure I'm parsing
| correctly!
| transpute wrote:
| Yes, NVD funding cuts and a growing CVE backlog began in late
| 2023.
|
| May 2024, https://therecord.media/nist-database-backlog-
| growing-vulnch...
|
| _> Moving forward, cybersecurity companies will have to
| "fill the void" .. NVD said in April [2024] that it is
| "working to establish a consortium to address challenges in
| the NVD program and develop improved tools and methods." ..
| CISA acknowledged the concerns and outrage of the security
| community and said it is starting an enrichment effort called
| "Vulnrichment, " which will add much of the information
| described by Garrity to CVEs._
|
| The second VulnCon event took place last week and no silver
| bullet has appeared,
| https://ygreky.com/2025/04/vulncon-2025-impressions/
| Vulnerability enrichment was mentioned in many talks.
| However, most organizations seem to handle it internally.
| There doesn't appear to be momentum toward a shared or open
| source solution - at least not yet.
| cma wrote:
| That says nothing about a funding cut, see my comment below
| transpute wrote:
| Following your comment's reference leads to a claim of
| NVD needing 300 to 550 million (?!) per year, but only
| receiving 4 million in funding. If anyone has pre-2024
| data on NVD or MITRE CVE funding, that would be helpful,
| https://news.ycombinator.com/item?id=43701532
| cowpig wrote:
| I've noticed that there's a post like this in most articles on
| HN that could be construed as negative for the current
| administration: some vague false statement followed by either a
| factually incorrect explanation or some quote that does not
| support the statement.
| transpute wrote:
| What is incorrect about the post above? There are citations
| from multiple reputable news outlets for each claim.
|
| People who actually work with CVEs have been posting about
| this problem on HN for 18 months.
| cowpig wrote:
| Your post has now been edited to be factually correct. But
| the misleading implication that this abrupt cut is part of
| some other cuts that started before remains.
| transpute wrote:
| The post (currently AND previous to comments being moved
| here from a different HN thread) links to the official
| _2024_ (not 2025) statement about NVD cutbacks. Here's a
| 3000 word article with quotes from Linux Foundation and
| commercial vendors, around the same time,
| https://news.ycombinator.com/item?id=43700884
| RVuRnvbM2e wrote:
| NVD != CVE
| transpute wrote:
| NIST owns the budget for both NVD and CVE, contracting
| MITRE to operate the CVE program.
|
| NIST budget was cut 12% in FY 2024 (Oct 2023 - Sep 2024).
|
| An earlier bill to supplement NIST funding has been
| reintroduced in 2025, https://fedscoop.com/public-
| private-partnerships-bill-nist-h...
| Larrikin wrote:
| Anyone that silently edits their posts after being called
| out for misleading statements or lies is arguing in bad
| faith.
|
| If you still have a cached copy of their original post
| you should publicly edit your earliest reply with their
| original quote.
| flanked-evergl wrote:
| Why do you post this on a comment that is neither of those
| things then?
| matthewdgreen wrote:
| I did find this post to be non-helpful and confusing. It would
| be helpful to edit it (or write differently in the future) to
| clarify that the sudden defunding event occurring today is
| separate and not related to the previous funding cuts. If
| that's the case.
| transpute wrote:
| Is there no connection between 2025 funding cuts and previous
| ones? e.g. If a year of work after the previous cuts resulted
| in an open-data collaboration between NVD and commercial
| vendors to share a subset of CC0 vulnerability metadata,
| could that industry collective now argue for government to
| share (with companies) the burden of funding an open,
| decentralized program for CVE tracking? Commercial vendors
| could still offer additional metadata and analytics, over and
| above the public baseline.
|
| Edit_1: found a proposed bill, April 2025,
| https://fedscoop.com/public-private-partnerships-bill-
| nist-h...
|
| _> A bipartisan bill that would establish a nonprofit
| foundation aimed at boosting private-sector partnerships at
| the National Institute of Standards and Technology was
| reintroduced in the House and the Senate.. the proposed
| foundation structure was described as replicating similar
| nonprofits that support public-private partnerships at other
| science agencies.. we encourage a strategy that leverages
| NIST's leadership and expertise on standards development,
| voluntary frameworks, public-private sector collaboration,
| and international harmonization.. NIST's funding has been in
| focus following a budget cut of roughly 12% to $1.46 billion
| in fiscal year 2024._
|
| Edit_2: is there a shortage of database rows, or people to
| write a shell script? Why not pre-allocate N CVE IDs for
| every CNA, while a new plan is worked out? At least one
| random commercial vendor could foresee the shutdown early
| enough to reserve CVEs.
|
| _> Garrity posted on LinkedIn, "Given the current
| uncertainty surrounding which services at MITRE or within the
| CVE Program may be affected, VulnCheck has proactively
| reserved 1,000 CVEs for 2025," adding that Vulncheck "will
| continue to provide CVE assignments to the community in the
| days and weeks ahead."_
| matthewdgreen wrote:
| I am now more confused and not less.
| transpute wrote:
| Do you have any visibility into pre-2024 funding for the
| NIST NVD and MITRE CVE programs?
|
| MITRE CVE/CWE contract, $29M for 2024-2025, https://www.u
| saspending.gov/award/CONT_AWD_70RCSJ24FR0000018...
| transpute wrote:
| Apparently 2024 NVD funding cuts did motivate CVE
| contingency planning, https://www.thecvefoundation.org/
|
| _> A coalition of longtime, active CVE Board members
| have spent the past year developing a strategy to
| transition CVE to a dedicated, non-profit foundation. The
| new CVE Foundation will focus solely on continuing the
| mission of delivering high-quality vulnerability
| identification and maintaining the integrity and
| availability of CVE data for defenders worldwide. "CVE,
| as a cornerstone of the global cybersecurity ecosystem,
| is too important to be vulnerable itself," said Kent
| Landfield, an officer of the Foundation._
| RVuRnvbM2e wrote:
| There is nothing in that article mentioning funding reductions.
|
| That article is about how the volume of software
| vulnerabilities are increasing, resulting in difficulty keeping
| up by the CVE and NVD projects.
|
| Please stop spamming this thread with political spin.
| transpute wrote:
| Both CVE (MITRE contract) and NVD are funded by NIST, https:/
| /www.securitymagazine.com/articles/100795-understandi...
|
| _> Since February 2024, the National Institute of Standards
| and Technology's (NIST) National Vulnerability Database (NVD)
| has encountered delays in processing vulnerabilities.. caused
| by factors such as software proliferation, budget cuts and
| changes in support.. NIST, an agency within the United States
| Commerce Department, saw its budget cut by nearly 12% this
| year._
| cma wrote:
| Reading that article closely it says nothing about an NVD
| budget cut, only a NIST one. They were trackijg the changes
| after NIST's budget was cut, not NVD's. As pointed out
| below, CISA announced a cut and then NIST more than made up
| for it by reallocating funds, for an NVD funding increase,
| even though NIST had their overall budget cut.
| transpute wrote:
| One of your references has budget numbers that are two
| orders (?!) of magnitude higher than the CISA number.
| Hopefully someone can chime in with granular historical
| data for NIST NVD and MITRE-via-NIST CVE funding.
| bradac56 wrote:
| dupe of a dupe https://news.ycombinator.com/item?id=43700258
| dang wrote:
| I'm not sure, but the current article looks to have somewhat
| more information in it, so I've merged that thread hither
| instead.
| 9283409232 wrote:
| Reminds me of Trump's first term where he said if we stopped
| testing for Covid, we'd stop catching new cases and case numbers
| would go down. If you stop testing for vulnerabilities then
| vulnerabilities go down. Easy stuff.
| dboreham wrote:
| So easy having the brain of a toddler.
| goku12 wrote:
| That's exactly what they're saying about the HHS cuts and the
| measles outbreak.
| flanked-evergl wrote:
| What I don't get is why people make things up and then get
| angry at the thing they made up. Is there not enough real
| things to be angry at?
| mjevans wrote:
| Mr. President, Do you want China to get the reports instead, or
| do you want the NSA to have a lead time where the vuln's are
| useful tools?
| hsbauauvhabzb wrote:
| If you /s/China/Russia/, when asking Trump, it's no longer a
| rhetorical question.
| hsbauauvhabzb wrote:
| For those reading, a fair few of my recent posts were
| downvoted after this comment, and it was initially flagged.
|
| If I violated some rule so be it, and I could care less about
| internet points, but it certainly feels like suppression of
| individuals based on individual posts which is a behaviour
| that could end up being the death of hn.
| mjevans wrote:
| It seems phrasing it in the form of a joke was too much.
|
| I was trying to convey (with levity/humor) WHY it should
| continue to be funded as well as the argument that should be
| made to the one currently in control of the spineless US
| Congress.
|
| Yes, fixing the vulnerabilities is important. However what the
| government probably does gain from it is an inside advantage in
| the lead time for vulnerabilities to protect against, as well
| as to exploit on adversaries.
| stego-tech wrote:
| Man, I just can't even muster the snark I usually have for these
| sorts of boneheaded decisions.
|
| This sucks, plain and simple.
| aprilthird2021 wrote:
| I can't believe what a bunch of bollocks this administration
| is. I couldn't believe it the first time, and this time I
| thought "Well at least I'm ready, it will be a lot like last
| time" and it's so much worse
| 01HNNWZ0MV43FF wrote:
| A lot was lost in the midterms and Supreme Court
| appointments.
|
| Hopefully these 4 years energize people to vote. I know
| protesting and direct action and so on are also important,
| but the gradient is not negative for voting for every office
| you can vote for in every election.
| aprilthird2021 wrote:
| Yes, the next elections are all I have to look forward to
| really.
| jjav wrote:
| Given the current government has blown off an unanimous
| 9-0 supreme court decision, right now I can't feel too
| optimistic there will even be more elections.
| hn_throwaway_99 wrote:
| I think there will be more elections, but I think they
| will be fraudulent, because I think Trump has shown he is
| adept at turning things around and then trying to pretend
| that what he's doing is analogous to what the other side
| has done.
|
| For example, a lot of people have forgotten, but the
| phrase "fake news" originally came about in the wake of
| the 2016 election about all the (actually false)
| misinformation that was spread on social media in the run
| up to the election. Trump adeptly then co-opted the term,
| so any news he didn't like he could just call it "fake
| news", and who was to say any news he called fake was any
| less fake than what people were calling fake before?
|
| My guess is the 2028 elections will be marked by fraud,
| and then when people protest or object, Trump and the
| Republicans will just say "Hey, you called all those Jan
| 6 protesters traitors and said the election was secure,
| how is now any different? Now you're all the traitors."
|
| The only belief that gives me hope these days is "History
| will judge the complicit."
| Terr_ wrote:
| I'm scared that elections won't be secure, especially with
| the way the Republicans are trying to (arguably
| unconstitutionally) wield federal power to force individual
| states to change their systems in abrupt ways.
| sofixa wrote:
| > Hopefully these 4 years energize people to vote
|
| You are assuming there will be next elections that are
| free, fair, and matter.
|
| Trump says a lot of things that ultimately doesn't matter,
| but he has also said, and is the type of brute to believe
| it, that he intends to stay in power. He and his cronies
| have successfully dismantled the checks and balances that
| should have prevented him from doing they, legally. IMO the
| only way he leaves the White House without stirring trouble
| is in a casket.
| the-chitmonger wrote:
| Let's pray that his health suffers, in that case. I am so
| unbelievably tired of reading the news and seeing another
| pillar of civilization dismantled.
| Onawa wrote:
| I would rather that he stays alive for the rest of his
| term. I am more scared of the damage that could be done
| by Vance. Trump is inept and easy to manipulate, but is
| fairly predictable in his actions. Vance and his
| technocrat bros could cause a lot more damage on the
| other hand. I'll take the devil we "know".
| xyzal wrote:
| I fear the situation either ends badly or in a bloodshed.
| They aren't respecting the courts, so assuming they will
| accept defeat in elections is naive.
| MiguelX413 wrote:
| Maybe that's the only way that people can learn.
| ThatMedicIsASpy wrote:
| People can learn once the world puts most of its money
| into education.
|
| The unfortunate part is that education is often also part
| of propaganda and spinning history for said propaganda.
| These days I wish education had a bigger emphasis on
| history and history should be looked at from different
| angles, like how the same thing is being taught from
| different angles.
| scoresomefeed wrote:
| No. Look at the bloodshed in the Middle East. Man is a
| bad animal.
| AlexandrB wrote:
| > Hopefully these 4 years energize people to vote.
|
| This euphemism has to end. I think you mean: "Hopefully
| these 4 years energize people to vote Democrat".
|
| Why not just say it plainly instead of using supposedly
| non-partisan language? This neutral phrasing seems to be an
| appeal to a "silent majority" that agrees with you and
| disagrees with Republican leadership. What if that silent
| majority doesn't exist?
| roughly wrote:
| > it will be a lot like last time
|
| A lot of people seemed to have had this theory, despite all
| the evidence to the contrary.
| crazygringo wrote:
| There wasn't any evidence, that's the problem.
|
| It was all opinion. Trump said a lot of stuff before this
| election, but he said a lot of stuff before his first one
| too.
|
| When people disagreed on what he might do, it was all
| guesses. There was no evidence to base anything on. Would
| his second term be restrained by people around him like in
| his first? That would be an evidence-based extrapolation.
| Would tariffs be all talk and little action, like in his
| first term? Extrapolating from evidence, they would be. But
| 2025 isn't 2017. Things would be different, but _how_? It
| 's all guesses.
|
| It's only hindsight that is 20/20.
| ddejohn wrote:
| It's insanely naive to have thought a second Trump admin
| would not be worse in every possible way. Did you pay
| attention at all to what was going on with SCOTUS?
| Project 2025?
|
| Saying "there wasn't any evidence" is borderline bot-
| speak. Anybody who thought Trump 2.0 was going to be like
| the first round was simply not paying attention _at all_
| and anybody telling others it wasn 't going to be like
| the first admin is either a Russian troll, the mainstream
| media, or just plain irresponsibly ignorant.
|
| "Nobody could have foreseen this" is about the dumbest
| take I think I've seen so far.
| crazygringo wrote:
| Oh please.
|
| Can you tell me where in Project 2025 it talked about
| sending legal immigrants to an Ecuadorian gulag? Or where
| it talked about 145% tariffs on China? Or removing
| fluoride from water, or going anti-vax? Or sending the
| economy into what might be a recession? Or where Musk
| would be invited in to rampage?
|
| You're being completely intellectually dishonest here. I
| don't support Trump _at all_ , but even people who
| thought they were braced for the worst have been
| blindsided by what's been happening. To call them
| "Russian trolls" or "irresponsibly ignorant" is the
| dumbest take _I 've_ seen so far. But it's real easy to
| pretend like you're smarter than everyone else _after_
| events have occurred, isn 't it? Like I said, hindsight
| is 20/20. But go on believing you're so much smarter than
| everyone else, if that's what your ego needs.
| alpha_squared wrote:
| Sorry, but this is a very misguided take. He tried to do
| all the same things his first term, but enough people
| around him kept him in check. Now, he explicitly got
| "yes" folks around him and purged the career folks who'd
| uphold the Constitution. He's emboldened like a child who
| just learned they can command the world to do their
| bidding without restraint.
| ddejohn wrote:
| It's one of the worst takes I've ever seen, and there are
| a lot of bad takes out there.
|
| Even the premise of their argument is silly -- "evidence-
| based extrapolation" lmao that's not how politics work at
| all.
| hansvm wrote:
| Weren't there major problems with the current CVE implementation,
| especially with the waves of script kiddies and AI tools spamming
| the database and the fact that projects who take security
| seriously have little to no say in the "score" that gets
| assigned?
| czk wrote:
| and then a random 9.8 critical comes that affects some software
| you have in a way that makes it a 0 in your environment but it
| doesn't matter cause the cve tanks your organizational Security
| Score (tm) by 10 arbitrary points and management is wondering
| when you'll secure the company again because the Security Score
| is their only tangible deliverable to measure success
| idiotsecant wrote:
| I feel that. So tired of management being completely
| uninterested in actual, actionable security holes but getting
| wildly spun up because they saw a notice with a big scary
| number that has absolutely no relevance in our architecture.
| icameron wrote:
| Yeah like when we bundled in a .js library for client side
| date processing that has a CVE affecting node.js servers with
| high score. Our auditors don't care they tag the whole app as
| high risk. It doesn't even run on the server!
| czk wrote:
| the auditors that sign off on your security to meet your
| clients requirements usually know way less about your
| security posture than your clients do
|
| its all just surface-level box-checking. most companies
| required to get 'penetration tests' just get an overpriced
| Nessus scan sold as a pentest and that meets their reqs.
| JohnMakin wrote:
| while this is true it in no way diminishes the value that
| orgs like cve provide
| jeroenhd wrote:
| Incompetent auditors don't detract from the classification
| system, though. If we removed every data point auditors
| misinterpret or don't care to understand, we may as well
| remove all metrics.
| giantg2 wrote:
| Most tracking tools have exception processes. But yeah,
| security as a product family instead of a simple score seems
| to be a foreign concept at most companies.
| maronato wrote:
| Don't let the perfect be the enemy of good. It is(was?) a
| very useful and important system.
|
| Trump must be receiving a lot of emails from companies
| wanting to fill the void, and I bet the Trumpiest of them all
| is going to be awarded a contract worth 10x the budget CVE
| had, and do a much worse job.
| horacemorace wrote:
| It's Way Better than what we had before: software vendors
| making even arbitrarier decisions about how to classify them.
|
| There are far too many bad actors for us to operate as an
| industry with no yardstick.
| ngneer wrote:
| I disagree that it is Way Better than before. A judgement
| call is worth more than a team wasting effort chasing
| irrelevant pseudo-vulnerabilities being reported as
| vulnerabilities. A broken yardstick is worse than no
| yardstick.
| grumbelbart2 wrote:
| But that's an issue organizations bring upon themselves,
| by defining semi-arbitrary KPIs that are used without
| proper interpretation. It's not directly caused by CVEs
| or assigned scores. It's like blaming git that it count
| lines in diffs, because your company created a KPI that
| measures developer's based on LOC changes.
| ngneer wrote:
| Fair point. I was not blaming CVE for the situation,
| simply bemoaning the situation.
| ngneer wrote:
| Spot on. Vulnerability scanners that make up an
| organizational Security Score (TM) tend to operate at the
| wrong level of abstraction, flagging some library somewhere
| that never runs and has nothing to do with your production
| flow or architecture, or some test keys with zero security
| impact. Go explain that to management, because obviously the
| security tools are right and you are wrong. This sad state of
| affairs is unfortunately the best that the security industry
| has been able to deliver. Trying to wrangle complexity by
| adding more complexity is the craziest notion to me. Yes, no
| scoring scheme is perfect, but when the scheme introduces
| more noise, what have we gained (well, security vendors gain,
| but what have organizations gained).
| j-krieger wrote:
| This is my research field. Do you have any input you can
| think of at the top of your head?
| ngneer wrote:
| That's very cool. You probably know more about it than I
| do, then, but my advice is to articulate the exact
| problem you try to solve.
|
| I expect your field is probably teeming with AI proposals
| or offers on how to manage vulnerabilities, but that is
| doubtful the way, because again it is adding complexity,
| and no classifier is perfect, especially when scanners
| fail to understand scanned applications and their threat
| models or environment.
|
| Stop selling external scanners, start simplifying code?
| This will never work, of course, because security vendors
| sell the promise of security to those willing to buy it,
| in the form of add-on products and capabilities.
|
| Empower people to ignore scanner reports without so much
| red tape? That would never work either, because megacorp
| wants compliance and reduced liability.
|
| Build secure systems as opposed to cataloging and scoring
| flaws? That would never work, because building secure
| systems is hard, nature tends to favor otherwise.
|
| Charge people for adding complexity and credit them for
| removing complexity? Sadly, there is no way to do that,
| especially since products must ship and quality is hard
| to observe, since it is often invisible and only surfaces
| when things are broken.
|
| Off the top of my head, would be nice to require proof of
| exploitation, by adding CTF-like capabilities to apps,
| such that only if the flag is captured do we consider the
| report real. This places more burden on scanners, in that
| it is no longer enough to report an outdated library.
| Requiring some proof of exploitability reduces noise and
| increases SNR, reducing false positives. Naturally, not
| all vulnerabilities have working exploits, and scanners
| can never fully simulate an adversary, so we may get more
| false negatives, but at least we would not have to waste
| so much time upgrading pointless modules and breaking
| applications to appease a false report. So the idea is
| "here is a dummy asset, show me how you leaked or
| compromised it". Adding the dummy asset should be cheap,
| but would force scanners to better simulate an attack.
|
| At the very least, there ought to be a knob to decrease
| scanner sensitivity.
| nikanj wrote:
| And it's not enough to explain it to management, you also
| need to explain it to your ISO auditors, your customers et
| cetera ad nauseam.
| elric wrote:
| Solving this problem in a generalized way is really hard.
|
| Maybe I have a dependency on Foo which has a critical
| vulnerability in a feature that I don't use. I suppress the
| warning and all is well. Then two weeks later someone on my
| team decides to use that feature, not knowing that there's a
| problem with it. Now we're fucked, and we'll never know
| because the vulnerability has been suppressed.
| sepositus wrote:
| I don't know of anyone who doesn't quickly become exhausted
| after running a CVE scanner on their code.
| gcr wrote:
| These sound like downstream effects of funding stress to me,
| no?
| tdb7893 wrote:
| The scores were never going to be that accurate across people's
| environments (IDK how much other places relied on them, places
| I worked never did that much) and issues with the scores don't
| seem to be a good justification to torch the whole CVE system
| anyway.
| hashstring wrote:
| This^ and to add to that, at the very least MITRE assigned
| IDs which is great. Plus they did an initial scoring, which,
| well... will never be perfect like you said and I'm sure
| these things evolve throughout time and get better (not
| talking necessarily CVSS vX).
|
| What a shame on this current gov. administration, if you can
| even call it that.
| mike_hearn wrote:
| Why isn't it a good justification?
|
| I think the question everyone in this thread should ask is:
| why is it the government's job to do this, especially given
| the prior widespread view that they're doing a bad job? Is
| the software industry so immiserated by poverty that it
| cannot organize its own distribution of security bulletins?
| Clearly not: GitHub already runs its own vuln tracking scheme
| that's better integrated with the tooling we use for open
| source software. The industry routinely sets up
| collaborations like standards bodies, information sharing
| groups and more. And there is as whole ecosystem of security
| companies to help you understand vulns in your stack.
|
| So there seems nothing specific to CVEs that requires
| government involvement, but the existence of the tax funded
| scheme does discourage the creation of competitors that might
| function better.
|
| But, to CVE or not to CVE ... that is not the question. US
| deficit spending is out of control. This sort of thing had to
| happen some day. It's what Europeans in the 2010s called
| "austerity" and it always makes some people scream but this
| graph:
|
| https://fiscaldata.treasury.gov/americas-finance-
| guide/natio...
|
| ... is not sustainable. Up to 1984 overall US debt was
| stable. Since then its growth rate became dangerous. Debt/GDP
| ratio is now worse than just after WW2. The federal
| government is currently spending more on interest than on
| defense or Medicare:
|
| https://www.crfb.org/blogs/interest-costs-have-nearly-
| triple...
|
| The US is currently getting its first taste of what parts of
| Europe started going through in 2008, and unfortunately
| there's bad news: the cuts you're seeing now are mostly
| cosmetic. They're what can be done within the current
| framework of laws, sort of, with lots of bending of the rules
| and creative interpretations of them and maybe some
| oversteps. But it's just the start of what's needed. Large
| scale reform of the laws themselves will be required
| regardless of whoever wins the next elections.
| theteapot wrote:
| > why is it the government's job to do this?
|
| Because the private sector can't see past their profit
| motive to the national defense motive.
| danso wrote:
| > _But, to CVE or not to CVE ... that is not the question.
| US deficit spending is out of control. This sort of thing
| had to happen some day._
|
| I suppose more people would be more amenable to these
| wholesale cuts if the current administration weren't
| blowing through even more money than before [0]:
|
| > _The new Treasury Department data shows a deficit of
| $1.307 trillion for October through March, the first six
| months of the fiscal year 2025. And spending is $139
| billion more in the first three months of 2025 compared to
| the same period last year, with borrowing over that period
| $41 billion higher._
|
| We're currently fighting no wars and yet Trump is proposing
| a record $1 trillion defense budget [1]:
|
| > _"We're going to be approving a budget, and I'm proud to
| say, actually, the biggest one we've ever done for the
| military," he said. "$1 trillion. Nobody has seen anything
| like it._
|
| And that's _before_ proposed cuts to tax revenue [2]:
|
| > _Extending the expiring 2017 Tax Cuts and Jobs Act (TCJA)
| would decrease federal tax revenue by $4.5 trillion from
| 2025 through 2034. Long-run GDP would be 1.1 percent
| higher, offsetting $710 billion, or 16 percent, of the
| revenue losses._
|
| So this whole "we're just imposing much needed austerity"
| to justify penny-wise-pound-foolish policies is kind of
| laughable when the proposed increase to our peacetime
| defense budget alone wipes out Elon's most recent estimate
| of DOGE's total savings [3].
|
| [0] https://apnews.com/article/trump-biden-budget-deficit-
| spendi...
|
| [1] https://www.militarytimes.com/news/pentagon-
| congress/2025/04...
|
| [2] https://taxfoundation.org/research/all/federal/trump-
| tax-cut...
|
| [3] https://www.nytimes.com/2025/04/14/us/politics/elon-
| musk-dog...
| mike_hearn wrote:
| Yes. The Republicans are not and never have been united
| around fiscal conservatism. Eliminate-the-deficit
| libertarians are one faction within the party but not the
| dominant one, and Trump doesn't come from it. Same with
| most right wing parties the world over: the bigger
| faction is usually one that likes both tax cuts and
| spending increases. That's why deficits are out of
| control across the west: between the tax-and-spend left
| and the don't-tax-but-spend right, the don't-tax-and-
| don't-spend contingent isn't big enough to outvote the
| others. Clinton was very unusual in this regard, perhaps
| a product of the short post-USSR consensus.
|
| Elon is a libertarian and has been allowed to go do some
| spending cuts around the edges. This gets support from
| Republican members of Congress partly because the USG
| turns out to be spending a lot of money on highly
| partisan Democrat projects, but mostly because it's
| someone else doing the cutting and not them. Even if they
| know they should be doing it themselves they don't want
| the crazies trashing _their_ cars, so if some outsider
| does it for them that 's a deal they'll happily take
| whilst it lasts.
|
| All that said, it's inevitable that the administration
| would be blowing through more money than before even with
| DOGE. It's the nature of debt that it compounds. The
| level of cuts required to even keep the deficit stable
| would be huge because interest payments are accelerating,
| and the cuts DOGE are allowed to make are small (even
| when they go further than they might technically be
| allowed).
|
| Right now there's just no mainstream support in US
| politics for serious austerity. There never is in any
| country, but sometimes the public can be convinced to
| agree to some amount if politicians do a good job of
| communicating the deficit problem. The UK in 2010 is an
| example of that, where the Conservative/Lib Dem alliance
| was able to convince the public to vote for spending cuts
| (albeit not as deep as were actually required... but it
| tided the UK over until the economy started growing
| again).
| rco8786 wrote:
| > why is it the government's job to do this
|
| This is like, exactly the sort of thing that the public
| sector should be doing. There's no profit incentive for
| this to happen in the private sector.
|
| I don't disagree with your overall sentiment re:
| unsustainable debt. But the answer must be reform and
| taking hard looks at the military budget, not just randomly
| cutting programs that you disagree with politically.
|
| More like the Clinton approach.
| mike_hearn wrote:
| But, why is there no profit incentive to do this when
| for-profit companies are already doing so?
|
| https://github.com/advisories
|
| Note that many of these entries start with GHSA not CVE.
|
| Agree that the military budget should face large cuts
| too, unless I guess a major war breaks out.
| rco8786 wrote:
| They are doing it, but there's no profit incentive.
| Github is a bit of a special case because of their
| commitment to OSS and the broader engineering community,
| but the moment a downturn occurs and MS takes a harder
| look at P&Ls, you better believe that's on the chopping
| block.
|
| The public sector is exactly where you need things that
| are important to society but don't make money.
| cantrecallmypwd wrote:
| This is bikeshedding. The point is an authoritative process and
| an identifier
|
| All this does is help Putin and other rich grifters.
| GolberThorce wrote:
| you like to say word 'bikeshedding', adoption of formal
| intellectualish sounding terminology even when inappropriate
| is orange-site affliction I advise against. I am saying this
| for your own sake... speak truths with POWER
| benatkin wrote:
| It's a legitimate term. It's like criticizing use of the
| word _startup_ or demanding someone put a dash in
| _frontend_ or _backend_.
| GolberThorce wrote:
| term is real... but is more like criticizing misuse of
| word startup. to be even more accurate it is what I said
| and not anything else
| benatkin wrote:
| Maybe you don't see how it's bikeshedding. Ah well, let
| me try to explain.
|
| It's because it's like if someone had forgotten to
| validate the user's role in an endpoint in a Django app,
| and someone said that they should have used Rails because
| it's easier to understand. In reality both are easy
| enough to understand to be able to do an authorization
| check, and the framework isn't the issue. So the person
| suggesting Rails is bikeshedding.
|
| Likewise, if someone made another vulnerability database
| it would likely have the same issue, and this isn't
| really the place to solve it. If somehow this does
| trigger the realization to solve it, then it will be by
| luck.
| stavros wrote:
| We're getting into pedantic arguments, but bikeshedding
| is when multiple people argue to death about the easy
| stuff _because it 's easy_, and don't argue at all about
| the actually hard stuff, because none of them know enough
| to argue about it. I don't know what your example is, but
| it's not bikeshedding.
| benatkin wrote:
| I had argued for a less pedantic take, but I guess by
| replying to you I'm being pedantic. It seems to me that
| my example not only is bikeshedding by the definitions I
| find but also that to me it fits your definition of it.
| It's easier to talk about what framework you think is
| best than it is to talk meaningfully about process, which
| is more relevant place to look to prevent serious bugs,
| assuming both frameworks are capable.
| https://en.wiktionary.org/wiki/bikeshedding
| stavros wrote:
| Bikeshedding is when people need to make a decision on
| something, and keep talking and talking about the easy
| stuff. Your example of someone offering a driveby opinion
| isn't an instance of a group of people needing to make a
| decision.
| benatkin wrote:
| Ah, it wasn't a driveby opinion how I imagined it, and
| I've experienced stuff like it in the past. It would then
| go into talking about rails features and libraries that
| could save the day, and the django counterparts. The
| decision that needed to be made would be what action to
| take to prevent a similar issue from occurring in the
| future.
| stavros wrote:
| I'm not saying it doesn't happen, but bikeshedding is
| when you say "OK guys we need to figure out the
| architecture of this complicated new service" and then
| there's a bunch of debate on libraries and frameworks and
| very little debate on the actual (hard) problem it needs
| to solve.
| cantrecallmypwd wrote:
| Thank you for the unsolicited defense. Linguistic
| _bikeshedding_ is tantamount to an ad hominem. It 's the
| mark of someone unable or unwilling to form a rational,
| valid argument or engage in civil discourse. Let's
| instead refocus to the HN site guidelines please. :o)
| aprilthird2021 wrote:
| Sure. There's also major problems with the video encoding
| pipeline at my big tech job. Let's just delete it
| ajross wrote:
| > Weren't there major problems with the current CVE
| implementation
|
| Absolutely. And if the headline was "DHS proposes improvements
| and streamlining to the CVE program" we'd all probably be
| cheering.
|
| Leaping from "This is Flawed" to "Let's kill This" is a logical
| fallacy. A flawed security registry is clearly better than no
| security registry.
| GolberThorce wrote:
| There are a lot of logical fallacies. Have you heard of the
| sunk-cost one? Or fallacy fallacy maybe? Or ten-tendril
| eschatomon fallacy?
|
| In honesty to say "logical fallacy" is spoddy, I advise
| against for aesthetic reason.
| worthless-trash wrote:
| This will get lost in the noise, but i think you mean cvss.
|
| CVE is simply identification of a flaw, not a scoring system.
| bjackman wrote:
| As an active consumer of CVEs: yea there are major problems. No
| there's nothing better and no I don't have any better ideas.
|
| The scores are mostly useless, I would not care if they
| disappeared, I do not look at them. I don't really understand
| why people get so upset about garbage scores though. If a high
| CVSS score creates a bunch of work for you then your vuln mag
| process is broken IMO. (Or alternatively, you are in the
| business of compliance rather than security. If you don't like
| working in compliance, CVSS scores aren't the root cause of
| your misery).
|
| Having a central list of "here's a bunch of things with stable
| IDs that you might or might not care about" is very valuable.
| Sander_Marechal wrote:
| > you are in the business of compliance rather than security.
|
| So, most businesses. They all need their ISO/NIST/HIPAA/etc
| certs.
| bjackman wrote:
| Yeah, most businesses need window cleaners too. If you're a
| window cleaner and you complain about all the birds
| shitting on windows, I dunno what to tell ya.
|
| If you're working in compliance either
|
| A) you're stuck in your compliance job, that sucks, CVSS
| scores aren't the reason why though.
|
| B) you enjoy compliance.
|
| C) you should change jobs.
| SkyBelow wrote:
| Often it is a second order impact. This creates a bunch
| of work for the compliance people, but then the
| compliance people end up competing a bunch of work for
| everyone else. If you count anyone who might have to
| follow compliance as working in compliance, then I
| purpose that there isn't enough non-compliance jobs to go
| around.
| bjackman wrote:
| Hmm I dunnno I think
|
| a) If you are having to do busywork for compliance
| reasons, you are either disempowered to push back on
| bullshit work (case A above, unfortunate, but your job
| was gonna suck anyway), or it's not really a second order
| effect, you work in compliance in a meaningful way.
|
| b) Compliance bullshit seems to expand into the space
| available to it. Nobody thinks CVSS scores are
| meaningful, the fact that they feed into compliance
| processes is not the CVSS scores' fault it's the
| compliance machine just globbing onto random bullshit as
| its expansion continues. If you took away CVSS scores it
| feels like it would just glob onto something else
| instead.
|
| Anyway, in the end I think we aren't disagreeing about
| that much. I think they're silly, if someone wanted to
| get rid of them I wouldn't try to defend them at all. I
| just wouldn'e be the person to push for that.
| bamboozled wrote:
| Getting a bit tired of posts like this (no offense), something
| dumb / nefarious happens like funding is cut for <useful
| thing>, then someone posts an off the cuff comment or question
| like, "wasn't this <useful thing> not that useful because
| <superficial reason>?".
|
| Why do people do this, to down play all the destruction of the
| last few months? Seems to be some type of coping mechanism.
| rco8786 wrote:
| Every system has problems. The challenge is to address the
| problems and fix them. Not just delete the entire system and
| claim a win.
| declan_roberts wrote:
| Yes it earnestly needed new direction and leadership.
| bearjaws wrote:
| Classic "oh its broken so throw it all away".
|
| It's the way it is because there isn't a good alternative. They
| cannot possibly know every environment that we operate in.
|
| To this day we still have large corporations down playing their
| issues, and it was way worse 20 years ago.
| ggm wrote:
| I wish this hadn't happened.
|
| I wonder what level of compartmentalisation inside DHS means they
| didn't see this as having sufficient downsides?
|
| I ask this, because I don't think anyone in the subject matter
| specialist space would have made a strong case "kill it, we don't
| need this" and I am sure if asked would have made a strong case
| "CRISSAKE WE NEED THIS DONT TOUCH IT" -But I could believe senior
| finance would do their own research (tm) and mis-understand what
| they saw in how other people work with CVE, and who funds it.
| hackyhacky wrote:
| > I wonder what level of compartmentalisation inside DHS means
| they didn't see this as having sufficient downsides?
|
| This was not a carefully-weighed decision based on a cost-
| benefit analysis. This was a political order, consistent with
| the administration's policy of "cut everything, recklessly,
| indiscriminately."
| tmpz22 wrote:
| Destroy, destroy, destroy. Promise to rebuild but don't. Take
| it all.
| cantrecallmypwd wrote:
| Vampire capitalism. They want civilization to break down so
| they can offer a solution for profit. The enemies of all
| people and life on the planet are a tiny group of oligarchs
| and their supplicants.
| 01HNNWZ0MV43FF wrote:
| Not unlike the manga Berserk
| CamperBob2 wrote:
| This isn't capitalism, any more than arson, burglary, or
| extortion is capitalism. Get some new material.
| tigerBL00D wrote:
| To be fair, we don't yet know how capitalism ends.
| Nevermark wrote:
| I agree, given the right definition of "capitalism".
|
| Unfortunately "capitalism" has two quite different
| meanings. Which are rarely clarified in use.
|
| Capitalism with a big C, a too common overarching
| ideology, gets bent to mean whatever the greedy,
| unethical and rich want it to mean so they can get more
| money.
|
| But small c capitalism, evolving from both practical and
| ethical foundations, is a system so useful it has
| multiplied the benefits of civilization. But it is just
| one such system.
|
| It can't do everything, it needs other independent
| systems (justice, dispute resolution, rules of clarity,
| risk & trust limiting systems, for starters) to work, and
| extending it to places it doesn't work causes great harm.
|
| (Like when perversely applied to those enabling systems,
| in big C form, as is happening now.)
| roughly wrote:
| > any more than arson, burglary, or extortion is
| capitalism
|
| Indeed.
| chris_wot wrote:
| So much for the wunderkinds in DOGE.
| sitkack wrote:
| @bigballs, please save U.S.
| drivingmenuts wrote:
| Given that the Kids at DOGE are all computer experts,
| this reeks of a calculated move.
| consp wrote:
| I think expert is not the right word for what looks like
| mostly rookies.
| krferriter wrote:
| Absolutely not. They are not broadly experts, and they
| are not making these decisions after careful
| consideration, as evidenced by their continual acts of
| stupidity and basic errors and cutting things despite
| having no idea what it is they are cutting. Musk got in
| an argument with someone who said DOGE cut funding for a
| cancer treatment program, and Musk was calling the person
| a liar, and the person provided evidence and Musk
| admitted it was an accident. They are a clown car of
| idiots who vastly overestimate their own knowledge and
| underestimate how much good the government actually does.
| They think they can just slash and burn and there will be
| no negative consequences because they think the
| government is worthless.
| chris_wot wrote:
| Until, like Ayn Rand, they actually need the government.
| Then they'll be complaining how the government doesn't
| provide services.
| riffraff wrote:
| My knowledge of Ayn Rand stops at having read a book (and
| considered it silly), when did she need the government
| and complained about it?
| chris_wot wrote:
| She was an Objectivist. She considered social security to
| be "legalized plunder". Then when she needed it, she
| decided to take it.
|
| One of her wonderful worldviews was to rejects altruism
| as a moral imperative, arguing that individuals should
| live for their own rational self-interest. Social
| security, based on the idea of supporting others,
| contradicts this principle.
| Nevermark wrote:
| It takes strong and complex social glue to create a place
| where millions can safely follow their own self-interest.
|
| Which means anyone whose wisdom matches their self-
| interest is going to understand that different things
| have very different efficiencies at different scales.
|
| And some things happen to be dramatically more
| efficient/person and more effective, the larger the scale
| they can be coordinated at.
| InsideOutSanta wrote:
| _> It takes strong and complex social glue to create a
| place where millions can safely follow their own self-
| interest._
|
| This exactly. All of these people who profess to believe
| in objectivism could easily move to a failed state and do
| anything they want to with zero government intervention.
| But they don't do that. They want all of the benefits of
| a working government with none of the things required to
| actually create a working government.
| cratermoon wrote:
| Side note: if they wait a little bit, they may end up not
| needing to move anywhere after all.
| jay_kyburz wrote:
| It is in your self interest to have a strong social
| safety net, because one day you might need it too.
| ndsipa_pomu wrote:
| Also, even if you don't need it yourself, it's far nicer
| to live in a society where people's basic needs can be
| met otherwise we end up living in some kind of Mad Max
| apocalyptic wasteland where people with nothing and
| nothing to lose roam the country looking for targets.
| Tainnor wrote:
| > One of her wonderful worldviews was to rejects altruism
| as a moral imperative, arguing that individuals should
| live for their own rational self-interest. Social
| security, based on the idea of supporting others,
| contradicts this principle.
|
| This position was already pointed out by Plato (in the
| Gorgias IIRC) as being inconsistent. Political systems
| are made up by people - if a society, in particular a
| democratic one, has certain systems in place, then this
| is probably because it was (at least believed to be) in
| the people's self interest.
| drivingmenuts wrote:
| I don't see altruism as being outside of my own self-
| interest. I think that you get what you give, so having
| to give up some money to the public good is OK (usually
| not awesome, but OK).
| orwin wrote:
| What's funny, and it might be because of the translation,
| but I first thought her book where all entrepreneurs are
| hidden away in a sort of parallel country was a dystopian
| satire and a joke about some people sense of self
| importance. Then I learned about her (and when the book
| was written too) and realised her book was to be read as
| it was written, 'seriously'. Which makes it silly, but a
| funny story.
| aaronbrethorst wrote:
| Medicare and social security after a lung cancer
| diagnosis (from being a heavy smoker)
|
| https://www.openculture.com/2016/12/when-ayn-rand-
| collected-...
| drivingmenuts wrote:
| Sorry, I really should have said "experts" with the
| rabbit ears. But it still reeks.
| chris_wot wrote:
| They've done their degrees and masters in Computer
| Science, and many of them dropped out. But they focused
| on AI, so I'm assuming this makes them great at
| statistics, but does this mean they are great at
| security? Given the way they've gone through a variety of
| departments, I'd say they aren't.
|
| The DOGE crew are incompetent. Witness their firing of
| all the people who look after the nuclear stockpile and
| Ebola research.
| yowzadave wrote:
| They are clueless kids at their first job, following the
| orders of their hero. You think they'll resist when the
| boss tells them, "cut everything"?
| shakna wrote:
| No. [0] I wouldn't say they are computer experts. [1][2]
|
| [0] https://www.404media.co/anyone-can-push-updates-to-
| the-doge-...
|
| [1] https://www.npr.org/2025/04/15/nx-s1-5355895/doge-
| musk-nlrb-...
|
| [2]
| https://www.bloomberg.com/news/articles/2025-03-14/doge-
| staf...
| RALaBarge wrote:
| Hang out around here for a while and you will realize
| quickly that us tech bros mostly just know tech stuff.
| Our perceived intelligence in topics which we don't spend
| our time on is called hubris and we are swimming in it at
| all times.
| ForOldHack wrote:
| Soon to be powned, by their own extreme short
| sightedness. Duh.
| nwatson wrote:
| Maybe "they" want to do the pwning with less coordinated
| resistance. Doing away with CVEs would help with that
| objective.
| jeltz wrote:
| No, they are not skilled enough to hack anything. These
| are just a bunch of average junior engineers with hubris.
| pohuing wrote:
| Soon to be? They already failed to deploy a website
| safely by exposing the db.
| https://www.404media.co/anyone-can-push-updates-to-the-
| doge-...
| tw04 wrote:
| I think you mean wonder kids.
| riffraff wrote:
| wunderkind is a loanword, it's one of those cases of a
| German word being used but being odd in English since
| it's so similar. Like kindergarten which is often speller
| as "garden".
|
| https://en.m.wikipedia.org/wiki/Wunderkind_(disambiguatio
| n)
| markhahn wrote:
| "tariff as wunderwaffe" often comes to mind these days.
| oezi wrote:
| Many of these terms originate during the Nazi regime and
| thus aren't used lightly in Germany anymore.
|
| Other example includes: Endgegner (final boss) or
| Endlosung (final solution)
|
| I would suggest to avoid such terms.
| ben_w wrote:
| > Endgegner
|
| I did not know about this, thanks for _die Vorwarnung_.
| In context, I 'd assume "ultimate enemy"
| (Gegner=opponent) as "final boss" sounds videogame.
| consp wrote:
| Many did in the golden age of German research, then to be
| destroyed by those mentioned.
|
| Either the philosophers or the mathematicians/physicists
| likely coined them.
| pseudalopex wrote:
| Wunderkind and Endgegner are used lightly in Germany.
|
| The parallels to Nazi Germany's striking but impractical
| weapons seemed intended every time I heard or read
| Wunderwaffe in English.
| hnlmorg wrote:
| I think the GP was making a reference to the Apple TV
| show "Ted Lasso".
|
| "Wunderkind" mispronounced as "Wonder Kid" is a running
| joke in that show.
|
| https://www.reddit.com/r/TedLasso/comments/132rw9v/what_t
| he_...
| obelos wrote:
| I'm pretty sure this is a joke reference to Ted Lasso.
| chris_wot wrote:
| Same thing.
| addandsubtract wrote:
| They were able to eliminate all open CVE's while cutting
| costs at the same time. Amazing!
| Cthulhu_ wrote:
| Did they promise to rebuild?
|
| If I'm giving them the benefit of the doubt (which I hate),
| it's a shotgun approach; cut things relentlessly and see
| what falls apart. Chaos engineering applied to a country
| and / or the world.
| willy_k wrote:
| That's exactly what it is, and they said as much
| repeatedly while campaigning. Voters, in their zealotry
| against the perceived status quo, failed to realize how
| much of what we have right now you don't want to cut
| recklessly, as well as just how reckless the people that
| they were choosing to do that job were.
| coldpie wrote:
| > in their zealotry against the perceived status quo,
|
| Perceived, not actual, because spreading lies and
| misinformation is what makes the most money for the ad
| sellers that make up 90% of our industry.
| watwut wrote:
| There are various glorious futures floating around about
| how this will make America better, stronger, more
| independent.
| SecretDreams wrote:
| > cut everything, recklessly, indiscriminately
|
| Mostly discriminately, tbh.
| MiguelX413 wrote:
| https://mathstodon.xyz/@johncarlosbaez/114000054766059217
|
| Ah yes, like the woke DEI grants for "Homotopical macrocosm
| for higher category theory" for having the prefix homo-
|
| Get a hold of yourself
| SecretDreams wrote:
| I can't tell what argument you're making within the
| context of my post?
|
| The OP said indiscriminately, which means they're cutting
| uniformly across the board. I responded with "mostly
| discriminately" which means they're more selectively
| cutting based on prejudice. You then linked me a data
| point where you show they cut funding because it has the
| word "homo" in it and tell me to "get a hold of myself"..
| but your link would directly support what I've said?
| dTal wrote:
| It is clear from context that the original comment is
| using "indiscriminately" in a sense of "without due care;
| thoughtlessly". Your first reply comes across as simply
| contradicting it, i.e. asserting that actually these cuts
| were made with an appropriate level of thoughtfulness.
| Your point that there _are_ criteria which are being
| applied is a useful contribution, but you should have
| expanded on this in your original comment, as it was not
| clear that you were reframing the discussion in this way.
| SecretDreams wrote:
| Respectfully, I took the word at face value and made what
| I thought was a fair, albeit half-jokingly correction.
| Certainly, I understood the context of the original post
| and I expected that this community would understand my
| follow up comment which is using correctly applied
| English. For whatever it's worth, I see no synonyms for
| indiscriminately that would fall under "without due care;
| thoughtlessly" on Merriam-Webster. Even if I understood
| what the OP was saying, it was not technically the
| correct verbiage to use. I would have thought I'd receive
| a similar level of "allowable nuance" in my comment that
| the OP was afforded.
|
| https://www.merriam-
| webster.com/thesaurus/indiscriminately
| howenterprisey wrote:
| You're completely right, for what it's worth, and I
| appreciated the wordplay.
| SecretDreams wrote:
| Thank you.
| metabagel wrote:
| I interpreted "discriminately" as exercising due
| diligence. I think in this instance you were perhaps too
| clever by half.
| qzw wrote:
| Most of the general population can't read above something
| like a fifth grade level. Here on HN it's higher, but I
| wouldn't say it's safe to assume you can just engage in
| even mild word play without risking being misinterpreted,
| unfortunately.
| HelloMcFly wrote:
| Written word play, especially in such a short sentence,
| will be hit or miss with even capable readers because
| one's interpretation will be devoid of interpersonal
| context (including nonverbal signals) and heavy on other
| context such as expecting some in this community to
| continue to defend Elon/DOGE because we've seen it plenty
| on HN to date.
| albedoa wrote:
| > albeit half-jokingly
|
| It seems then that you could have acknowledged
| MiguelX413's comment without the feigned aloofness?
| SecretDreams wrote:
| He came in quite hot and has made no acknowledgements of
| my rebuttal. To be honest, taking a deep breath and
| giving me a more sensible response than what I got could
| have gone a lot way.
|
| We're allowed, and should be encouraged, to write with a
| small amount of nuance and creativity.
| rfrey wrote:
| Indiscriminate means at random or without judgement. The
| comment you're arguing with clearly (and cleverly) said
| the cuts are not random. As one data point, I did not
| read the comment as contradicting anything, but as
| agreeing and expanding.
| fennecfoxy wrote:
| Afaik there's never been a DEI initiative (or similar,
| I'm not American) that I've ever heard of to hire more
| gay people specifically. Most of us would hate to be
| hired for our sexuality rather than our skills.
|
| There's nothing "woke" about it and screaming woke woke
| woke isn't going to change the fact that we exist and you
| don't like it. I'd tell you what I really think of you
| but it would invoke Dang.
| metabagel wrote:
| You misinterpreted that comment, which was sarcastically
| pointing out a study which was purportedly cut simply
| because it had the word part "homo" in it.
| GuinansEyebrows wrote:
| You have got to stop engaging with the idea of "woke" as
| a specific ideology to stand against. It's like you
| purposefully intend to misunderstand common shared
| meanings of words.
| derbOac wrote:
| There are many problems going on right now, but in terms of
| cuts this is one of the most problematic: everything is
| secret, with no oversight or deliberation. It's
| indistinguishable from corrupt malice because it's not done
| with open thoughtfulness.
| jacobyoder wrote:
| I just can't believe your take on this. The White House
| press secretary has directly said, multiple times, "this is
| the most transparent administration ever". /s
|
| In reality, this entire process is insanity. We've had
| examples of government spending overhaul in the past -
| early(?) 90s - both sides worked together, cut lots of
| spending across programs, downsized tens of thousands of
| federal workers, and balanced a budget, to the point where
| we had a surplus. It was tough, took time, wasn't perfect,
| but was deliberated and debated and far far far more open
| and transparent than all this. But their goal was actually
| improving government (even if that meant reducing some
| areas). The current 'leadership' goal is to
| dismantle/destroy as much as possible, as this is led by
| people who think government in general should not exist.
| tlogan wrote:
| Yes, this is 100% consistent with their policy: cut
| everything and if you find out that something is really
| really needed then reverse it.
| markhahn wrote:
| it might be ignorance; it might be malice.
|
| it might also be deliberate: that they actually don't think the
| government should be involved in this sort of thing. after all,
| someone could be making a profit on this, and that seems to be
| their highest value. if gov is involved, that makes it a
| communal effort, and you know what else starts with "commun-"?
|
| yes, those reasons are stupid and ignorant AND intentional.
|
| but is there any evidence against that interpretation?
| ggm wrote:
| Hanlon's razor. I also tend to impute malice to things I
| don't like, but I think it's hard to go past stupidity.
| groby_b wrote:
| Stupidity rarely has a _consistent_ destructive track
| record. You score occasional wins. Only malice allows every
| decision to do damage. (The other razor, essentially -
| Occam)
| JoshTriplett wrote:
| Sufficiently advanced stupidity is indistinguishable from
| malice.
|
| (Leaving aside that there's plenty of evidence of malice
| here.)
| gregw2 wrote:
| I love Hanlon's razor. Super-helpful in certain contexts:
| "Never attribute to malice that which is adequately
| explained by stupidity."
|
| But, having known about it for a dozen years now, I also
| find it inadequate alone as a razor without the following
| caveats/corollaries:
|
| Hubbard's corollary to Hanlon's Razor: "Never attribute to
| malice or stupidity that which can be explained by
| moderately rational individuals following incentives in a
| complex system". (
| https://en.m.wikipedia.org/wiki/Hanlon's_razor#Exceptions )
|
| Or (HN) Nerdponx's punchier simplification: "When money is
| at stake, never attribute to incompetence what could be
| attributed to greed." (
| https://news.ycombinator.com/item?id=41066724 )
| Terr_ wrote:
| Hanlon's Razor is susceptible to pathological inputs,
| causing unbounded runtime.
|
| A large amount of things related to Trump fall into that
| category, and it's important to recognize when you need to
| instead treat it as a superposition: It is both malice
| _and_ incompetence, unless the perpetrators decide to plead
| just one or the other.
| incompatible wrote:
| > someone could be making a profit on this
|
| Yes, there are apparently various ways of profiting from
| vulnerabilities. The interesting question would be whether
| any of the regime insiders have a way to profit.
| markhahn wrote:
| I think it's more of a principle: if it looks like someone
| could charge money for it, they think that would make the
| country stronger, because all they understand is first-
| order profit. Trump's ethics is "get away with whatever you
| can".
|
| For instance, most people find healthcare middlemen
| (pharmacy benefit managers, etc) to be grotesque parasites.
| But to a laissez-faire fundamentalist, they're smart for
| finding a way to liberate some profit, even laudable.
| Aurornis wrote:
| This sort of thing is happening across the federal government.
| There is no rhyme or reason. DOGE has been given an unrealistic
| target for cuts and they're desperately cutting whatever they
| can get their hands on. If you look at the federal budget it's
| nearly impossible for DOGE to hit their stated goals without
| touching benefits like medicare and social security (which are
| off limits so far) so the only option is deep, deep cuts into
| the narrow slice of the federal budget that excludes those
| protected categories.
|
| There is no rhyme or reason to what gets cut, other than
| someone under pressure to hit KPIs (dollars cut) was
| desperately searching for things that looked easy to cancel.
|
| This is happening _everywhere_ the federal government touches.
| Most people aren 't aware of it until they come around and pull
| the rug on something that intersects with your own life.
|
| Even my die-hard Republican distant relatives are suddenly
| shocked because programs they benefited from are being cut.
| They thought they voted for something different.
| shakna wrote:
| I'd say that the rhyme and reason are quite clear [0]. They
| published a playbook, and they are implementing it at a
| record pace.
|
| > The NSC [National Security Council] staff will need to
| consolidate the functions of both the NSC and the Homeland
| Security Council (HSC), incorporate the recently established
| Office of the National Cyber Director, and evaluate the
| required regional and functional directorates.
|
| > Given the aforementioned prerequisites, the NSC should be
| properly resourced with sufficient policy professionals, and
| the NSA should prioritize staffing the vast majority of NSC
| directorates with aligned political appointees and trusted
| career officials. - Project 2025, pg 52.
|
| > ... History shows that an unsupervised NSC staff can stray
| from its statutory role and adversely affect a President and
| his policies. Moreover, while the NSC should be fully
| incorporated into the White House, it should also be allowed
| to do its job without the impediment of dually hatted staff
| that report to other offices. - Project 2025, pg 53.
|
| The goal is to build up a political organisation to use as a
| weapon, and to scrap the rest - as a legal excuse to say that
| the political appointments will be necessary.
|
| [0] https://www.project2025.observer/
| ForOldHack wrote:
| They have to find some gumbah to head the security
| dept,because the best one they had,left in a hurry. Heard
| he went to Denmark. ( I am really really kidding )
| sofixa wrote:
| > This sort of thing is happening across the federal
| government. There is no rhyme or reason. DOGE has been given
| an unrealistic target for cuts and they're desperately
| cutting whatever they can get their hands on
|
| You make it sound like poor DOGE employees are being forced
| to do this on this kind of schedule, which definitely isn't
| the impression I got. They're all a bunch of incompetent
| overconfident weirdos who think they know better and what to
| do. Is there any pressure to do anything quickly?
|
| And the US federal budget is quite easy to trim. E.g. remove
| an aircraft carrier from the planned construction pipeline
| and you've saved $15 billion with no actual ramifications.
| SpicyLemonZest wrote:
| Who knows whether it will happen, but in principle DOGE is
| working under some time pressure as they're scheduled to be
| dissolved in mid-2026.
| ForOldHack wrote:
| The ryme is Humpty Dumpty, had a great fall. Now China and
| Russian security forces step up their relentless attacks.
| Let's hope the white house falls first.
| riffraff wrote:
| > Even my die-hard Republican distant relatives are suddenly
| shocked because programs they benefited from are being cut.
| They thought they voted for something different.
|
| Out of curiosity, which programs? And is this enough to
| change their opinion about Trump, or do they still think
| it'll be worth it?
| bruce511 wrote:
| >>They thought they voted for something different
|
| Like what exactly? I mean the guy ran on cutting the budget
| by 2 trillion. In his last term he gave tax breaks yo the
| rich. Where did they think the cuts were coming from?
|
| He ran very hard on raising tarrifs. Which demonstrably raise
| prices (thats literally their goal.) But now people claim "I
| didn't vote for this."
|
| In truth they voted for him because he was the Republican on
| offer and they're die-hard Republican. The Republican party
| has made no secret of its agenda for decades.
|
| I get it, people are good at cognitive dissonance. But this
| is the place for blunt truth. They voted for this. I'm not
| letting Republicans got off the hook here. They voted for
| this.
|
| Just like to my Republican friends who are upset that CVE is
| cut. You voted for this. The general public benefit from CVE
| even though they dont know it exists. Just like you
| benefitted from dozens of other programs you didn't know
| existed, but have also been cut.
|
| That's the problem with cuts. They ultimately end up hurting
| everyone.
|
| Now clearly there's some fat that could be trimmed. Companies
| do it all the time. Done well its good. Swinging a hatchet in
| a crowded elevator does not seem like "Done well".
| lolinder wrote:
| > In truth they voted for him because he was the Republican
| on offer and they're die-hard Republican. The Republican
| party has made no secret of its agenda for decades.
|
| This is actually simply not true. The Republican party
| before the Tea Party looked nothing at all like this. Trump
| won the presidency last year riding a wave of distinctly
| not-your-typical-Republican lower class voters. As he rose
| the old guard Republican establishment formed the anti-
| Trump wing of the party until they were forced out one by
| one.
|
| To put some numbers to this: Bush won the upper income
| brackets by 5+ points in 2000, with a lead that widened as
| you went up the income ladder. Trump lost the equivalent
| brackets in 2024 by 5+ points, a 10 point swing away from
| what Bush won them by. The lower brackets are even more
| stark, with a whopping 18-point swing towards Trump in the
| $30k-$50k bracket (inflation adjusted to $15k-$30k).
|
| These numbers show that Trump is not a Republican in the
| George W Bush sense and he's certainly not a Republican in
| the Ronald Reagan sense. He's a populist and won on a
| populist agenda by putting together a coalition of rabid
| social conservatives (who probably really did go Bush in
| 2000) and poor people (who largely did not).
| rat87 wrote:
| Populism is not an agenda it's a style. Also the majority
| of poor people voted Democrat, the majority of people
| with low education levels voted for Trump (which is not
| the same thing as dumb, although voting for Trump is dumb
| regardless of PhD or lack of HS diploma). There's overlap
| between low levels of education and income but if you
| define class by income then low income people mostly
| voted Dem
| sanktanglia wrote:
| You are ignoring that trump rode to power explicitly by
| enabling the shittest of Republicans that already exist.
| To try and let republicans off the hook for supporting
| him, especially a 2nd time? Is hilarious
| lolinder wrote:
| Even the first wave of Republican support came from the
| Tea Party types more than the establishment types.
| bruce511 wrote:
| I'm upvoting you because you make a coherent argument,
| and votes here should be for that, not whether I agree
| with you or not.
|
| I would agree he's not George Bush, much less Ronald
| Reagan. Nevertheless those who voted for Bush and Reagan
| also voted for Trump.
|
| This has been "decades" in the making in the sense that
| since Obama was elected (in 2008), Republicans have
| embraced racism at the heart of their populist message.
| That swing rightward was made palatable to center
| republicans with a woman democratic candidate in 2016
| (one not terribly well liked in democratic circles) and a
| black woman candidate in 2024.
|
| While racism, and misogyny gather a bunch of votes, long-
| term distrust of institutions is sown, and fostered.
| Republican policy becomes protecting white guys, and
| especially old, rich, white guys.
|
| Reagan was popular and competent, and worked for the good
| of America. Today's president is nothing like him, but
| wins because a bunch of people "vote Republican".
| lolinder wrote:
| > Today's president is nothing like him, but wins because
| a bunch of people "vote Republican".
|
| There's a component of that, but it's not the primary
| cause. A lot of former Republicans stopped voting
| Republican with Trump, including a lot of old rich white
| guys, and a lot of the current Republican voters didn't
| vote for Bush. He wins because of the new wave of voters
| that counterbalanced the flight of the educated core of
| the Republican establishment.
| pseudalopex wrote:
| > The Republican party before the Tea Party looked
| nothing at all like this.
|
| Starve the beast is older than the Tea Party.[1]
|
| [1] https://en.wikipedia.org/wiki/Starve_the_beast
| lolinder wrote:
| There are extremely superficial similarities here, but
| they're just that: extremely superficial. Along the same
| axis but in totally different orders of magnitude, and
| orders of magnitude make a difference.
|
| Obamacare and communism are along the same axis too, but
| the Republicans who claimed they were the same thing were
| obviously wrong.
| michaelt wrote:
| _> Where did they think the cuts were coming from?_
|
| When someone hands you a pencil, you don't wonder what
| variety of tree the wood came from, or what paint chemistry
| was used for the coating. It's a pencil. You might have
| broad opinions on whether the one in your hand is
| comfortable to use, and sharp - but you leave the details
| to the pencil makers.
|
| About 70% of the population engage with politics the same
| way: Leave the details to the people who do this stuff for
| a living.
|
| Do they expect to be disappointed? Sure, but everyone who
| engages with politics expects to be disappointed.
| virgildotcodes wrote:
| This pencil was proudly advertised as being comprised of
| the remains of all that was decent in humanity. The fact
| that it wrote in blood was gleefully touted and cheered.
| pseudalopex wrote:
| You are a pencil company director. A CEO candidate
| promised to cut expenses by 30% by eliminating waste.
| People who do this stuff for a living countered wood and
| graphite exceed 70% of your expenses. The CEO candidate
| proposed to increase graphite spending. Do you wonder
| what the CEO would do if hired?
|
| > Do they expect to be disappointed?
|
| Aurornis said their relatives were shocked.
| jeltz wrote:
| It is traditionally cedar.
| daveguy wrote:
| This is exactly the attitude Putin tries to encourage in
| his population. If enough people don't pay attention or
| don't think what they do matters, it's easier to
| subjugate a population.
|
| If people in the US aren't starting to notice what
| Musk/Trump are doing it will bode very poorly for the
| future of the US.
| eCa wrote:
| > They thought they voted for something different.
|
| They voted for the leopards to eat other people's faces, not
| _their's_.
| russellbeattie wrote:
| Remember, DOGE has nothing to do with money or "efficiency".
| It's a pure ideological dismantling of the Federal government
| aimed at eliminating oversight, regulations, assistance and
| entitlements as envisioned by ultra-conservatives for
| decades.
|
| This isn't speculation or hyperbole, it's specifically laid
| out in their published plans: By hobbling or outright
| eliminating federal agencies responsible for executing the
| laws passed by Congress, the administration can circumvent
| the democratic process and impose their extreme vision of
| limited government on the country, regardless of popular
| support.
|
| The U.S. system of government relies on established norms as
| much as it does law. Conservatives realized that they can
| ignore precedent with impunity if they had an executive
| willing to do so. They then spelled out exactly how, and are
| now enacting that plan.
|
| Then SCOTUS's decisions last summer turbo boosted their
| agenda. The ruling that only Congress can hold the President
| legally accountable essentially means executive power is
| unchecked if the legislature is unwilling or unable to
| Impeach and convict. The President can now confidently ignore
| the law and judicial orders with a veneer of legality. And
| this is what he's doing.
|
| (The fact that all this just so happens to benefit Russia
| after their decade long campaign to destabilize their
| opponents in the West is a topic for speculation.)
|
| DOGE is about permanently altering how our country works
| modeled on the right wing worldview, plain and simple. Since
| that's their overall goal, they're not concerned where they
| swing the wrecking ball - it's all going to get destroyed
| eventually.
| misantroop wrote:
| That plus privatising a lot of it. Kills two birds with one
| stone, eliminate regulation and fill your pockets with
| cash.
| pron wrote:
| > The U.S. system of government relies on established norms
| as much as it does law.
|
| And it's also happily breaking the law. The Executive
| doesn't legally have the power to allocate resources (or
| not), not to mention the power to arbitrarily suspend due
| process.
| fennecfoxy wrote:
| Something different like gay people, women, immigrants all
| suffering while they laugh. Who's laughing now? From an
| outsiders perspective, I sincerely hope that Republicans get
| to feel a fraction of what these usually marginalised groups
| feel every day.
|
| You'd think that lessons would incite learning but that has
| never seemed to be the case throughout history.
| Spooky23 wrote:
| No, we're in a middle of a coup. Palantir or some other odious
| company will get paid 100x more to do something.
| cavisne wrote:
| MITRE has a trademark on the term CVE.
| pjmlp wrote:
| As if laws have any meaning to this administration, and
| anyone expecting this will only last four years instead of
| turning into one of those countries so much admired by the
| captain at the helm, is fooling themselves.
|
| When the citizens realise this, the structures to clamp
| down any revolution will be in place.
| fennecfoxy wrote:
| TBF trade-marking a term like "CVE" is the most
| ridiculous fucking thing and just reeks of modern
| American copyright law type stuff.
| quesera wrote:
| It's only superficially ridiculous.
|
| "CVE" is trademarked and emphasized (e.g. included in the
| shorthand notations, e.g. _CVE-2014-0160_ ), explicitly
| to prevent other groups from using "CVE" in a way that
| causes confusion in the marketplace. And yes, this is the
| same reason trademarks exist for commercial purposes.
|
| But imagine if Microsoft could issue CVEs against Apple
| ... or OpenAI against Anthropic, etc.
|
| The label "CVE" has to have a known authority to be
| useful. And the only way to ensure that is to trademark
| it. See also: "Linux(tm)".
| ozim wrote:
| People will not submit vulns as happily to such business.
|
| Most of vulns will go unaddressed because company like
| palantir will most likely want only really good vulns like
| 0-click RCE.
| daveguy wrote:
| Putin, Xi, and Un say thank you.
| epistasis wrote:
| Your words don't make any sense in this environment. The idea
| that any person at an agency could stand up to or convince the
| DOGE team of anything is preposterous.
|
| Anything that weakens the US or puts our cybersecurity in a
| place that Russia can exfiltrate data will happen. This is not
| about the US needing anything and it's silly to think
| otherwise. See also the NLRB whistleblower and the security
| backdoors that DOGE demanded to allow data exfiltration and the
| subsequent death threats to the whistle blower.
|
| You mindset is behind the times and needs to adjust to a,
| frankly, insane current reality.
| mmooss wrote:
| > Your words don't make any sense in this environment. The
| idea that any person at an agency could stand up to or
| convince the DOGE team of anything is preposterous.
|
| Your comment embraces and spreads the powerlessness they want
| you to feel and spread.
|
| Of course you can stop them - like any other negotiation in
| life, especially non-friendly ones, you need to make it in
| Trump's interest either by carrot or stick. Trump has
| interests; identify them and identify your power in those
| regards ('power and interest' is the term), and use it.
|
| Also, stop helping them make DOGE the scapegoat. It's Trump.
| epistasis wrote:
| DOGE is doing this, it's not a "scapegoat", and Trump is
| not going to negotiate anything here, that's ridiculous.
|
| What leverage do you have for the DOGE boys? What power?
| Resigning? Because on the Defense side of the government
| the best leverage that some teams have found is mass
| resignation, meaning that nothing happens.
|
| There is no negotiating with bullies, it merely breeds more
| concessions.
| mmooss wrote:
| > DOGE is doing this, it's not a "scapegoat", and Trump
| is not going to negotiate anything here, that's
| ridiculous.
|
| DOGE follows Trump's direction and acts on his behalf, as
| you must know. They make a big deal out of DOGE so
| Trump's name is less attached to these actions. Then they
| can take much of the blame with them when they go away,
| with Trump and the GOP blaming them for 'excesses'.
|
| > Trump is not going to negotiate anything here, that's
| ridiculous.
|
| > What leverage do you have for the DOGE boys?
|
| You don't understand how negotiations work. Everyone has
| interests, strengths and weaknesses, and power. You need
| to make it in Trump's interest to keep the CVE program.
|
| Everyone saying they are helpless, and that anything else
| is ridiculous, are panicking. Very unfortunately -
| dangerously - many people legitimize the panic. It's so
| normalized that it's "ridiculous" not to panic.
|
| Every day you continue this behavior, you fall further
| and further behind and lead others in that direction.
| Will you wake up in time?
| djur wrote:
| I don't think there's any reason to believe that Trump is
| mentally competent to understand what's happening here or
| engage in any kind of meaningful negotiation.
| figgis wrote:
| Currently the "discussion of leverage" you are talking
| about is out of the hands of the leaders who run these
| programs.
|
| The amount of disrespect you have shown for someone that
| is just telling you 99% of federal workers have
| absolutely no leverage says a lot.
| stavros wrote:
| Isn't the US supposed to be the birthplace of modern
| democracy? When did you guys forget about protests and
| rallies?
| SpicyLemonZest wrote:
| It's just not practical to organize a rally to save a
| niche cybersecurity program. People are busy protesting
| to protect Medicaid and keep themselves out of foreign
| gulags, they can't divert the attention to CVE.
| stavros wrote:
| That's fine, protests aren't surgical tools anyway. As
| long as people are protesting, it's OK.
| nosianu wrote:
| > _Isn 't the US supposed to be the birthplace of modern
| democracy?_
|
| I would not dare not mention the revolutions in England
| and in France. And before that some Greece city states,
| and definitely Rome. The US declaration of independence
| is just another point.
| throitallaway wrote:
| > You need to make it in Trump's interest to keep the CVE
| program.
|
| This guy is ~80 years old and bragged about "person,
| woman, man, camera, TV." He recently got into a Tesler
| and exclaimed "everything's computer!" Have you seen the
| way his aids explain executive orders to him (like a
| child) before he signs them?
|
| He doesn't have the foggiest notion of comprehension of
| what the CVE program is, or how it would benefit him.
| Unless you're greasing his wheels, it's not going to
| happen.
| 1oooqooq wrote:
| he sure understand two things.
|
| one it costs the us and is needed by everyone, so he
| thinks but paying it someone will pick it up and then the
| us will be the free loader.
|
| second, he understands that helps he and his pals wash
| dirty money.
| markhahn wrote:
| I'm curious by what means you think Trump can be
| bargained with.
|
| Do you mean things like handsfull of like-minded
| countries selling t-bonds? No one in the R party has any
| leverage, and it's not clear that even a few US
| billionaires could exert any influence.
|
| Do you really think Trump has ever heard of "CVE" or
| could comprehend them?
| chris_wot wrote:
| No, it's definitely DOGE doing all of this. Each one of
| these young fools need to be named and shamed. The level of
| damage they have done is unprecedented. They will, in their
| later years, hopefully look back at this time in their life
| with a great deal of shame and embarrassment.
| Wololooo wrote:
| I have the feeling that there will be no redemption arc
| for those ones and the repenting would be for show before
| a court of public opinion.
|
| I'm going to be to the point here, if you guys over there
| don't start to heavily push and organise, and I said it
| already, you're one Reichstag fire away from something
| very bad, and from my point of view, there is probably
| one kristallnacht pending in the mix.
|
| This is not a hyperbole and if someone wonders why this
| has relevance to the discussions, in this case most of
| the people around here are blue team, and it does feel
| like the red team has already taken anything that wasn't
| attached and now taking the time to take what's bolted
| on...
|
| I guess the silver lining of all this, is in their
| hubris, they forgot the bread and games motto, so they're
| might still be a chance to turn things around somewhat...
| But the window is closing at an impressive speed.
| chris_wot wrote:
| I'm an Australian. We have a guy called Clive Palmer, who
| has formed a party called (no joke) the "Trumpet of
| Patriots". It's certain nobody will vote for him. The
| opposition leader married himself to MAGA (and close to
| Trump) and now it appears like this will prevent him from
| winning.
|
| The rest of the world is mostly against Trump.
| throwawaygmbno wrote:
| It needs to be the "shame and embarrassment" Nazis felt
| at the end of WWII and not the traditional shame and
| embarrassment they are used to feeling after losing the
| civil war and Jim Crow laws. It will just happen again in
| a generation otherwise.
| watwut wrote:
| Nazi did not felt shame and embarrassment. They felt
| loss. They felt to be weak. Nazi and Germans felt sorry
| for themselves after the WWII. The feeling of sorry for
| stuff they have done to others is something Germany found
| a bit later, largely due to Nuremberg and general
| policies not allowing it to stay hidden.
|
| Forget about them feeling sorry for anyone but
| themselves. They will feel resentful and as if they were
| being treated unfairly even when actual clear criminal
| investigation happens.
| watwut wrote:
| No, blaming "someone inside DHS" is what makes no sense. It
| 100% makes sense to blame DOGE and actual perpetrators. You
| can stop them only if you start to blame those who do the
| stuff you dont like instead of blaming everyone else except
| them.
| tgsovlerkhgsel wrote:
| If you made this careful analysis, you'd hear "CRISSAKE WE NEED
| THIS DONT TOUCH IT" for almost everything (and it likely would
| be right for a significant portion but not everything).
|
| That's why the current approach seems to be to axe everything,
| listen to how much screaming there is, then reinstate only the
| projects where the screaming is _really_ loud.
| delusional wrote:
| You forget that their stated policy (and I don't doubt their
| commitment) is that whoever complains the loudest were
| probably scamming. That "honest people don't complain"
| conception wrote:
| So the dumbest way to do anything. Got it.
| phtrivier wrote:
| Please read Isaacson biography of Musk.
|
| The "Musk algorithm" is described in detail, and can be
| summed up as a "reverse Chesterton's fence"
|
| "If you are not forced to reinstitute 10% of the rules you
| slashed, you have not slashed enough".
|
| What happens while the 10% are slashed is left as an
| exercise to the voter.
|
| Hopefully, the cve db will be deemed part of the 10%.
| overfeed wrote:
| > "kill it, we don't need this"
|
| "We are paying MITRE how much? Bigballs and co will write a
| better ststem in 1 week and have it integrated with xAI. How
| hard could it be? Send out a first draft of an xAI contract to
| our DHS contact"
| IOT_Apprentice wrote:
| They were at the mercy of 20 year olds from doge. I wonder when
| doge enters the NSA & NRO WHAT information will they steal &
| put in their hard drives.
|
| All of this is criminal behavior on the the current regime.
| eadmund wrote:
| > I wonder what level of compartmentalisation inside DHS means
| they didn't see this as having sufficient downsides?
|
| The National Vulnerability Database has been unable to keep up
| with the flow of CVEs for over a year now:
|
| - https://anchore.com/blog/national-vulnerability-database-
| opa...
|
| - https://www.cyberreport.io/news/cve-backlog-update-the-
| nvd-s...
|
| - https://www.ibm.com/think/insights/cve-backlog-update-nvd-
| st...
|
| - and many, many, _many_ others
|
| It has been a complete disaster for months. At this point,
| perhaps the thinking is to radically change approaches?
| gtirloni wrote:
| You assume there's a plan. Interesting.
| rco8786 wrote:
| > perhaps the thinking is to radically change approaches?
|
| If there had been a replacement or reform plan for even one
| single iota of the things this admin has cut, I might give
| them the benefit of the doubt. But there's not. It's just
| kill, kill, kill.
| metabagel wrote:
| Cutting the program would seem to go in the opposite
| direction of what is needed.
| rco8786 wrote:
| > I wonder what level of compartmentalisation inside DHS means
| they didn't see this as having sufficient downsides?
|
| Come on, are you living under a rock right now? There are
| massive indiscriminate funding cuts to anything that Elon/Doge
| deems to be "fraud", and they explicitly do not care about the
| collateral damage.
|
| This is not about the DHS or "compartmentalization". This is
| just a politician running amok and having real consequences.
| martin8412 wrote:
| Also there has been funding cuts to all agencies where Musk
| is currently under investigation. NHTSA is getting cut so
| they can't get in the way of Tesla.
| paulmendoza wrote:
| No one analyzed it most likely. It's possible on of the college
| students working for Doge doesn't understand security because
| they are a child with no real world experience that Elon
| brought in to slash costs.
| yawnxyz wrote:
| I guess their new business model is to sell zero days to the
| highest bidder
| alephnerd wrote:
| The private sector zero day market collapsed last year with
| Zerodium - corporate bug bounties, nation states in-housing
| offensive security operations, and the democratization of
| knowhow destroyed the Zero Day market.
| nkassis wrote:
| My tinfoil hat says they want to privatize this through one of
| the administrations friends. A disastrous decision here.
| 9283409232 wrote:
| Palantir is about to get a contract.
| goku12 wrote:
| I thought that the point of the CVE database is to improve
| security, not wreck it?
| jacobsenscott wrote:
| s/is/was/
| aprilthird2021 wrote:
| Or worse, NSO Group
| epistasis wrote:
| Why would they spend money to replace it? The idea is to weaken
| and destroy the US and its institutions. Giving Palantir money
| might mean that security improves, and that goes against their
| goals. They have already demanded that Russia stop being
| treated as a cybersecurity threat in other areas of the
| government, this is a way to ensure that systems are vulnerable
| to attack.
| throitallaway wrote:
| Exactly. The Trump admin is well on its way tanking the USD
| with tariffs and getting every country (including the
| penguins) mad at us. The rationalization given by the admin
| for tariffs (trade imbalance) make zero sense, and they
| haven't offered anything else.
| phatfish wrote:
| These sort of government services are always under attack by
| private organizations. The US Gov doesn't have to give
| Palantir or whoever a contract, they just cede the ground,
| give the right people a heads up, and then make the new
| subscription service a "recommended service provider" as a
| solid to whichever of Elon's circle gets the nod.
|
| In the UK the some "entrepreneur" was after monetizing access
| to the Land Registry a couple of years ago. Apparently the
| free UK Gov service was not fit for purpose it needed a
| paywall to make it better. Nothing as globally significant as
| the CVE database, but you can see if the vultures are going
| after small UK Gov services, something like the CVE database
| is absolutely a chance to add to the executive bonus pool.
| markhahn wrote:
| Trump stupidity hurts the country and world.
|
| But maybe this is an opportunity to do CVE better.
| cantrecallmypwd wrote:
| > But maybe this is an opportunity to do CVE better.
|
| Okay, how? This sounds like looking for lemonade in a genocide.
| robertlagrant wrote:
| > This sounds like looking for lemonade in a genocide.
|
| It really doesn't. This level of catastrophising has no
| point. It would be nice if CVE continued to exist, but it
| wasn't close to perfect, and perhaps it can continue in
| another form. There's no particular reason the US taxpayer
| has to sponsor global security threat tracking any more than
| any other taxpayer or customer.
| cantrecallmypwd wrote:
| This is also a myopic argument against funding standards
| bodies that support the internet.
|
| The point of having a global, shared database is a single,
| authoritative (more-or-less), semi-vetted repository that
| can hold vendor accountable externally without digital
| amnesia or downplaying issues, and global unique
| identifiers. If that takes an international nonprofit
| funded by bits of the free world who are okay with
| investing in commonwealth infrastructure, so be it. Those
| who don't understand what they're destroying so casually
| are ignorant, and possibly evil if they do understand.
| robertlagrant wrote:
| > This is also a myopic argument against funding
| standards bodies that support the internet.
|
| No, it's the opposite. Things like this shouldn't be in
| the hands of a single government. They should be
| independent and funded by many parties. The part of your
| message that isn't catastrophisation is agreeing with
| exactly what I'm saying.
| bathtub365 wrote:
| Now the NSA can hoard more 0days and the general public suffers.
| Win win for this administration
| goku12 wrote:
| It's more likely to boost the zero day black market. I don't
| know if I want to attribute this to idiocy (indiscriminate cost
| cutting), greed (contracts for their crony pals) or malice
| (hoarding and trading 0 days).
| gryfft wrote:
| ?Por que no los tres?
| outside1234 wrote:
| These four years are going to be the death of all of us.
| cantrecallmypwd wrote:
| War with China and doing enough reprehensible acts to stoke
| protests to declare martial law to stay in power indefinitely.
| throitallaway wrote:
| I feel like we're only a few weeks away from someone "home
| grown" experiencing an "administrative error." The slide into
| madness continues.
| gryfft wrote:
| More like only a few days away, honestly.
| wiseowise wrote:
| Wait until they start a war against Albania.
| Latty wrote:
| I find it a little incredible people are still talking about
| "four years".
|
| They tried to reject the election result and do a coup, and
| were rewarded for it by getting back into power. They are
| refusing to follow the law or the courts. They are sending
| people to gulags in foreign countries. All the checks and
| balances were destroyed last time. The party has been stripped
| of anyone who would fight the admin or reject this illegality.
| They have set up a power grab over elections.
|
| There will not be free and fair elections in four years unless
| they are simply too incompetent to rig it, the rubicon was
| crossed _long_ ago. Without mass protest that makes it
| impossible for them to hold power, American democracy is dead.
|
| They have tried to do it, they say they want to do it, they
| have the ability to do it, they are actively doing it, and no
| one is stopping them. How are people still acting like in four
| years they are going to neatly hand over power to be prosecuted
| for their crimes?
| SpicyLemonZest wrote:
| Organizing mass protests isn't something you do _instead of_
| organizing electoral opposition. Even in countries that haven
| 't had fair elections for a while, people generally still
| organize opposition and talk about how they're going to vote.
| The best way to ensure your opponents retain power is to go
| around telling people it's too late and they've already won.
| Latty wrote:
| I'm not saying people should not organise to vote, I'm
| objecting to the framing of "in four years this will be
| over" or "in four years we can fight this", if you are
| waiting for elections to solve this alone, that's a
| mistake. Elections _alone_ won 't be enough. It's not too
| late to do anything, it is too late for _just_ voting
| against it to be enough.
| phtrivier wrote:
| I understand you have elections in two years, don't you ? I
| don't know if a complete reversal congress is possible.
|
| That would be a good litmus test. "They" have not prevented
| special elections so far ; if "They" need to prevent the next
| one, whatever they try will happen then, I suppose ?
| Latty wrote:
| I'm British, but I think to expect free and fair election
| in the US in two years is to stick your head in the sand.
|
| I don't see them _preventing_ elections, but just rejecting
| or altering results that don 't support them: the litmus
| test is already triggered: the special election in North
| Carolina has an ongoing court case trying to throw out
| ballots to allow the Republican to win.
|
| They have also pushed a executive order claiming sweeping
| powers over elections which they will use as pretext to do
| this nationally. Blatantly illegal, but they have already
| shown they are ignoring the courts, so who will hold them
| to account? Mass civil unrest is the only thing left.
| atomicbeanie wrote:
| The white house prefers chaos. This will certainly be a step in
| that direction.
| yieldcrv wrote:
| if only there were 188 other countries and an entire private
| sector in each one that could fund this thing they are also
| affected by
| xyst wrote:
| Some companies are already clueless when it comes to CVE
| management. Probably won't see the effects immediately but give
| it a few more years for new generation of vulns to be
| created/found and we will be back to early 2000s level security.
|
| Open season on American corporations for domestic and foreign
| hackers.
|
| If program isn't brought back then CVE database likely to be
| fragmented amongst the "private" CVE databases.
|
| Sec Corp A has 700 well documented CVEs but Sec Corp B has 702
| CVEs in their database since NIST funding pulled. What do corps
| do? Maybe some of them with massive budgets setup contracts with
| both to get "full spectrum coverage". Maybe other non-technical
| companies that think of IT as strictly a cost will go with the
| cheapest or forego it all together.
|
| Who knows maybe we get ~~~free labor~~~ open source community to
| pick up the slack?
|
| This country with the orange man administration is quickly going
| to shit. Not in a "I dislike {opposing party} way" either. In a
| "I dislike authoritarian regimes" way.
| mmooss wrote:
| > In a stunning development
|
| Who is still stunned by these things? They want you to be
| stunned; they want you to tell everyone else that you're stunned
| to spread feelings of terror and powerlessness. If you actually
| are stunned, you are stunningly ignorant. If you are not and
| still saying it, perhaps to emphasize your unhappiness, you are a
| 'useful idiot'. Either way, if you are saying it, you are a
| useful idiot.
|
| You should have known decades ago: The GOP impeached a President
| for lying about sex; they fabricated intelligence to invade
| another country (killing thousands of Americans and 100,000+
| Iraqis) - and that was all before 2004. They've voted almost
| unanimously, multiple times, to bankrupt the country (by refusing
| to authorize debt for existing obligations). Nobody (i.e., the
| Dems failed to) stopped them or made them pay a price, so why
| wouldn't they keep doing those things. (Edit: And if you object
| because the analysis criticizes one side and therefore you reject
| it as partisan, that's a big part of the reason nothing was
| done.)
|
| This time they published Project 2025, telling you what they were
| going to do.
| mcintyre1994 wrote:
| Project 2025 literally calls for dismantling the DHS. Seems
| pretty unsurprising that the CVE database wouldn't be in the
| list of things they'd care to maintain in that process.
| arghandugh wrote:
| This industry relentlessly lionized Trump and Musk, elevating
| them to positions of power and handing them the power to destroy
| at will.
|
| This is your moment! Enjoy it!
| Gigachad wrote:
| It's astounding that the users here watched all the horrendous
| things going on and ignored them. But now the CVE numbers are
| gone it's shocking and too far.
| throitallaway wrote:
| Come again? This is Hacker News, a heavily moderated forum
| with a narrow focus. We don't discuss Israel or El Salvador
| here (unless it's tech related.)
| gortok wrote:
| I would hope the folks that frequent HN would not be so
| insular as to only read what happens on HN and not read any
| other news source.
|
| If you've somehow missed Trump's systematic dismantling of
| academic freedom or his disappearing of folks he doesn't
| like, then we have a far bigger problem than the limits of
| what is discussed on HN.
| flanked-evergl wrote:
| Please, this place has permeated with Trump rage since before
| he took office. The only way you could think he was ignored
| is to not have read any comments.
| pseudalopex wrote:
| > It's astounding that the users here watched all the
| horrendous things going on and ignored them.
|
| Many most voted and most commented submissions were the other
| things.
| Ferret7446 wrote:
| I don't see why this should be publicly funded, so I don't really
| see an issue with this. The industry benefits from having a CVE
| database, so the industry should fund it.
| klysm wrote:
| There are going to be all kinds of messed up incentives if this
| is funded from industry.
| throitallaway wrote:
| True, although Google's Project Zero seems to be run pretty
| well.
| worthless-trash wrote:
| Different goals, not cve related.
| Ferret7446 wrote:
| Like what?
| guhidalg wrote:
| No, "the industry" is all of us alive in the 21st century who
| depend on software to make material decisions and to be
| resilient to attacks and tampering. We were all funding it, and
| now surely we will see some big tech company now assume
| responsibility from the federal government (please god don't
| let it be Oracle...)
| skirge wrote:
| so "all" should pay, not only US taxpayers.
| guhidalg wrote:
| That would be an improvement. Perhaps the UN should fund
| it.
| kristjansson wrote:
| Because secure systems benefit the public generally, not just
| the corporations that make a profit operating those systems.
| maronato wrote:
| The industry won't want to fund it. It'll want to profit from
| it.
| insane_dreamer wrote:
| So you trust industry now?
| sMarsIntruder wrote:
| Same question would be for government funded agencies.
| insane_dreamer wrote:
| No, because the gov funded agencies don't have a personal
| stake in the outcome.
|
| That's why industry regulating itself doesn't work, and why
| government regulations exist.
| Xelynega wrote:
| Don't open source developers and users of their software also
| benefit from the CVE database?
|
| If it were privately funded, what incentive would these private
| companies have to track bugs for these open source projects
| that don't make money?
| sMarsIntruder wrote:
| The insane number of downvotes you're getting for saying basic
| common sense stuff, it's why we should push for stricter
| political rules here in HN.
|
| You didn't say something wrong or controversial, just an
| opinion. Some ideologies love to pay things with other people's
| wallets, and they'll do whatever they can to pursue this.
| sMarsIntruder wrote:
| Especially the L guy who downvoted this after 10 seconds. get
| a life
| the_doctah wrote:
| Why is the government responsible for CVEs again?
| throitallaway wrote:
| Every now and then the government decides to fund things.
| Public schools, roads, police, firemen, GPS, NOAA,
| cybersecurity, government cheese, etc.
| sschueller wrote:
| "the government" aka "We the people". It is in all our
| interest. This is like asking why the government is responsible
| for roads.
| dingaling wrote:
| > This is like asking why the government is responsible for
| roads.
|
| Thought experiment:
|
| If roads were built by private companies, could a Government
| justify the expense maintaining a database of all the
| potholes?
| Xelynega wrote:
| Yes, as it would be a public good to everyone to be able to
| know where the potholes(that aren't profitable to fix for
| these private companies apparently) are so they can avoid
| them.
|
| They might take a step back and realize that it would be
| more cost-effective to just own the roads, in which case
| your thought experiment ends where we are, because where we
| are was a place reasoned to(to an extent).
| pseudalopex wrote:
| Pot holes do not enable fraud, ransom schemes, data
| breaches, denial of essential services to millions of
| people, and so on.
| goku12 wrote:
| Doesn't the government use those software (private and open
| source) to handle private information of citizens and other
| sensitive information? And what about their contractors?
| That alone justifies maintaining such a database.
| jowea wrote:
| National (technological) security?
| wichitawch wrote:
| I'm surprised that it was USA's responsibility to fund this in
| the first place. Why weren't other countries providing funds?
| defrost wrote:
| It's a near certitude that Russia and China each have databases
| of exploitable software errors and prize zero days.
|
| It was to the advantage of the US and allies to coordinate and
| lead in tracking and fixing such errors.
|
| Multiple countries, companies, and individuals contributed
| finding and fixing bugs.
|
| The administrative task of keeping track was one part of a
| greater picture, a part that came with first to be advised and
| other perks.
|
| It's not that the US had a _responsibility_ to take on the lead
| admin task, more that in past times the US saw an advantage to
| being at the centre of global action.
|
| This is just another part of increasing US isolationism.
| wichitawch wrote:
| > It was to the advantage of the US and allies to coordinate
| and lead in tracking and fixing such errors.
|
| From what I understand of the article, none of these allies
| were funding it.
|
| > Multiple countries, companies, and individuals contributed
| finding and fixing bugs.
|
| Clearly that itself isn't enough. Someone has to pay for
| maintaining this service. It appears that no one other than
| USA spent money in funding it.
| epistasis wrote:
| Why would other companies pay for it if they had never been
| asked?
|
| Why would it be shut down without asking for others to fund
| it, if it's some sort of burden on the US?
|
| Programs like this pay for themselves many times over.
| There are only two reasons for cutting this: absolute
| idiocy, or active sabotage of the US.
| lyu07282 wrote:
| Almost every other western country does fund their own
| databases, CVE was just significant because its the one
| central source of truth. its like a standard. Instead of
| having to coordinate with dozens of different registries
| every time you publish a vulnerability you just communicate
| with one instead.
|
| Researchers also don't directly talk with MITRE they go
| through one of the intermediaries that assigns the number.
| insane_dreamer wrote:
| It's called providing leadership. Worth the money. China will
| happily fill the void.
| bamboozled wrote:
| I hate this whole disaster but why can't Europe step in for
| stuff like this?
| Peanuts99 wrote:
| Because they have their own programs for this already.
| lars_francke wrote:
| The CVE program was started over 25 years ago. It is very
| reputable (until yesterday) and it was very much in the
| interest of the US to be seen as the stewards of this.
|
| The funding requirements can't be that high and I'm willing to
| bet that other countries and entities would have happily
| stepped up if they had the chance.
|
| Up until recently CVE was very centralized and only in the last
| few years have there been steps in more decentralization with
| CNAs taking more responsibility, Red Hat as a CNA of last-
| resort etc. So, the cost of doing all of this work has already
| been shifted partially (!) away from the US but I have not seen
| any movement towards e.g. moving the program to a foundation
| which could have been done.
|
| Personally I would conclude that it was the responsibility of
| the US to pay for this because they wanted to and it was in
| their best interest to control this program.
| flanked-evergl wrote:
| They have the chance to step up now. Every Comercial company
| that is supposedly so reliant on this for their very
| existence has the opportunity today. They can fund it.
| lars_francke wrote:
| I mention this in another comment. The infrastructure for
| an alternative is already partially in place.
|
| In my opinion it's mostly the industry needing to adapt to
| a new setup that needs to happen. It was just "easy" to
| rely on what's already there. A lot of company policies
| need to be adapted etc.
| epistasis wrote:
| What commercial company is going to "fund" this? It's such
| a strange idea, disconnected from the real world. You may
| as well say "companies can start doing road maintenance, as
| they are so reliant on them for their very existence."
|
| And perhaps if there had been more than a days notice, some
| consortium could be pulled together, but who's going to
| pay? Why would private companies do this, how do they
| profit? CVE program was the roads that everybody could
| drive on.
|
| The basic lack of understanding of how the world works is
| killing the US. Why do people think we have such a massive
| GDP? Where do people think that comes from? We've given
| control of everything in society over to our dumbest and
| greediest members that have no clue about how anything
| works.
| flanked-evergl wrote:
| Ask the person I was responding to:
|
| > I'm willing to bet that other countries and entities
| would have happily stepped up if they had the chance.
| drstewart wrote:
| >but who's going to pay?
|
| The EU. They can have all the massive advantages that
| funding MITRE will give them. Why won't they step up to
| the plate? It's killing the EU and they have absolutely
| no idea how anything works. It's why they're a dying
| empire.
| flanked-evergl wrote:
| I will bet money that removing the cap from a bottle will
| be a hate crime in Europe before they start funding a
| institution like MITRE that actually functions.
| happosai wrote:
| Because USA was a superpower that can afford it easily. Taking
| the leadership in everything is quite cheap price to pay when
| the other end of the bargain is everyone else has to follow
| you.
|
| Now of course USA is ceasing (voluntarily, by stripping down
| every international soft power effector in government) to be a
| superpower, to the great glee of dictators all around the
| world.
|
| The "we can't afford being great" is a direct admission that
| USA is no longer a superpower. And is not going to become great
| again, just another nation again (at whims of China).
| lyu07282 wrote:
| The nazis don't think that though, uh I mean conservatives.
| After they've burned down everything, they expect still to be
| a superpower somehow. Do they think they can just start a war
| with everyone who doesn't play ball? It's hard to comprehend
| what their rational is, if there is one.
| aabhay wrote:
| I'm surprised that the world's greatest universities are in the
| United States. Why weren't other countries providing funds?
| toyg wrote:
| Don't worry, that will also end soon. Regimes that require
| political subservience from universities, like the current US
| administration, inevitably result in poor research
| capabilities in the long run.
| tdb7893 wrote:
| The US has made at least hundreds of billions of dollars from
| it's tech companies and has had a dominance over global tech
| for a long time. The tech industry has brought a crazy amount
| of money and power to the US so it makes sense the US puts
| extra effort to support it.
|
| The US isn't supporting it out of charity, it's good for US
| businesses to have someone coordinating this for everyone. Why
| would we want to rely on other countries to be supporting our
| tech sector? At least now we are subject to only the capricious
| whims of our own government, as little comfort as that is right
| now (if another country was funding it we would be relying on
| the whims of a foreign government, which isn't ideal when tech
| is the golden goose of your modern economy).
| jeroenhd wrote:
| It's a program the US government spun up to serve America's
| interests. Why would someone else pay for American interests?
|
| Other countries have their own programs, some cooperating with
| the US, others separate. China has the CNNVD if you're
| interested in helping Chinese society safe. My government
| operates https://advisories.ncsc.nl/advisories to serve my
| country's interests.
|
| Of course, the US is free to abandon their programme and rely
| on Chinese, Russian, and European vulnerability databases to
| keep their country safe. It does save them a couple of million
| after all!
| phtrivier wrote:
| Because, contrary to popular views, there is no "government of
| the world".
|
| So, since the US government needed that (it provides security
| to US businesses), they organised and funded it (as everything
| else, with US taxpayers money, and savings from investors in US
| and abroad.)
|
| Now, the US government decided to commit temporary-seppuku, so
| a number of things will happen:
|
| * state-level government will use their local-taxpayer money to
| fund similar efforts (with duplication of effort), or share it
| with everyone
|
| * another country or block of country will do it, and decide
| whether they want to "share". (I suppose Russia and China have
| more of an incentive to keep their CVE DB private, given their
| level of dis-integration with US economy ? EU maybe ?)
|
| * an international, ad-hoc organisation is created to share the
| funding (something like NATO.) Multi-latteralism is not exactly
| in fashion this days, but if EU does it, it will be
| "international" by design since we're not really a federation ;
| so, states in "Southern Canada" are welcome to join.
|
| * or none of that happens, the CVE db rots for a while, until a
| sufficiently embarrassing cybersecurity problem occurs, and the
| CVE db is deemed worthy of the "10% you need to bring back" by
| President Elon.
|
| Pray your company, families and friends are never on the wrong
| side of the "reverse-Chersteron's fence".
| rurban wrote:
| So who will maintain it then? Either the EU or China I suppose.
| They can easily fund it.
|
| Maybe the Dutch should go ahead.
| lars_francke wrote:
| ENISA in Europe has the mandate of building a EU vulnerability
| database for the NIS 2 directive anyway and it's coming soon...
|
| And CIRCL in Luxembourg are providing vulnerability-lookup
| which can also assign IDs but in a more decentralized way:
| https://www.vulnerability-lookup.org/documentation/
|
| VulnerableCode can help with discovery etc.
| https://vulnerablecode.readthedocs.io/en/latest/introduction...
|
| So, parts of this are already in place and I assume this will
| be a big boost towards a new vulnerability ecosystem.
| esnard wrote:
| This sounds like good news, thanks!
|
| Do we already have an ETA for the ENISA vulnerability
| database?
| jeroenhd wrote:
| Us Dutch have https://advisories.ncsc.nl/advisories although a
| lot of that is just analysing CVEs and their impact on society.
|
| An EU solution would probably be much better. Would suck for
| Americans, though, they'd need to get up early to meet European
| office hours.
| cbondurant wrote:
| Am I missing something or was this literally announced with less
| than 24 hours of warning that one of the critical components to
| the cyber security landscape was disappearing.
|
| What the fuck are you supposed to do about this. This is
| something that should have had multiple MONTHS of warning in
| order to allow those who depend on the CVE infrastructure to plan
| what to do next with their security posture.
| mrtesthah wrote:
| Consider this part of the attack on the American
| infrastructure, economy, and society. Attacks do not abide by
| laws, official procedures, or come with warnings.
| pjc50 wrote:
| CVE-zero: the attack is coming from inside the White House.
| cookiengineer wrote:
| If there are any Europeans here, I'd love to make my
| vulnerability database that's accumulated from all linux security
| trackers and the CVE/NVD open source if I can manage to find some
| folks who'd help with maintenance.
|
| Currently hosting costs are unclear, but it should be doable if
| we offer API access for like 5 bucks / month for private and 100
| / month for corporate or similar.
|
| Already did a backup of the NVD in the last couple hours,
| currently backing up the security trackers and OVAL feeds.
|
| Gonna need some sleep now, it's morning again.
|
| My project criteria:
|
| - hosting within the EU
|
| - must have a copyleft license (AGPL)
|
| - must have open source backend and frontend
|
| - dataset size is around 90-148 GB (compressed vs uncompressed)
|
| - ideally an e.V. for managing funds and costs, so it can survive
| me
|
| - already built my vulnerability scraper in Go, would contribute
| it under AGPL
|
| - already built all schema parsers, would contribute them also
| under AGPL
|
| - backend and frontend needs to be built
|
| - would make it prerendered, so that cves can be static HTML
| files that can be hosted on a CDN
|
| - needs submission/PoC/advisory web forms and database/workflow
| for it
|
| - data is accumulated into a JSON format (sources are mixed non
| standard formats for each security tracker. Enterprise distros
| use odata or oval for the most parts)
|
| If you are interested, write me on linkedin.com/in/cookiengineer
| or here.
| f_devd wrote:
| Maybe something to bring up to one of these e.V.'s if it ends
| up being difficult to get started: Codeberg.org, nlnet.nl,
| ccc.de
| tagyro wrote:
| +1 for ccc.de
| cookiengineer wrote:
| Codeberg might be a nice cooperation partner for hosting the
| git repositories. Gonna write them!
|
| I'm also visiting the local CCC chapters here this week,
| maybe it makes sense to have a separate e.V. where the CCC
| chapters are beneficiaries?
| weinzierl wrote:
| Try to talk to the people from the Sovereign Tech Fund, they
| have a history of sponsoring security relevant projects in the
| EU.
| jauco wrote:
| And maybe the sidn fund?
| decide1000 wrote:
| Nlnet for opensource
| Sander_Marechal wrote:
| Yes, maybe reach out to Michiel Leenaars from the NLNet
| foundation. But IIRC NLNet mostly funds shorter
| development tracks, not ongoing upkeep/maintenance.
| NekkoDroid wrote:
| > Sovereign Tech Fund
|
| It's actually been upgraded to the Sovereign Tech Agency now
| greenRust wrote:
| Great idea. I'm interested in helping. I'll dm you.
| Ucalegon wrote:
| The EU should just buy MITRE. Move it to the EU and make it a
| EU based project.
| panny wrote:
| This would be hilarious. That would be a good thumb in the
| eye to the current administration who complained long and
| loud about how Obama let ICANN leave US possession. Just
| imagine the campaign commercials in 2026,
|
| >The POTUS transferred our cyber defenses to the EU
|
| Ouch
| rob74 wrote:
| Well, that's kind of the point? The current administration
| doesn't care about cyber defense, any less than it cares
| about protecting the environment, protecting consumers,
| having top-notch universities and research, foreign aid
| etc. etc. Actually, it takes pride in not caring about all
| of these things.
| Ucalegon wrote:
| Not to mention the administration aren't going to be held
| accountable for, or actually be impacted by, the harms
| that come for their actions.
| rocqua wrote:
| My guess is that they feel they are supplying something
| the whole world is benefiting from, and they believe that
| unfair. That ignores the fact that the US benefits
| immensely from this, and that they benefit domestically
| from providing that benefit more widely by getting a lot
| of free contributions from the outside. But the US foots
| the bill of those who do get payed, so its unfair...
| fragmede wrote:
| It's so unfair that I have an great job so I can treat my
| friends to dinner all the time! I hate being rich.
| imcritic wrote:
| It's rather "I know I'm rich, but why do friends expect
| ME to pay for dinner all the time? It's so unfair!".
| clort wrote:
| Its a bit like when you are a two-bit loser but have a
| private island where you can do whatever you like, and
| invite every celebrity you can find over to party every
| weekend, then start complaining that they haven't paid
| any of the island running costs and that they are all
| spongers because you are the main attraction of the
| island parties.
| pyrale wrote:
| Another analogy: my friends and I often eat at the
| restaurant I own, and occasionally, I pick the tab. I
| complained angrily about it, and now they want to try out
| other restaurants or dine at home.
| chillingeffect wrote:
| And at the best restaurants! And I get to choose the
| restaurant! And choose when we eat! And pick the
| appetizers, drinks, entrees, and desert!
|
| So instead I will allow myself to be robbed and we'll all
| share the cost of a low-key restuarant. Or maybe let's
| charge each other to eat together, yeah!
| chillingeffect wrote:
| This american admin doesnt seem to understand the
| benefits of leadership. Like being de facto currency,
| ability to operate while deep in debt, etc.
| 1659447091 wrote:
| > The current administration doesn't care about cyber
| defense, any less than it cares about protecting the
| environment
|
| On the contrary, I would argue that they deeply care
| about the environment. The REAL point of all those tit-
| for-tat tariffs with China including with small
| mail/packages are to drastically cut cargo/shipping
| emissions. The threatening of annexation of Canada? That
| was really to get ~70% reduction in air passenger traffic
| BECAUSE they care about the environment. Same with
| creating a few high profile border horror story incidents
| against nationals from allied countries. The real point
| of it? Reduce transoceanic air passenger loads and save
| the environment. /s
| jibal wrote:
| You need to make that /s more prominent.
| nottorp wrote:
| HN is extremely humour challenged. I suppose the majority
| fails to put a monetary value on it...
| jonnybgood wrote:
| MITRE is a non-profit. All the EU has to do is reach out to
| MITRE and be willing to fund the project.
| Ucalegon wrote:
| I know that they are a 501(c)3, but they have significant
| revenue and intellectual property, so in order to do the
| lift and shift, there would need to be some money changing
| hands to accomplish it. Not only that, but being owned by
| the EU gives the ability for MITRE employees to have the
| option to immigrate to the EU to protect against any
| retaliation.
|
| I cannot believe I am typing that second sentence, but here
| we are.
| bkor wrote:
| > Not only that, but being owned by the EU gives the
| ability for MITRE employees to have the option to
| immigrate to the EU to protect against any retaliation.
|
| According to which rule would "owning by the EU" result
| in an option to immigrate? Immigration is handled on a
| per country basis. I don't see how the EU provide such an
| option.
| labster wrote:
| The EU can accomplish it with diplomacy. It's unknown
| technology in America, but diplomacy and asking to work
| together is truly powerful.
| bkor wrote:
| > The EU can accomplish it with diplomacy.
|
| Agree. It'll likely happen that way. Still, dislike the
| initial incorrect assertion.
| Ucalegon wrote:
| https://eur-lex.europa.eu/eli/dir/2009/50/oj
|
| The EU has agreed upon programs in order to bring in,
| through an immigration policy, high skilled persons from
| non-member states. More importantly, working within the
| member nations, as to which member nation would want
| MITRE to be located within their borders, is not
| something that is a hard sell given that it has economic
| advantages for whichever state(s) onboard MITRE.
| graemep wrote:
| That still leaves decisions on who to admit to states. As
| far as I can see its main effect is to allow people
| admitted to one country as highly skilled to travel to
| (not live in) other countries?
| bkor wrote:
| > The EU has agreed upon programs in order to bring in,
| through an immigration policy, high skilled persons from
| non-member states.
|
| Where in this is the option that the EU provides an
| option to immigrate because the EU owns something?
|
| I'm very well aware of knowledge workers. It's not
| something the EU can provide as an option. What you
| linked to is the legal framework around how EU members
| can provide such a thing.
| Cthulhu_ wrote:
| I think all the big companies that owe their ongoing
| business should band together and fund it. No way an
| organization like this should rely on just one sponsor.
| 2b3a51 wrote:
| I think that I'm in favour of pricing in externalities
| like this.
|
| What cross-industry organisations exist that could
| coordinate?
| dev_l1x_be wrote:
| Non-profit means (in this case) payed by somebody who does
| not have anything to say about the transaction. It would be
| better to pay for it so that people who are interested in
| this subject have a say.
| elric wrote:
| I don't think the EU has any interest in this. They've been
| aware of the risk of relying on the US for software security
| for years, but AFAIK there have been no efforts to do
| anything about it. Maybe the current situation will kick some
| butts into gear ...
|
| Off topic: your username is very appropriate given the
| situation.
| FirmwareBurner wrote:
| _> They've been aware of the risk of relying on the US for
| software security for years, but AFAIK there have been no
| efforts to do anything about it. _
|
| Indeed. Just as Germany knew their economy is vulnerable to
| Russian gas and did nothing about it, even after the 2014
| invasion of Crimea. Just as the west knew moving their
| entire manufacturing sector to one country would make them
| vulnerable, but choose to ignore it because it was too
| profitable.
|
| I never _EVER_ saw politicians act proactively for the good
| of the nation or the people, all they do is act reactively
| after the shit hits the fan to control public opinion and
| blame someone else to make sure they get re-elected, that
| 's it.
|
| Once you realize our rulers aren't competent at their jobs
| or acting in the peoples' best interest, it all makes
| sense. They're in it for the grift and to enrich their
| monopolistic friends in the private sector, to make sure
| line goes up in the next quarter, that's it.
|
| Yes, I know there are good politicians out there who care
| and fight for their local communities, but they never make
| it to rule at national or international stage and actually
| change the rotten system because the status quo doesn't
| allow that.
| concordDance wrote:
| > I never EVER saw politicians act proactively for the
| good of the nation or the people,
|
| This is almost certainly because those cases don't make
| the news.
| FirmwareBurner wrote:
| They do where I live, but those are drops in the bucket
| compared to the industrial scale theft(wealth transfer)
| the central government operates.
| ameister14 wrote:
| Well, in the United States it doesn't make the news.
| exceptione wrote:
| Yup.
|
| Politicians react to the public when it stands up.
| Otherwise it will follow other agenda's.
|
| That is why it is critical to have an informed public.
| When journalism has to compete with corporate owned Fake
| News and Entertainment, journalism dies, and democracy
| will follow. Then, add the spy business of Big Tech in
| the mix, with algorithmic silo's. The people don't even
| realize they are locked up in a jar, where they live on a
| diet of cultural engineering.
|
| Now, pause a moment and think about what happens when you
| add AI-models to the mix. Your daughter, your neighbor
| will be totally brain-wrecked.
| FirmwareBurner wrote:
| _> When journalism has to compete with corporate owned
| Fake News and Entertainment, journalism dies, and
| democracy will follow. _
|
| Which journalism are you referring to? The one owned by
| Rupert Murdoch? The Washington Post owned by Jeff Bezos?
| MSNBC? CNN? Are they better just because they're owned by
| different billionaires and interest groups?
|
| I got news for you, the journalism you knew died a long
| time ago.
| xolox wrote:
| American independent journalism seems to be dying
| (unfortunately) but I think in Europe there are several
| large news organizations reporting on things that matter
| in a relatively independent fashion, at least a lot more
| independent than what we see happening in the US (I'm
| thinking of e.g. The Guardian, Le Monde, I could also
| name a couple of Dutch news sources, but they would mean
| nothing to 95% of the readers here).
| exceptione wrote:
| That is not news to me (see my post history). The
| information landscape in America is segmented, and works
| to keep the Big Picture out the frame. To quote myself:
| - No real journalism, instead, career in media house
| depend on commercial ownership. Narratives tailored to
| segment, but no deep and critical analysis.
| - "Let us talk about the tariffs today, they make zero
| economic sense" - "I think what he meant is..."
| - "Of course this is not entirely correct, but..."
| - "President Trump has said.." - "Rubio did a
| press conference today" - Only drama, never
| the Big Picture. - Elections? According to
| the press, those are just - The latest polls!
| - Repeat marketing from spin doctors at affiliated media
| houses - "Debate" = Reality TV, scores are
| given on wit and emotional play
|
| As an English speaker, you have one option and that is to
| read The Guardian.
| jibal wrote:
| It's certainly because they have a belief based in
| ideology, not fact.
| sharpshadow wrote:
| Germany had with under the best deal for gas possible
| with Russia, I don't understand the sentiment calling it
| a vulnerability. There is still a working pipeline
| available and Russia stated clearly if would continue
| delivering gas, if Germany wants to.
| FirmwareBurner wrote:
| _> I don't understand the sentiment calling it a
| vulnerability_ - You're Germany. -
| You join NATO for protection from Russia, an actor with a
| long history of military aggression[1] - Your
| export economy is based on manufacturing. - The
| energy driving your manufacturing sector is ~60% cheap
| gas from Russia, your military aggressive partner.
| - Russia invades Georgia in 2008 and Ukraine in 2014 to
| no ones surprise - Leaders of USA and Eastern
| Europe warn you of Russia's influence on your economy
| - You ignore all this and build another gas pipeline from
| Russia - You are surprised Russia invades
| Ukraine(again) and gas sanctions cripple your
| manufacturing economy
|
| MFW German leaders and HN commenters see no vulnerability
| in this.
|
| Someone please stop the planet, I wish to get off, my
| sanity can't handle this level of stupidity anymore.
|
| [1] https://natoassociation.ca/a-timeline-of-russian-
| aggression/
| everythingisfin wrote:
| > Someone please stop the planet, I wish to get off, my
| sanity can't handle this level of stupidity anymore.
|
| News from an American here, on an antidepressant and
| deathly fat from stress eating:
|
| I'm worried about the eventual welfare of those
| protesting. I'm hearing that people of color are being
| told by their pastor to stay home rather than protest so
| as not to risk being used as scapegoats.
|
| My family and friends are divided and still dividing over
| politics. I recently was crazily ranted to by big-
| personality entrepreneur immigrant that told me his story
| of how easy it was to come to the states, rags-to-riches,
| and how they were supporter of the administration because
| "they don't want to pay taxes for illegals". Part of the
| half of the U.S. that supports the administration isn't
| just brainwashed, but has a very strong, angry, and
| desperate look, and the other part says "just wait four
| years and it will be over", but it won't; before the
| election, this party used gerrymandering and legal action
| to ensure that election, then post-election replaced
| election officials and many government officials.
|
| The DOE is claiming anti-semitism and the need to have
| viewpoint diversity to deny funding to schools that are
| known for their open viewpoints.
|
| And yet somehow I'm still surprised when they kill the
| CVE program.
|
| It's an ever-escalating circus of chaos, because our
| administration thinks this was needed to ensure U.S.
| interests, because those vulnerable in the U.S. were
| manipulated by outside actors and internal power-hungry
| politicians and zealots, and all is spun to just feed
| into the chaotic nationalism that is trying to one-up
| every other dictator that has ever lived.
|
| To top all of this off, AI, which I use daily, will take
| my job before I retire, and I have no backup plan.
|
| Despite all of this, I have the will to live, to support
| those whom I love (even the crazy ones), and to try to
| make the world better. I continue to pray for direction
| on all of this.
| belter wrote:
| Follow the money...
|
| "German journalist dubbed the 'Putin connoisseur' had
| secret book deal with Russian oligarch" -
| https://www.icij.org/investigations/cyprus-
| confidential/germ...
|
| "Russia's best friends in Germany: AfD and BSW" -
| https://www.dw.com/en/russias-best-friends-in-germany-
| afd-an...
|
| "12 Germans who got played by Putin" -
| https://www.politico.eu/article/blame-germany-russia-
| policy/
| holoduke wrote:
| The sources you mention are straight out of a propoganda
| handbook. Not worth the read and hugely fabricated fake
| sensational news.
| belter wrote:
| Instead of countering a single fact, you labeled the
| whole thing. That's usually how people protect a
| narrative, not challenge one.
| ta1243 wrote:
| Politico, ICIJ and Deutsche Welle are hardly unknown
| fringe sources with shady backgrounds
| rostigerpudel wrote:
| Except what Russia states and what Russia does are only
| aligned when it serves Russia. Russia stopped delivering
| gas through NordStream 1. After that, Germany took note
| of the danger and decided it would do better without that
| dependency.
|
| https://www.aljazeera.com/economy/2022/9/2/russias-
| gazprom-k...
| m000 wrote:
| > Germany took note of the danger and decided it would do
| better without that dependency.
|
| So they just swapped dependencies. And it's not that the
| new dependency will have no strings attached.
|
| Diversifying while keeping russian energy in the loop, as
| part of a risk-management strategy, would make more
| sense. Completely cutting off russian energy just gives
| more bargaining power to their new energy provider.
| throw__away7391 wrote:
| If we put half the effort into shoring up our
| institutions and reinforcing our shared norms and
| cooperative values as we are into "de-risking"
| everything, right now, and all at once, we'd all be in a
| much better place. Overnight we all just accepted that
| this new transactional, mercantile, hostile mentality was
| the way of things and the only way it can be. This is a
| self-fulfilling fatalistic prophecy and is going to move
| us backwards into a much worse, less prosperous world,
| empowering the bullies and the tyrants even more.
|
| Greed got us here. There's a rules based world possible
| where Russia sells gas to Germany. Russia did not
| transform from an free and democratic society with
| respect for human rights and the international community
| into an authoritarian dictatorship overnight; we turned a
| blind eye to this when it suited our short term economic
| needs and that is how we allow ourselves to sleepwalk
| into the situation we are now. Had we held first to our
| principles we'd have either had the impact the neoliberal
| trade focused policies were supposed to eventually
| deliver or at the very least not ended up with
| dependencies that gave such governments leverage and
| eventually blow up in our faces. Had we instead put human
| rights first and foremost we would not have created and
| empowered these monsters.
|
| Same thing with Trump's reelection in the US. By all
| rights in a functioning democracy Trump should be sitting
| in jail right now along with the January 6th
| insurrectionists. The Biden administration had 4 years to
| prosecute, but felt it was not politically expedient to
| do so. Likewise what is left of the GOP within the
| republican caucus right now faces a similar choice
| between short term benefits and upholding the principles
| which nearly everyone in congress and even the Trump
| administration has previously claimed they would uphold.
| m000 wrote:
| > Had we held first to our principles
|
| *our alleged principles
|
| Something can't be called a "principle" when it is only
| selectively applied.
| usrusr wrote:
| Except that Russia did not deliver (not any meaningful
| amount anyways), when the pipelines were still intact.
| And yes, they pretended to be willing, firing off a
| series of excuses sufficiently transparent to make it
| clear between the lines that it's a demonstration of
| power. Get your history straight: "Russia stated clearly
| if would continue" has between zero and negative value.
| nosianu wrote:
| > _There is still a working pipeline available and Russia
| stated clearly if would continue delivering gas, if
| Germany wants to._
|
| You conveniently leave out that _minor detail_ that it
| was RUSSIA who stopped the gas.
|
| Germany tried hard to keep it going, even making a
| sanction-exemption or a Siemens turbine repaired in
| Canada, which according to Russia was needed. Only that
| when they were to receive it nothing happened, gas
| stopped anyway.
| sharpshadow wrote:
| Nordstream 1 which had if I recall correctly one working
| turbine left and went into inspection during which an oil
| spill was noticed and the restart of the service was
| postponed. Shortly after Nordstream 1 Pipeline A + B and
| Nordstream 2 Pipeline A was been blown up. It's up to
| debate if the oil spill which was uncovered during the
| inspection which postponed the gas delivery was a
| political move. The turbine, which underlies sanctions,
| should have been still in transit during that time and
| even if delivered useless.
|
| There is still Nordstream 2 Pipeline B intact available
| to deliver gas and it uses Russian made turbines compared
| to Nordstream 1.
|
| The whole discussion is very special to say the least if
| you leave out that some adversary blow up the
| infrastructure.
| nosianu wrote:
| Russia _refused_ to accept the turbine! It was in
| Germany, and Russia blocked the delivery.
|
| "Moskau blockiert offenbar Weitertransport von Nord-
| Stream-1-Turbine" ("Moscow apparently blocks further
| transport of Nord Stream 1 turbine") --
| https://www.rnd.de/politik/russland-blockiert-offenbar-
| weite...
|
| I'm German, I followed those developments closely at the
| time. Russia refused to deliver gas! The blowing up of
| the pipes happened quite some time after that!
|
| You also don't mention that German Gasprom, which
| controlled German gas reserves, emptied them just before
| the war! -- https://www.faz.net/aktuell/wirtschaft/gas-
| speicher-in-deuts... (German, paywall), --
| https://www.zeit.de/news/2022-01/21/ungewoehnlich-leere-
| gass...
|
| That shows that Russia prepared for using gas as an
| economic weapon against Germany especially well before
| they even started the war.
|
| From the Zeit article:
|
| German
|
| > "Die Gasflusse uber die deutschen Grenzen sind unublich
| niedrig fur diese Jahreszeit - mit Ausnahme von Nord
| Stream 1, die sind konstant hoch", sagt Fabian Huneke. Es
| sei verwunderlich, dass vor dem Hintergrund der hohen
| Preise und der hohen Nachfrage die Gaslieferkapazitaten
| Richtung Europa so wenig genutzt wurden. "Wenn Gazprom
| sich marktrational verhalten wurde, wurden sie die
| Gaslieferungen nach Europa auch durch die Pipelines, die
| durch Belarus und die Ukraine fuhren, verstarken." Den
| Grund fur dieses Verhalten sieht der Energiemarktexperte
| in der Ukraine-Krise.
|
| English, translated by Google
|
| > "The gas flows across the German borders are unusually
| low for this time of year - with the exception of Nord
| Stream 1, which are consistently high," says Fabian
| Huneke. It is surprising that, given the high prices and
| high demand, the gas delivery capacities to Europe are so
| little used. "If Gazprom behaved in a market-rational
| manner, they would also increase gas supplies to Europe
| through the pipelines that run through Belarus and
| Ukraine." The energy market expert sees the reason for
| this behavior in the Ukraine crisis.
| thaumasiotes wrote:
| > Moskau
|
| Tangentially... how did the German name of the
| city/region get into _that_ form? Is it a loan from
| English?? Germany and Russia have been closely entwined
| for centuries.
|
| Wikipedia has a comment which appears to make no sense:
|
| > The [old] form Moskovi has left traces in other
| languages, including English: Moscow; German: Moskau;
| French: Moscou; Portuguese: Moscou, Moscovo; and Spanish:
| Moscu.
| detaro wrote:
| Seems its actually (in both German and English) developed
| from older Russian forms, and Russian shifted afterwards
| again: https://en.wikipedia.org/wiki/Moscow#Etymology
| thaumasiotes wrote:
| But all of the older forms include a /v/. How did that
| drop out of every language except Portuguese?
|
| (There is an English term _Muscovy_ for the region, but
| wiktionary suggests that it derives from the formal name
| given to the region in international Latin rather than
| deriving from Russian. In that case, a /w/ would also
| generate a letter V, so there's no explanatory power.)
| pyrale wrote:
| U, v and w are all derived from the same letter v, for
| which no distinction existed in latin (same for i, j and
| y).
|
| Apparently, when different languages started to make the
| distinction, they picked a different letter combination:
| ov, ou, ow, au, u, etc. probably depending on the local
| way of pronouncing the word.
|
| Same for latin ivvenis, modernized to juvenis, which gave
| young, jeune, jung, joven, etc.
| sharpshadow wrote:
| The transport of the turbine was accompanied by sanctions
| and each party didn't wanted to get punished, awaiting
| exemption documents for delivery. As the article already
| states in the headline and further acknowledges in the
| content Russia was not refusing to get their turbine back
| but waiting for documents themselves which the article
| beautifully conceals with the little word 'apparently'.
|
| The unusual low gas storage reserves at the beginning of
| the year 2022 in Germany with 45% compared to usual 75%
| while Nordstream 1 is delivering at full capacity could
| be related to the sanctions which lead Poland to stop
| transit through the Jamal pipeline and other transit
| routes through Ukraine and possibly gas market trade
| activities. Having just the 'economic weapon' argument is
| lacking, especially in regard that Russian gas is still
| to today reaching Germany and it is in the interest of
| Russia to deliver.
| javier2 wrote:
| NordStream 1 had been stopped from Russian side for
| nearly 4 months before this, with constantly shifting
| goal post excuses.
| chillingeffect wrote:
| Perfect exmple of the "one-deep" conservative response.
|
| PP is looking for a pattern, finding, and abstaining from
| questioning or contextualizing it:
|
| Engaging only with the first or most obvious layer of an
| issue--never going deeper into context, nuance, or
| systemic causes.
|
| The quickest counterexample that comes to mind is
| Elizabeth Warren's Consumer Financial Protection Bureau.
| It has returned billions to American citizens.
| FirmwareBurner wrote:
| I'm gonna have to stop engaging with you here if you
| start a comment by accusing someone to be a conservative.
|
| If your first reaction is putting people into
| political/ideological camps in order to make their
| arguments weaker and easier to attack form a holier than
| though political/ideological angle, it's game over for me
| as I like to judge actions objectively based on the
| outcomes, not conservative vs democrat, left vs right,
| etc. since corruption and incompetence is colorblind.
|
| I don't care which side of the political isle did what,
| I'm pointing at the systemic failures of the entire
| system built like a house of cards by all political
| parties, which collapsed as no thought was put into
| building it, and only chased short term profits at the
| expense of long term security. Trying to finger point a
| single political side only detracts from the issue which
| is the classic "divide and conquer" tactic politicians
| have been using to deflect blame and get away with it.
| bsenftner wrote:
| It is damningly simple, the root cause beneath far too
| many issues our advanced civilization faces: we have a
| global adult immaturity issue, species wide. The leaders
| that are crony capitalist and widely populist are in
| truth terribly immature public figures. Our incredibly
| short sighted (also an immature behavior) news and
| analyst media pretends to be adult while never really
| having any solutions that are not plain school yard
| bullying and tribe glorifying. And the public is only
| allowed outsider fringe opportunities to include their
| voice in these public non-debates. We do not produce
| adults anymore, we produce a civilization of Lindsay
| Lohans that think they are adult men and women.
| dsr_ wrote:
| If capitalism is allowed to operate without regulation,
| it corrodes.
|
| If government is allowed to operate without regulation,
| it corrodes.
|
| The pattern is clear. Unchecked power imbalances are bad
| for everyone, but the folks at the top of a power
| imbalance generally advocate for it, and change the
| environment to ensure their power and reduce everyone
| else.
| bsenftner wrote:
| What is that aspect of humanity that causes unchecked
| power to imbalance anyone and everyone? I'm saying it is
| unchecked immaturity. Recognition is step one. If the
| species identifies en mass there is an unchecked
| immaturity issue in adults, a huge amount of it will
| evaporate, and people will be given an excuse to start
| calling other adults on their immaturity. Harsh, but
| necessary as the immature are actively justifying
| destroying people all over the place.
| Lendal wrote:
| The death of Occam's razor, because protecting one
| sensitive person's tribal political identity is more
| important than solving the problem.
| belter wrote:
| https://www.enisa.europa.eu/topics/vulnerability-disclosure
| ta1243 wrote:
| I thought exactly the same until
|
| https://euvd.enisa.europa.eu/
|
| Appeared on the front page, with (c) 2005-2024 by the
| European Union Agency for Cybersecurity.
|
| This is just an example of US cultural defaultism.
| belter wrote:
| This should be work for the ENISA:
| https://www.enisa.europa.eu/
|
| https://www.enisa.europa.eu/topics/vulnerability-disclosure
|
| They have a tender going on tracking best practices:
| https://www.enisa.europa.eu/procurement/vulnerability-
| disclo...
|
| So they will take 12 months to select for the tender...18
| months pondering on the report...and in 3 years they make a
| tender out for a solution...
| Xelbair wrote:
| oh but you forgot the mandatory time before they even start
| considering the tender.
|
| looking at average speed of bureaucracy in EU it will take
| roughly a year to set date for a meeting that will set the
| date for actual meeting which will decide if this will go
| forward or not....
|
| (if you think i'm joking - i'm basing this on proposed EU
| initiative for nuclear power which started with setting a
| date of meeting to setup a meeting to draft an agenda)
| _joel wrote:
| 100% - I wonder if this is partly by design.
| nottorp wrote:
| I'm kind of thinking of Frank Herbert's BuSab here...
| mvandermeulen wrote:
| Sir Humphrey ran that meeting if I recall correctly
| belter wrote:
| The five stages of creative inertia:
| https://youtu.be/PcghKtd-yP0?t=23
| juicyyy wrote:
| Im also interested in helping
| JimBlackwood wrote:
| I'm interested to help! I added you on LinkedIn, so will
| message there after you accept. :)
| anontrot wrote:
| Try if you can find some help here https://openssf.org/
| wustus wrote:
| Depending on deployment strategy I could help with Kubernetes
| stuff.
| sneak wrote:
| The AGPL is a nonfree (and nonsensical) license.
|
| There's nothing wrong with normal GPL.
| lifthrasiir wrote:
| Is there a non-free license approved by FSF and OSI and
| compatible with DFSG?
| goodpoint wrote:
| There are already many security trackers, why writing a new
| one? The issue is paying people to handle the advisories.
| cookiengineer wrote:
| I agree with you there. Before CISA got sacked / taken down,
| they were working together with the BSI and other CERT
| agencies on a vulnerability exchange format.
|
| This might be the optimum time to implement CSAF and to lead
| by example when it comes to vulnerability disclosures.
| harrisi wrote:
| I'm not European but I'd love to help.
| mwe-dfn wrote:
| The European, GDPR compliant subnet of the Internet Computer
| could suit your needs. The app would be decentralized out of
| the box and it can't be shut down by a single entity like a
| traditional cloud provider or nation state. Hosting 100GB costs
| about 500$ per year [0]. This is not a traditional hosting
| provider, it's a decentralized cloud. Reach out on the forum
| [1] or to me if this sounds like a good fit to you (I think it
| does, from your list of requirements).
|
| [0] https://internetcomputer.org/docs/building-
| apps/essentials/c... [1] https://forum.dfinity.org/
| immibis wrote:
| Or just use a normal host where hosting 100GB costs about
| $60.00 per year.
| vachina wrote:
| My 4TiB seedbox at home costs $5 in electricity.
| mwe-dfn wrote:
| As mentioned in the response to the sibling, I am not just
| talking about hosting the data, but also running the app.
| Ofc, with a lot of traffic the running costs would
| increase.
|
| The reason for the higher price is that both data and
| running software is redundant and decentralized by design -
| no need to configure anything.
| f_devd wrote:
| Seems way overkill & unnecessary. Wouldn't the e.V.
| (foundation) especially with FOSS backend/frontend already
| ensure continued operation? Also if it's about
| redudancy/resilience it seems like good ol' torrent/ipfs or
| even a dedicated dht (if you really want to have fast updated
| content) would be much more efficient.
| mwe-dfn wrote:
| >FOSS backend/frontend
|
| That phrase does not address where and how to host data and
| run software, and while I think an e.V. would be a great
| idea, it also does doesn't address it. So these concerns
| seem orthogonal to my input.
|
| The IC Protocol is indeed about redundancy and resilience,
| but also about sovereignty and security, and it does not
| just host data (like torrents) but also runs software in a
| verifiable way (in particular, for every message you get
| from a dapp on the ICP, you get a certificate that proves
| that the majority of nodes in the subnet agree on the
| result).
|
| In a nutshell, it's a platform that gives you many
| guarantees (security, redundancy, sovereignty) out of the
| box - as opposed to classical solutions which have to be
| composed of many different building blocks that need to be
| orchestrated to work together.
| tecleandor wrote:
| (Spain, doing storage and web hosting) What usually worries me
| the most is the administrative or management part, which I
| don't know how big would be for this project...
| senda wrote:
| messaged on linkedin fyi
| lars_francke wrote:
| Honest question: Does this not already exist?
|
| - https://vulnerability.circl.lu/
|
| - https://osv.dev/
|
| - https://vuldb.com/
|
| And a few others?
| cookiengineer wrote:
| OSV is made by Google/Alphabet and therefore also prone to
| Trump intervention (see Gulf of Mexico executive order).
|
| The circl.lu might be actually a potential cooperation
| partner.
|
| (Vuldb is down right now)
| SSLy wrote:
| you've slept just 3 hours? Go back to bed..
| kiru_io wrote:
| Maybe just a toilet break (see the bio): > Fun fact: All
| my comments have been written on the toilet. I don't use
| social media anywhere else.
| biorach wrote:
| https://xkcd.com/1369/
| cookiengineer wrote:
| Yep, toilet and now back to bed :D
| ljm wrote:
| Taking TDD to a level it's never been before
| JCharante wrote:
| hmm? it's already daytime in Europe where he's located
| croes wrote:
| https://www.enisa.europa.eu/news/another-step-forward-
| toward...
| belter wrote:
| Other authorities:
| https://www.cve.org/programorganization/cnas
|
| The CVE program is really important. This Administration is
| truly the example of the D.O.G.E. - Department Of Gaffes
| and Errors
| cookiengineer wrote:
| > https://euvd.enisa.europa.eu/
|
| They already did it. Great!
|
| Maybe we can ask them how to contribute to their software,
| as it seems to be proprietary at the moment?
|
| edit: lol, their manifest.json is still the React
| boilerplate: https://euvd.enisa.europa.eu/manifest.json
|
| Their database seems to also only contain fairly recent
| CVEs (up until 2019? some CVEs are missing...) and not
| before that
| numpad0 wrote:
| All major powers have at least one each, some few for
| different parts of bureaucracy. Most of them are probably
| minimum budget operations just rsync-ing US CVD but they
| exist.
| ozim wrote:
| We can only hope they will get enough exposure now so
| they can get funding to fix stuff.
| rickdeckard wrote:
| To quote the article "Fourth, national
| vulnerability databases like China's and Russia's, among
| others, will largely dry up (Russia more than China)."
| "Fourth [sic], hundreds, if not thousands, of National /
| Regional CERTs around the world, no longer have that
| source of free vulnerability intelligence."
| "Fifth [sic], every company in the world that relied on
| CVE/NVD for vulnerability intelligence is going to
| experience swift and sharp pains to their vulnerability
| management program."
| BrandoElFollito wrote:
| This is (without any irony) the first useful thing I see
| from ENISA.
| mitjam wrote:
| The main costs definitely not hosting and can be quite
| significant. MITRE had $2.37B revenue in 2023, most if it
| contributions. I don't know how much of it can be attributed to
| the CVE, but I assume it's not an insignificant part of it:
| https://projects.propublica.org/nonprofits/organizations/422...
| hypercube33 wrote:
| I would email someone like Patch My PC they seem good stewards
| of stuff open source from my vague looking and they are good
| people. They may just host a clone of it that's open.
| newsclues wrote:
| Why EU?
|
| Canada may be another friendly option
| com wrote:
| Canada's been described as the Ukraine of North America.
|
| Let's not site global critical infrastructure within 150km of
| US land borders for a generation, please.
| jetster735180 wrote:
| I don't believe I've heard that before.
|
| As a Canadian, I can confirm it's nothing like what's
| happening in Ukraine.
| sberder wrote:
| Looks like some people are already getting things moving:
| https://www.thecvefoundation.org/
| worthless-trash wrote:
| Some cnas may also submit. Is this something you are open to?
| dev_l1x_be wrote:
| We should host it and collect membership fee from people who
| need this data. This way we can make it resilient against lack
| of government support. I would love to pay 5-10EUR/month to use
| such a service.
| delusional wrote:
| Meh. It's not like I was going to ask the facist autocracy about
| my software vulnerabilities.
| nelox wrote:
| Just what is needed with an adversary during and asymmetrical
| trade war.
| insane_dreamer wrote:
| CVE was anti-American woke.
|
| No, more seriously, just like with shutting down NOAA services,
| it seems the goal is to:
|
| 1. cut services (we saved taxpayer money!!)
|
| 2. at some point later: oh, we actually need those services
|
| 3. pay <insert your favorite vendor here, preferably one
| connected to Musk> to provide the service (see! we don't need to
| pay gov employees!!) (fine print: the vendor costs 2-3x the
| original cost). But by then no one is looking at the spending
| numbers anymore.
|
| Slick moves.
| SirHumphrey wrote:
| And here lies the problem. Even from a libertarian perspective
| DOGE is counterproductive because maintaining a system is much
| more cost effective than starting it anew.
|
| Especially when you cut something recklessly, figure out in
| month that you need back that capability right now and have
| very little leverage to negotiate with private providers.
|
| When you look at the last cutting effort in the Clinton
| administration the difference in jarring.
|
| Combine that with the fact that with a few exceptions DOGE has
| been cutting the most cost effective programs (i can't think of
| a better bang for buck science program than NOAA) it's saved
| very little vs the amount of pain it has caused.
| darkwater wrote:
| Heeeeey but he runs Tesla like this and it's an hyper-valued
| company!!!1! He cannot be wrong, he is a genius!!
| JackYoustra wrote:
| There are quite a few threads on hackernews that were cautiously
| optimistic about doge with, frankly, pretty naive libertarian
| takes about how the government works.
|
| The government is not particular (in the sense of particularism)
| and cannot be easily tuned to fix particular problems; rather,
| its best solutions come through institutional procedure and
| design, such as the tension between the FAA and the NTSB that, at
| a first glance, would seem like obviously needless duplication
| and waste.
|
| It is a broad, blunt, wasteful instrument to solve broad, blunt
| problems in a way that may not be the best but that work far, far
| better than alternatives that have been tried.
|
| That the effort to treat government like a personal budget has
| ended up destroying important things is a sad inevitability of
| such efforts. I hope it goes remembered.
| simpaticoder wrote:
| _> I hope it goes remembered._
|
| It won't be. Willful ignorance is a cornerstone of the
| movement. You can't lie about what you don't know. You can't
| have a bad take if you don't know. Upton Sinclaire said in the
| 1930's: "It is difficult to get a man to understand something,
| when his salary depends on his not understanding it." Now add
| to "salary" "identity", "relationships", "sense of belonging to
| the group". This is why critical, independent thinking,
| speaking truth to power, must be separately honored and
| encouraged by a healthy culture, because these attributes are
| by default mercilessly punished. (Physical courage and heroism
| are honored by a healthy culture for similar reasons.)
| JackYoustra wrote:
| I mostly agree, although I really disagree with 'speaking
| truth to power' -- I feel like the outsized reverence for
| this is exactly what got us into this mess. For YEARS,
| there's been a culture of celebrating opposition for
| opposition's sake, a performative stance of always
| positioning oneself against the perceived holders of power,
| rather than critically evaluating the actual accuracy or
| value of what's being said.
|
| Democrats are repeatedly pilloried simply because they govern
| while the Republicans cosplay as a permanent opposition, and
| therefore became 'the power' to speak against. Governing
| inherently involves trade-offs, compromises, and complex
| realities that never match ideological purity. Thus, an
| atmosphere developed where people who engaged in governance--
| and therefore took responsibility for difficult, real-world
| outcomes--became easy targets for criticism that was more
| interested in the aesthetics of "truth to power" than in
| providing accurate analyses or constructive solutions.
|
| As a result, "speaking truth to power" became a performance,
| disconnected from accountability or genuine insight. The
| loudest critics weren't necessarily those with the most
| accurate or useful truths, just those who most visibly
| positioned themselves as opposing power structures. This
| reinforced public cynicism and undermined nuanced
| understanding of governance and policy, further obscuring
| genuine critique and necessary reforms.
| 1970-01-01 wrote:
| Root cause: Layer 8 failure
|
| https://www.computerhope.com/jargon/l/layer8.htm
| apexalpha wrote:
| Why is this sponsored by such an American gov entity?
|
| I guess it's one of those things you never think about until it
| goes wrong.
|
| The world would do well to move this kind of stuff out of the US
| quickly, just like ICANN and stuff.
| kbumsik wrote:
| Because gov infra also relies on CVE?
| porridgeraisin wrote:
| Good. CVEs were the poster boy of goodharts law for the longest
| time. Most security vulnerabilities behind CVEs are utterly
| meaningless.
| goku12 wrote:
| Ah! Another one to add to the following list:
|
| - What disease did the CDC ever prevent?
|
| - What improvement did the NHTSA ever bring to full self
| driving?
|
| - What improvement in airline safety did the FAA bring?
|
| - What good did FEMA do in any disasters?
|
| I don't want to quip about how their achievements are invisible
| because they prevented the disasters that would have brought
| the spotlight on them, even when they were too underfunded to
| properly do their jobs. But I sure would like to see the people
| making these smart comments to give it a try and see how that
| goes. Then again, I have no complaints - at this rate, we'll
| get that chance soon.
| 4ndrewl wrote:
| To the "I wish HN would stay out of politics" crew.
|
| You can stay out of politics, but politics will always come and
| find you.
| t0lo wrote:
| Everything is political now by design. It's meant to reach into
| every facet of society and community and restructure it.
| Braxton1980 wrote:
| Everything was always political. Laws, the economy, conflcit.
| How is any person not affected by these? The government is
| responsible for all or a large part of how a country
| functions.
|
| People who say "I'm not political" are deflecting to avoid
| conflict
| t0lo wrote:
| I mean I think The Republican Incumbent was chosen
| specifically as a tool because he is so extreme, pervasive
| and demoralising and creeps into everything. Definitely by
| Russia, maybe also by our "friend" in the ME. Although it's
| not that reported on they are on friendly terms.
|
| Disaffection lends itself easily to creating a Russia-style
| society. This all feels pretty Dugin-esque, and his
| proposition (return to values, reject interest/hope in
| politics because it is always flawed anyway, bind together
| under the state) fits perfectly, and is finding prominence
| at the perfect time.
|
| Just my opinion, but to me this seems far more akin to
| Dugin than whatever Curtis Yavin is pushing
| ndr42 wrote:
| What is "ME" referring to?
| NikkiA wrote:
| "Middle East" is the usual expansion, and fits in context
| here.
| HelloNurse wrote:
| The "friend" could be Israel or some person like Mohammed
| bin Salman.
| NikkiA wrote:
| Given the treatment for supporters of gaza, almost
| certainly Netting-yahoo
| darkwater wrote:
| > People who say "I'm not political" are deflecting to
| avoid conflict
|
| A great truth. Even isolating yourself from society like a
| hermit is still a political decision: you are rejecting
| society as it is, and prefer to live in your own solo
| society. That's politics.
| dcow wrote:
| I don't think that's totally accurate. If I live as a
| hermit but perform my civic duties like voting and paying
| any taxes, I don't see how choosing to live in solitude
| is anything more than a lifestyle choice.
| perching_aix wrote:
| When this is discussed, what's being meant is that everday
| party politics are spilling out and overwhelming a
| project's or industry's individual, internal politics,
| which are often a completely disconnected meta.
|
| Appealing to "well everything is connected" I'm not sure is
| useful. It's interesting from a semantics perspective the
| first few times you come across it maybe, then swaps around
| into being plain frustrating, then lands on just missing
| the point.
|
| Finally, I think people who want to stay out of said party
| political meta I think are doing a pretty big favor to
| their mental health, and I really can't fault them one bit
| for it. No coincidence either.
| noelwelsh wrote:
| Two things:
|
| "Party politics" is ill-defined, and so a "no politics"
| rule becomes an arbitrary hammer that bosses can use to
| smash employees. If I say "I'm going to get a COVID
| vaccine this afternoon" is that discussing party
| politics? In the UK, where I live, the vaccine was
| provided by the government, so I'm implicitly discussing
| the actions of the government. That is under any
| reasonable definition a discussion of politics.
|
| "everyday party politics are spilling out and
| overwhelming a project's or industry's individual,
| internal politics" is how "no politics" rules are usually
| justified, but this was not what happened in the poster
| child cases of implementing "no politics" rules
| (37signals, Coinbase). 37signals in particular tried to
| spin it this way, but it was the actions of a group
| within the company approved by the founders that caused
| the problem. (Coinbase was just completely incoherent
| from the start. Their mission is something like "End
| economic inequality" which a reasonable person could take
| to mean anarchist or communist discussion is on topic.)
| graemep wrote:
| The covid vaccine example is a good one in terms of
| something in everyday life that is politicised.
|
| It is also illustrates the problem with discussing
| politics in an international forum. The KCL study of
| covid conspiracy theories (carried out during the
| pandemic) found that in the UK young people and those who
| identified as left wing were more likely to believe
| conspiracy theories. I am pretty sure this is
| significantly different from the US. Also matches things
| I have heard (e.g. my daughter met people at university
| who refused the vaccine because "we don't trust the
| Tories".
|
| It is pretty common for Americans to assume that the
| Conservatives are equivalent to Republicans, and Labour
| are like the Democrats, which is very far from the truth.
| It has always been far from the truth but the reasons why
| change - e.g. in the 80s Thatcher and Reagan were not far
| apart, but that that time Labour were far to the left of
| the Democrats (actual socialists).
| perching_aix wrote:
| There's no way to define any modality of politics such
| that someone like you won't come around and start going
| off about how it's a leaky segmentation, and is actually
| just an excuse for censorship.
|
| Every artificial segmentation of the real world is leaky.
| Just like the recognition that politics is everywhere,
| this too is not actually inquisitive. It's like arguing
| that stairsteps are chairs. They can be, but that doesn't
| make the word "chair" _ill-defined_.
|
| > but this was not what happened in the _poster child
| cases_ of implementing "no politics" rules
|
| There is no such thing. These may be notable cases in
| your cohort, for me it's the first time I heard of these.
| And I've seen my fair share of these rules.
| Braxton1980 wrote:
| > I think are doing a pretty big favor to their mental
| health, and
|
| It your mental health is harmed while defending your
| political views it's possible your views are the issue.
|
| For example if my view was that "domestic animals
| shouldn't be abused and penalties increased for such
| crimes" I wouldn't have mental health issues discussing
| this.
| concordDance wrote:
| The vast majority of people will get stressed talking to
| people they think are evil or against their values.
| Someone breaking down in tears because another person
| says they "don't give a fuck about the bloody Gazans" is
| not behaving particularly unusually.
|
| The views don't matter as much as how strongly they are
| held.
| graemep wrote:
| > Someone breaking down in tears because another person
| says they "don't give a fuck about the bloody Gazans" is
| not behaving particularly unusually.
|
| it might be reasonable if you have personal close links
| to Gaza (e.g. you are worried about family who live
| there), but otherwise it OUGHT to be very unusual.
| saagarjha wrote:
| Why?
| AlexandrB wrote:
| > it might be reasonable if you have personal close links
| to Gaza (e.g. you are worried about family who live
| there)
|
| That's _another_ problem with political discussions at
| work - you 're often not sure _why_ someone has a
| particular beliefs and so it 's hard to know whether
| disagreement will be taken as an abstract difference of
| opinion or as an attack on their family, friends, or
| homeland.
| pjc50 wrote:
| Funnily enough, one of the UK's odder, more intense, and
| probably mentally ill domestic terror campaigns was
| carried out by anti-vivisectionists.
|
| (https://en.wikipedia.org/wiki/Stop_Huntingdon_Animal_Cru
| elty)
| pseudalopex wrote:
| Were they anti vivisectionists? Or animal testing
| opponents who called animal testing vivisection?
| perching_aix wrote:
| So if I now said some intentionally asinine garbage, e.g.
| about how dogs need to be disciplined, shown who the pack
| leader is, and sometimes that necessarily involves a
| beating, and how if you disagree you're woke, that
| wouldn't make you very understandably very distraught?
|
| Because it would make me pretty distraught, and I don't
| think that it's because anything is wrong with the idea
| of not abusing animals.
|
| Even doing this mental exercise for the sake of this
| conversation is already extremely frustrating for me. And
| I don't think this should surprise you, or is anything
| strange or unusual.
| juliendorra wrote:
| Alternatively people who say "I'm not political" are
| benefiting from the status quo and political direction of
| things (long term, not necessarily short term). They frame
| inaction as apolitical.
| InsideOutSanta wrote:
| One of the benefits a working democracy conveys to its
| citizens is that they largely don't have to care about
| politics. They can trust that government action is
| relatively consistent over time, that laws will be enforced
| fairly enough, that their property will be protected to a
| reasonable degree, that the currency will be reasonably
| stable, that the roads will be maintained, that some public
| transport will be available, that sudden wars won't erupt
| around them, and so on.
|
| That's what makes working democracies successful. But it
| seems that it also makes democracies vulnerable because
| people don't realize they have these benefits _because they
| live in a working democracy._ They start to think these
| benefits have nothing to do with politics and are just the
| way things are, like the laws of nature.
| demosito666 wrote:
| Interestingly, I believe that the reality is exactly the
| opposite: on the political regimes' spectrum of
| democratic -> authoritarian -> totalitarian only the
| middle one doesn't require people's participation. Both
| democracy and totalitarism need to be actively maintained
| by significant part of the population, otherwise they
| converge to the "natural" state of things - authoritarian
| order. None of the stuff you listed (fair laws, property
| rights, etc.) occur naturally once it has been set up at
| some point in past. That's why they talk about "checks
| and balances" all the time, and they are impossible
| without active participation.
| pjc50 wrote:
| What distinction are you making between authoritarian and
| totalitarian here?
| demosito666 wrote:
| I think the most significant distinction is exactly that:
|
| Authoritarian - leaves people alone in general as long as
| they stay out of politics. Examples: 90% of regimes
| throughout human history. Almost all post-soviet
| countries, almost all of Middle East and Africa,
| Singapore, etc.
|
| Totalitarian - forces people into actively participating
| in leader's political goals and penetrates the daily
| life. North Korea, USSR, Nazi Germany, Fascist Italy.
| Braxton1980 wrote:
| >Authoritarian - leaves people alone in general as long
| as they stay out of politics.
|
| Directly, yes, but their policies still affect people.
|
| For example, if an authoritarian leaders enacts economic
| decisions that damage the economy everyone is affected.
|
| If I pay more for goods and services due to Tariffs
| aren't I being forced to participate in the leader's
| political goals?
| jowea wrote:
| The distinction is fuzzy, but I think what is meant here
| is more directly political. In a totalitarian system, it
| is considered important for everyone to know and openly
| and regularly support state ideology with words and
| deeds. In the least totalitarian but authoritarian
| system, the state just wants apathy and obedience from
| its citizenry.
|
| So it would be totalitarian leaning for a leader to make
| a speech (watching is mandatory btw) saying that buying
| foreign is anti-patriotic and generating social censure,
| in addition to the tariffs, for people seen with foreign
| goods.
| InsideOutSanta wrote:
| Yeah, I should have phrased this better. When I said that
|
| _> citizens (...) largely don't have to care about
| politics_
|
| I didn't mean that it wasn't harmful if they didn't care;
| I meant that there was no clear, immediate incentive.
| Braxton1980 wrote:
| >One of the benefits a working democracy conveys to its
| citizens is that they largely don't have to care about
| politics
|
| The citizens elect the government so how can you not care
| about poltiics?
| InsideOutSanta wrote:
| _> The citizens elect the government so how can you not
| care about poltiics?_
|
| I don't think there's a direct correlation between the
| ability to vote and caring about politics. People usually
| care about politics when it affects them negatively. I
| would guess that most people in most democratic systems
| don't have strong negative experiences with their
| governments and, thus, are not incentivized to care about
| politics.
|
| Note that I'm not making an argument that they _should_
| not care. I think they should, but the very system that
| allows participation probably also decreases the
| incentive for most people to participate.
| Braxton1980 wrote:
| >. I would guess that most people in most democratic
| systems don't have strong negative experiences with their
| governments
|
| Opinion polls about political parties and leaders seem to
| always hover near the bottom end, at least in the US [1]
|
| [1] there are always bumps after elections (change), war
| (nationalism), and tragedy (group sympathy)
| jowea wrote:
| Well, a bit. A part of liberal democracy is that
| elections don't matter that much. The losers can trust
| that they aren't going to be arrested, have their
| property confiscated etc. The established system like the
| courts, constitutions separation of powers and other
| anti-majoritarian things will prevent most extreme
| measures. And in at least some political systems, it is
| expect that no matter what some minimally competent
| people will win and govern not that differently from what
| the election loser was going to do.
|
| And remember voting is not mandatory and a lot of people
| don't vote. Those people are ultimately letting others
| decide, and a lot of them are hoping the voters are going
| to pick well, or at least decently.
| silverquiet wrote:
| And yet the Republicans have campaigned on tearing down
| government for my entire life. And people treated me like
| a fool for believing them.
| Cthulhu_ wrote:
| Everything already was, you just didn't recognize it because
| it was to your benefit / in your interests.
| paganel wrote:
| Agree, but it goes both ways, with technology (that many of
| us here have helped create and maintain) also reaching out
| into every facet of society and community, many times in
| close symbiosis with the political powers that be, to the
| detriment of said society and community.
|
| Not 100% sure what I wanted to say, maybe that said politics
| (and the political as a whole) wouldn't have invaded almost
| our entire lives without the help of technology.
| po1nt wrote:
| That's because we got reliant on the funds from government.
| Maybe it's time to break the dependency.
| jocaal wrote:
| > That's because we got reliant on the funds from
| government
|
| Not we, some people got reliant on the funds from
| government. It is always at the cost of someone else. The
| tax the rich and bourgeoisie mentality is what led to Mao
| Zedong and Stalin, but no-one wants to learn about history
| anymore.
| Moomoomoo309 wrote:
| Tax the rich mentality also led to the "golden age of
| capitalism" of the 1940s, 50s, and 60s. The tax rates on
| the wealthiest in the US at that time were huge, and that
| money went into job programs, housing assistance
| programs, construction projects, etc.
| okeuro49 wrote:
| "You can stay out of politics, but politics will always come
| and find you."
|
| No, it's just recognising that it is silly to talk about
| politics, as certain views are just downvoted.
| spookie wrote:
| Of all places I find this one the most shielded from this
| behavior as long as you're civil.
| goku12 wrote:
| It's true that HN insists on and respects civil behavior.
| But HN doesn't always remain impartial in terms of
| downvotes, flagging and removal of comments when it comes
| to some topics that are inherently political. There was one
| such overtly political thread recently where some of the
| opposing comments were flagged and removed. Those comments
| were not even as inflammatory as the news article itself.
| It indicates that HN does have a majority political bias
| that they're not hesitant to impose up on the discourse.
|
| I'm not going to go into specifics of the topic because I
| don't want to start another episode, though I do have the
| complaint that such actions distort the discourse unfairly
| to one side. And I also understand that political biases
| are human nature and that they can never be fully
| eliminated. But at the same time, it would be harmful to
| pretend that the discourse on HN is apolitical, balanced or
| that it shields you from that sort of censorship. Imagine
| making a good-faith counterargument, only to have it
| flagged and removed because the opposition doesn't like it.
| And when asked, you get cited a point in the CoC, except
| that it's not applied uniformly and impartially in that
| thread. Makes you wonder what the purpose of flagging is at
| all! That will just put certain groups at an undisclosed
| disadvantage and lets harmful stereotypes flourish without
| any challenge. All we can do is to be forthright about this
| fact and try our best to have a civil debate.
| dmckeon wrote:
| People trying to ignore politics are like fish trying to ignore
| water.
| strogonoff wrote:
| Not talking about politics is itself a political position (in
| favor of status quo).
| stingraycharles wrote:
| Depends. We're a small, very international startup and have
| a super strict "no politics" policy. Politics and work are
| not a good combination when you're employing people from
| all over the world.
|
| But I would not consider it a political statement to adopt
| this policy.
| noelwelsh wrote:
| Your statements are incoherent. Politics is decision
| making and power relationships within groups of people.
| It is 100% a political statement to adopt this policy as
| it exercises power over a group. You cannot function as a
| group without politics. "Where do y'all want to go for
| lunch" is also politics, as it involves group decision
| making and power relationships (Do you go to the
| vegetarian place? Do you avoid the spicy place?) It's a
| completely banal decision but it is still politics.
|
| If what you want is a "don't piss off your coworkers by
| discussing topics unrelated to work that you know will
| annoy people" policy, that is fine, but don't pretend you
| are not engaging in politics.
| concordDance wrote:
| "Politics" is a stupid word because everyone has a
| different idea about what it means and so they all talk
| past each other.
| strogonoff wrote:
| The word "politics" is vague, and that only makes banning
| political discussions worse if it only becomes political
| when the higher-ups don't like it.
|
| Say your company has a possibility of working with some
| client company who is directly or indirectly involved
| with cause X. If it is "political" to talk about _not_
| working with them because of X, but it is "not political"
| to talk about working with them, then you see what I
| mean.
|
| It doesn't have to be a destructive conversation: one
| employee might say we should avoid them, but you might
| say we need to work with them because we need the money
| now and can drop them later when we are in a better
| place. Other employees could talk how cause X is not that
| unethical for reasons. If someone balks at a point of
| view incompatible with theirs and is incapable of
| expressing a viewpoint in a way that respects other
| views, maybe that someone is not mature enough and next
| time your HR can avoid that type.
| pixl97 wrote:
| Many people that ban political discussions miss the irony
| that it's a political decision.
| gedy wrote:
| Yeah exactly, the same people who shout the loudest about
| "everything is politics" and want to talk about it at
| work would go apeshit if someone at work said "I'm not
| comfortable with abortion", etc. HR would quickly be
| called and shut them down.
| def13 wrote:
| The politics of saying "no politics" is that you are
| drawing some line that separates some political issues
| into "politics" and others into "not politics". Because
| to truly avoid all politics is impossible; even if you
| believe banal, purely intra-personal politics are not
| political so much of the basic organization of a business
| & capitalism are politics. "Should we allow remote work"
| for example is a deeply political question that ties
| deeply into discussions about the rights/value of
| neurodivergent & disabled people in the workplace. To say
| 'I don't believe in God' is a deeply political and
| dangerous statement in some parts of the world, but
| fairly banal where I live. To contrast, in Indonesia, it
| is technically _unconstitutional_ to not believe in a
| "one and almighty God"
|
| I wish people were at least honest about "no politics" to
| mean "lets avoid to unsafe, potentially divisive issues
| relative to our geographic location, and take the basic
| tenets of neoliberal, capitalistic society to be
| assumed". And yeah, that is a more than reasonable
| policy. Its a difficult policy in international spaces,
| because its very hard to not trespass that line when
| political contexts differ so strongly across the globe
| lou1306 wrote:
| > take the basic tenets of neoliberal, capitalistic
| society to be assumed
|
| Well, then any discussion about an illiberal oclocratic
| executive (such as 47's) should be fair game...
| DrillShopper wrote:
| > The politics of saying "no politics" is that you are
| drawing some line that separates some political issues
| into "politics" and others into "not politics".
|
| I find someone's heuristics for deciding which category a
| statement falls into chiefly turns on if they agree with
| the statement. If they agree with the statement then it
| is not political, and if they disagree, it's political.
| rini17 wrote:
| I am torn.com player which is a MMORPG as far removed
| from politics as can be. But when large part of dev team
| are ukrainians that were suddenly unable to work from
| clearly political reasons you can't ignore it.
| squigz wrote:
| One might argue that it's even more important to discuss
| international politics these days, considering how
| interconnected the world is and how so many countries
| seem to be facing many of the same issues.
| orwin wrote:
| I think it exists two different general ideas of what
| politic mean.
|
| For some (including me), politics are, following the
| oldest definition: 'how do I and fellow humans organize
| ourselves to live together' this often leads to a belief
| that everything is politics (for me it's true, but it's a
| belief, not a fact).
|
| For other, I think that when they say politics, they
| think of geopolitics and partisanship, which is fair,
| because it's how politicians and political journalists
| themselves define politics. For this group, hopefully,
| not everything is politics.
|
| So to me, this disagreement about wether or not all is
| political is often semantic rather than ideologic.
| pseudalopex wrote:
| The disagreement is semantic and irrelevant in the sense
| the question at hand usually is which topics and opinions
| are forbidden at work.
|
| The disagreement is semantic and relevant in the sense
| people who say no politics at work believe their
| categories of politics and not politics are obvious.
|
| The disagreement is ideological in the sense ethical
| concerns about products or customers are designated
| political often.
|
| Politicians, political journalists, and people who say no
| politics at work do not define politics as geopolitics
| and partisanship.
| tobr wrote:
| How do you define politics? For example, are employees
| allowed to be LGBTQ? Are they allowed to mention their
| relationships to colleagues?
| pxoe wrote:
| Being straight is also pretty much political at this
| point. With the way it's being slipped into the culture
| (all that trad stuff, images of lifestyle to aspire to,
| etc.) and has become (has always been perhaps) a part of
| political messaging and campaigning, heterosexuality is
| political. Even within the heterosexuality itself and its
| expressions, there's still politics - "what's the right
| way to do it" and such. (not saying this like 'oh those
| poor straight people' but just that, it is all, all
| political)
| tobr wrote:
| For what it's worth, I completely agree, I just thought
| LGBTQ was a clearer example because of how different it
| is seen in different parts of the world, and how it is at
| the same time an inescapable part of many people's
| identity.
| criddell wrote:
| For a lot of people on HN, a ban on politics discussions
| in the office is impossible because we have to deal with
| software licenses.
| strogonoff wrote:
| First, "no politics" is not a political statement to me,
| more of an implicitly adopted political position.
|
| Personally, if I have a personal political position and
| my colleague has an opposite one, I don't see why we
| can't talk about it. If you have a workplace rule about
| no politics during working hours, you better have this
| rule for all non-work discussions at work, or I
| personally would feel uncomfortable.
|
| -- If politics talk happens at work too much and affects
| productivity, then it is a problem, but then it is a
| problem with any non-work topic.
|
| -- If it causes heated debate, ruins morale, and makes
| people dislike each other, then it is a problem, but then
| it is a problem with any topic that causes heated debate.
| For some people it's golf, for some philosophy, for some
| music. How many topics should be banned?
| dcow wrote:
| Are you from the US? In the last 15 years it has become
| impossible for two people to reasonably disagree over
| political positions because of how much vitriol is thrown
| around on the attention markets--even if both individuals
| themselves are rather tame. When having an otherwise
| normal political opinion makes you a racist bigot or a
| beta cuck because the opposition is so determined to get
| their way at any cost, no, you can't just talk politics
| at work and have a cohesive team. Someone will feel
| oppressed.
|
| Work is about making money. Politics is a distraction
| unless there's an issue that directly affects the
| business. Then it's fair game. Like this one. Many teams
| of individuals will have to figure out how to navigate
| this situation so discussing it in context is apropos and
| can be done objectively.
| strogonoff wrote:
| > When having an otherwise normal political opinion makes
| you a racist bigot or a beta cuck because the opposition
| is so determined to get their way at any cost
|
| If someone calls me a racist bigot or a beta cuck, that
| is a problem. That problem also has nothing to do with
| politics. It has to do with someone not being emotionally
| mature enough or equipped to handle a discussion with
| someone who has different views, or someone having a
| mental breakdown.
|
| I am not from the US, but I had enjoyed some reasonable
| conversations with people from the US (among other
| countries) with very different views, and I was never
| called names. There are awkward moments when you have to
| hear something you don't agree with, but that is most of
| life if you ever interact with people.
|
| The key is to be like an HTTP server: liberal in terms of
| what you can accept, but strict with what you put out
| there.
|
| > Work is about making money.
|
| You have _just_ thrown another political position into
| the mix, I hope you realize that?
| AlexandrB wrote:
| > It has to do with someone not being emotionally mature
| enough or equipped to handle a discussion with someone
| who has different views, or someone having a mental
| breakdown.
|
| Any moderately sized company is practically guaranteed to
| have a few people like this. So getting into these
| discussions has a high risk of becoming an HR issue as
| tempers flare and conversations become vitriolic.
|
| There's also the issue that the company founders and
| leadership have political opinions of their own that
| might inform company policy and any political opinion to
| the contrary may be perceived as pushback from a
| "troublemaker".
| strogonoff wrote:
| > getting into these discussions has a high risk of
| becoming an HR issue as tempers flare and conversations
| become vitriolic.
|
| Here we can forget that IRL face to face people are much
| less likely to be offensive to each other. If they get to
| literal name calling and aggression, sure, that's an HR
| issue, HR gets paid to sort this out, doesn't it? I don't
| see how politics is different from any other topic on
| which people can have strong opinions.
|
| > There's also the issue that the company founders and
| leadership have political opinions of their own that
| might inform company policy and any political opinion to
| the contrary may be perceived as pushback from a
| "troublemaker".
|
| That is why "no politics" is somewhat dishonest. In my
| view, either blanket forbid all off-topic talks, or don't
| censor by topic and handle fights if they arise. There
| can also be softer guidelines about how to behave at work
| without an actual ban of any topic.
| pseudalopex wrote:
| Or censor by topic specifically and honestly.
| dcow wrote:
| I agree with your ideal. I used to be one of those people
| who would just talk about whatever in any context
| assuming everyone was mature enough to have academic
| discussions and not get personal. Political viewpoint is
| a protected class in the US. But we all saw what happened
| to James Dramore. Real consequences for holding a
| political opinion that allegedly made him "unemployable
| at Google" where his politics were so threatening to the
| established order that Google just couldn't operate with
| him in the mix. You'd think G has the most mature
| employees... and either they do but humans are just
| toxically unable to hold differing opinions, or they
| don't and therefore have to maintain a safe space for the
| comfort of their sensitive workers.
|
| The silliest part: what was his thesis? Well that using
| race and gender based quotas during hiring and leveling
| made Google less competitive. Certainly not a privileged
| white male tech bro just barreling through the company on
| a racist bigoted spree leaving tears in his wake. There
| is more interesting discussion to be had here about how
| the Civil Rights Act has been weaponized in the US and
| companies feel they have a legal obligation now to prove
| that their systems don't yield "unfair distribution of
| protected classes", or whatever the actual wording is.
| And how that is at odds with a world where you can openly
| discuss politics at a company without fear of falling
| afoul of the Chief Diversity Officer (ffs, there are
| executives installed to maintain the order now). And
| related: just look at how pockets of people respond to
| Trump's second term insisting that he's a fascist
| dictator and anybody who doesn't see it is a de facto
| fascist. But I digress.
|
| Nobody wants to bet their job on being on the losing end
| of a kafka traps and thought terminating cliches.
| ksec wrote:
| You would have been cancelled if you said this between
| 2014 - 2019 at the peak of it all.
|
| At least now you can say it out now without being
| downvoted into oblivion.
| concordDance wrote:
| It's in favor of not having relationships break down in
| your community/company.
|
| Only a small percentage of people are able to handle
| fundamental disagreements calmly and without it bleeding
| over to other interactions.
|
| Will the SE and sales guy work as well together if the
| former knows the latter donates half his commission money
| to organizations that help kill babies?
| eMPee584 wrote:
| but letting > the SE and sales guy
|
| never find out about their shared passion is kind of
| cruel, too?
| j45 wrote:
| It's not uncommon for one side to come out with their
| position/interpretation/belief whether it's passion or
| not.
|
| Maybe at a work function, team party, conference, etc.
| strogonoff wrote:
| I have friendly relationships with a few people who have
| political opinions some of which are opposite to mine.
|
| > Will the SE and sales guy work as well together if the
| former knows the latter donates half his commission money
| to organizations that help kill babies?
|
| A friend of mine is a vegan. Anywhere he works, to him,
| most of his coworkers not just help kill conscious beings
| that have self-awareness and feel pain, they literally
| eat them. Does this mean talking about what you have for
| lunch should be banned? Does this mean he should throw a
| fit any time he talks to a non-vegan?
|
| Incidentally, we sometimes have good debates about the
| nature of consciousness, the effectiveness of individual
| veganism on reducing suffering, utilitarianism and
| deontology, vegan food options, etc. I feel being
| converted and I don't mind it.
| AlexandrB wrote:
| > Anywhere he works, to him, most of his coworkers not
| just help kill conscious beings that have self-awareness
| and feel pain, they literally eat them. Does this mean
| talking about what you have for lunch should be banned?
|
| You're making the opposite case of what you think. Your
| Vegan friend is avoiding taking about politics
| _constantly_ because they 're not bringing up the fact
| that everyone is consuming the flesh of innocent animals
| every time they go for lunch. If they started talking
| about the politics and beliefs of veganism at every meal
| shared with coworkers, I think it would have a negative
| impact on those relationships.
| strogonoff wrote:
| He does not bring up consuming products of animal
| suffering (including egg and milk products) directly, but
| he does order vegan food, which is enough to make a point
| (for me at least).
|
| What he is doing by expressing his philosophical position
| simply through his order is turning me subsequently
| ordering something with eggs into a philosophically
| loaded action as well. That, of course, shifts my opinion
| on the question.
|
| I am making the point I am making: if we worked together,
| we should be free to discuss veganism or paleo diet
| (which I have discussed with a coworker previously)
| whenever either of us wanted, and he demonstrated being
| an adult about it when we do. If he asked to not talk
| about it because it made him uncomfortable, then we
| wouldn't. I do not see why political discussions have to
| be different.
| pjmlp wrote:
| Turning the question around, will the SE and sales guy
| work as well together if the former knows the latter
| donates half his commission money to FSF while the other
| is hard advocate for commercial software?
|
| Politics are across all layers, including at technology
| decisions.
| kortilla wrote:
| No it's not. It's having discipline to not pollute
| unrelated conversations with your politics. I am very
| against the status quo but I don't complain about it to a
| bunch of anonymous usernames on a forum focused on
| technology.
|
| You can believe something without proselytizing.
| MiguelX413 wrote:
| Things are often inherently political.
| johannes1234321 wrote:
| Technology and the consequences of using technology are
| inherently highly political.
|
| New or improved technologies shape communities.
|
| Ignoring that is a political statement as well.
|
| Just see how online media has changed discourse, how
| Amazon changed retail business, how business analytics
| change the way businesses work, how always being
| connected changes relations, ...
|
| When developing technologies one can be Wernher von Braun
| "(where the rockets land and whether they contain
| explosives is) not my department" or one can consider
| consequences.Both are a political position, with
| consequences.
| drstewart wrote:
| >Technology and the consequences of using technology are
| inherently highly political.
|
| So what stance does The Art of Computer Programming take
| on communism?
| egoisticalgoat wrote:
| Is communism the only political topic? Or does whether or
| not The Art of Computer Programming talk about
| accessibility in software not constitute a political
| opinion?
| acdha wrote:
| That's a very narrow redefinition of both technology and
| politics, and even there it's only a step away from
| discussions about how automation affects millions of
| jobs, how daily lives are shaped by what's allowed by the
| software which large companies or governments build, or
| how amassed data can be misused in ways which wouldn't be
| possible without efficient algorithms.
| johannes1234321 wrote:
| Between the four books there is a lot of paper being
| printed, with chemicals which have to be sources
| somewhere.
|
| But a bit more serious there are different angles to
| this:
|
| One is that the formalization Knuth did, is basis for the
| way other research on computer science has been setup.
|
| His work on TeX as part of writing the books has great
| impact on how scientific reports are being written, which
| themselves have consequences.
|
| And then there is all the consequence while implementing
| technology. How optimisations by better algorithms enable
| data mining, replacing manual labor, ...
|
| Now of course impact differs. Not everybody is building
| V2 rockets (as well as Saturn rockets) like von Braun
| did, but there are many wheels in the machinery.
|
| I myself am a small wheel in building database engines.
| The software is used by sports clubs to manage their
| members, shop owners to manage their inventory, companies
| to run their ads and air craft carriers to replicate
| strategic data across the ship, so that if one part is
| damaged, the other can still operate. If I were to leave,
| the organisation would continue developing, but the work
| has impact.
| ttepasse wrote:
| Knuth in the wake of the Iraq war and the Abu Ghraid
| crimes asked some "Infrequently Asked Questions" which
| are of course highly political. He kept this page linked
| on top of his home page. And in 2022 he wrote a
| postscript with more political questions.
|
| https://www-cs-faculty.stanford.edu/~knuth/iaq.html
| drstewart wrote:
| I didn't ask about Knuth.
|
| I asked about the book. Everything is inherently HIGHLY
| political, thus this should be an easy question.
| strogonoff wrote:
| > You can believe something without proselytizing.
|
| You can _talk about politics_ without proselytising. Why
| should discussing a topic even invoke the words like
| "belief" and "proselytising"?
|
| Not only stating an opinion is compatible with a
| constructive discussion that could lead to a mutual
| adjustment of opinions--in fact, stating your opinion is
| often a pre-requisite to having a discussion that could
| lead to it being changed.
|
| The magic happens when person A realizes that another,
| equally sane person B can think very differently about
| topic X. At that point, the person A has to either 1)
| write the person B off as crazy (not so easy when that
| person is obviously sane in every other way), or 2)
| realize that there may be _something_ to it and ever so
| slightly adjust own opinion on topic X, or at least
| become more tolerant.
|
| Not being able or willing to freely exchange and converge
| on opinions with people whom you routinely meet in real
| life, only discussing them online in your respective
| bubbles, is a sure way to having only more and more
| wildly incompatible and divisive opinions, and I suspect
| it is exactly what has been happening in recent years.
| JumpCrisscross wrote:
| > _having discipline to not pollute unrelated
| conversations with your politics_
|
| Discipline isn't found in hiding. Someone who cannot
| discuss politics without polluting conversations isn't
| disciplined, they're unpracticed in conversing and
| thinking through their views.
| iteratethis wrote:
| Incorrect, not talking about politics does not signal any
| political affiliation.
|
| I think the "everything is political" statement is
| technically correct but practically useless. In the
| workplace the discussion is mostly about allowing or
| disallowing politics that are irrelevant to the business.
| brightball wrote:
| No it's not. It's a position that comes from experience of
| knowing that it's a complete waste of time because nobody's
| mind is being changed.
|
| Further, there are entire segments of political groups who
| just want to assume your beliefs like a political straw man
| so they can denigrate you.
|
| It's an unhealthy waste of time and that doesn't truly hit
| you until you invest the time in talking to an otherwise
| rational person, provide the closest thing to proof of your
| perspective in a situation and then watch them deny it
| anyway.
| strogonoff wrote:
| > it's a complete waste of time because nobody's mind is
| being changed.
|
| What you said can be true if you approach the discussion
| with an attitude of "I want to change everybody's mind"
| instead of trying to get to some agreement and truth.
|
| Not only stating an opinion is compatible with a
| constructive discussion that could lead to a mutual
| adjustment of opinions--in fact, stating your opinion is
| a precursor to having a discussion that can change it.
|
| > It's an unhealthy waste of time and that doesn't truly
| hit you until you invest the time in talking to an
| otherwise rational person, provide the closest thing to
| proof of your perspective in a situation and then watch
| them deny it anyway.
|
| The magic happens when one person realizes that another,
| obviously sane in every other way person can think very
| differently about topic X. Repeated exposure to
| alternative views from other people in your circles
| leaves no alternative except to adjust your own opinion
| on topic X.
|
| Thing is, it's tricky or impossible online. Aside from a
| handful of well-known people with some reputation or
| infamy, most of us only know each other as handles with
| no context. On the Internet, no one knows you are a dog
| or a basement dweller who lives with his parents and
| could never hold a job. Meanwhile, access to a group of
| like-minded people is always at your fingertips when you
| are online. However, when you are in a company of people
| who clearly are similar enough in what they achieved, in
| their choice to work for the same company, maybe good in
| their software engineering skill, etc., it makes their
| opinion something that may count.
|
| Not being able or willing to freely exchange and
| consequently converge on opinions with people whom you
| routinely meet in real life, and only discussing said
| opinions in your respective online bubbles, strikes me as
| a path to having more and more divergent, incompatible,
| extreme opinions (which I rather suspect might have been
| happening a lot in recent years).
| brightball wrote:
| > Repeated exposure to alternative views from other
| people in your circles leaves no alternative except to
| adjust your own opinion on topic X.
|
| I have not found this to be true when it comes to
| politically aligned beliefs.
| strogonoff wrote:
| Maybe don't always just take their word for it. Some
| (most?) people will continue to express their view
| vocally, but the fact of encountering an opinion from
| someone they otherwise find a reasonable and sane person
| will cause introspection and adjustment, and maybe in a
| different group they would express an adjusted opinion.
| Most people are always affected by others (excluding
| sociopaths or other unusual cases).
| brightball wrote:
| In person when you can communicate tone and know there is
| a level of mutual trust, I would generally agree.
|
| Over the past few years I've even begun to wonder about
| that though.
| enraged_camel wrote:
| >> No it's not. It's a position that comes from
| experience of knowing that it's a complete waste of time
| because nobody's mind is being changed.
|
| I think the issue is that when people debate someone,
| they want to "win" by having the other side accept
| defeat. You are right, that rarely happens, especially in
| politics.
|
| However, as someone who has participated in countless
| formal debates, I'll share a secret: your goal in a
| debate isn't to convince the person you're debating. It's
| to convince the audience. And that happens quite
| frequently, even if it's not immediately visible to the
| debate participants.
| brightball wrote:
| That is certainly a valid point, especially in formal
| debates.
| jowea wrote:
| You don't need to completely change someone's positions
| for it to be worthwhile. This is a thread about something
| that has directly to do with HN's usual tech topics, and
| it would be hard to not talk at least a bit about the
| political aspects.
| anon373839 wrote:
| It's really a question of time and place. There are many
| foundational topics in life, such as politics, religion, and
| philosophy. But it's not always helpful or appropriate to
| discuss them in a particular setting.
|
| That said, HN already has an extremely wide range of subject
| matter, so I wouldn't say politics should be out of place
| here. It can, though, become a divisive distraction that
| disrupts other conversations, so I can appreciate that some
| limits are needed.
| starspangled wrote:
| Ignore politics entirely maybe, but people who are tired of
| hearing the exact same extremist reductive opinions over and
| over again everywhere aren't necessarily ignoring politics.
| Yes we know it's all because conservatives are fascists and
| corrupt and Russian agents and liberals are communists and in
| bed with the Chinese, etc., not caring to hear about it again
| is not surrendering the battle of good vs evil.
|
| For me, ironically, the worst casualty of "politics"
| infiltrating everything is... politics. I mean the respectful
| and reasoned discussion of politics. Not that it was ever in
| great supply, but now it is non-existent.
| mr_toad wrote:
| > People trying to ignore politics are like fish trying to
| ignore water.
|
| Like fish, most people do ignore it until it turns foul.
| cantrecallmypwd wrote:
| Yep. It's also true of people who think they can simply move
| out of the US and that "solves" the problem too. America's
| problems are still (almost) everyone's problems too.
| goku12 wrote:
| True. But it's much less of a problem outside. For example,
| does the gun culture in the US affect the rest of the world?
| It sure does. You can guess where most of the illegal weapons
| come from. But we rarely even think about getting shot while
| at school or on our way to the groceries.
| blueflow wrote:
| The problem is not political topics, it is how people discuss
| them.
| titaphraz wrote:
| That's a massive issue. Every topic is so polarized that it's
| as if it's evil vs. good.
|
| But I think people are waking up, because things they took as
| non-political god given right is being made political and
| taken away.
| titaphraz wrote:
| It's exhausting because of
| https://en.wikipedia.org/wiki/Firehose_of_falsehood
| h1fra wrote:
| HN and founders will say "no politics here" on the regulated
| internet, drinking regulated water, eating regulated food,
| breathing regulated air.
| pjc50 wrote:
| Apart from the few maniacs On Here who seek out the
| unregulated intentionally. Raw milk (all those tasty
| diseases). "Research chemicals" (don't hear so much about
| that lately, but there were whole microdosing fads).
| franktankbank wrote:
| Raw milk is delicious, my ancestors have been drinking it
| for millennia.
| chillingeffect wrote:
| And we enjoyed our milkborne tuberculosis, typhoid,
| scarlet fever, diphtheria, and septic sore throat
| thoroughly, too. The risks actually doubled the joys. Why
| does a supposedly enlightened society step all over my
| right to choose which eliminated diseases to bring back?
| pixl97 wrote:
| Oooh, ooh, oh, don't forget the brucellosis either.
|
| But hey, I only get to enjoy this if the measles here in
| Texas don't get me first.
| user_7832 wrote:
| Isn't this literally survivorship bias? Those who died
| early wouldn't have had offspring.
|
| 1 - https://en.wikipedia.org/wiki/Survivorship_bias
| franktankbank wrote:
| Not saying its a good choice for those whose ancestors
| didn't go through the selection process.
| JumpCrisscross wrote:
| Your ancestors didn't face bird flu.
|
| That said, I'm for people being idiots. I'm just done
| paying for it. If you're chugging raw milk during a bird
| flu epidemic and your family gets sick because of it,
| basic insurance and the public should only pick up the
| cost after you've declared bankruptcy.
| franktankbank wrote:
| Similarly I wish I could enact carveouts so I wasn't
| supporting peoples health problems related to commenting
| way too much on the internet, hackernews in particular.
| numpad0 wrote:
| not everyone's ancestors
| bluGill wrote:
| Only about 1/3rd of the world. However by coincidence
| fluency in English correlates high with ability to drink
| milk as an adult.
| skywhopper wrote:
| And many of them died from doing so.
| nindalf wrote:
| Milk is my main drink. I don't drink beer or wine, it's
| mostly just plain milk for me. And while there is a
| substantial taste difference based on the % of fat, I
| have never seen a difference in taste between pasteurised
| and non-pasteurised. I actually bought a bottle of raw
| milk from a farmer just to try it. No negative effects,
| but it just tasted insipid compared to 5.4% fat milk I
| can get at the supermarket.
|
| People who claim a taste difference between raw and
| pasteurised, I'd very much like to see someone taste the
| difference on the _same_ cow 's milk blind, before and
| after pasteurisation. I just don't think it affects the
| taste much, and certainly not as much as fat %.
|
| And for people who claim health benefits, I would like to
| see a double blind study demonstrating those benefits.
| franktankbank wrote:
| You may be onto something about the different cows. This
| was while I lived in France temporarily. I had no idea
| that I was drinking raw milk. I was commenting how
| delicious it was and a coworker said "oh is that the
| stuff you have to boil". Me "wut". It was much better
| than the supermarket milk I could get.
| ceejayoz wrote:
| It isn't raw if it's been boiled.
|
| That's pasteurized. At a higher temp than the supermarket
| stuff, even.
| franktankbank wrote:
| Might not have been clear. I wasn't boiling it because I
| couldn't read the french instructions.
| AlexandrB wrote:
| The confounding factor is milk fat. In my experience
| higher fat milk just tastes better regardless of any
| other factor and milk straight from the cow will have up
| to 5% milk fat compared to 3.25% for "whole" milk. Try
| drinking a shot glass of 10% cream sometime, it's
| amazing.
| bitexploder wrote:
| What the cows eat matters for how milk tastes too. Cows
| can get sick. Udders can get infections. Milking
| processes (machinery) and its ease of cleaning can vary.
| Bacteria is everywhere. Pasteurization is a cheap,
| effective and has no real drawbacks. This whole raw milk
| thing is just silly and has become political for some
| silly reason.
| bluGill wrote:
| I think the main difference is fresh. When I was in high
| school I stayed with a dairy farmer who brought in a jug
| of milk from the tank for breakfast after milking the
| cows. After that I can't drink regular milk.
|
| Pasteurization does affect taste though. Around me there
| are two different dairies, one does regular
| pasteurization and one does vat pasteurization and I can
| tell the difference. There is ultra pasteurization which
| is just gross. I've never put unpasteurized head to head
| against equally fresh pasteurized though, and given what
| I now know I'm not going to.
| AlexandrB wrote:
| I _love_ ultra pasteurization. I 'm lactose intolerant so
| I have to drink "lactose free"[1] milk and in Canada such
| milk is often UHT pasteurized since it has to stay on the
| store shelf longer (lower inventory turnover). It's
| amazing that we can, non-chemically, disinfect a dairy
| product in such a way that it will stay good for months
| even without refrigeration.
|
| In Mexico I suspect that almost all milk is ultra
| pasteurized since it's not refrigerated in stores and has
| wicked-long expiration dates. It's also some of the best-
| tasting milk I've had so I think that flavour has more to
| do with some of the other milk processes (like skimming)
| and the livelihood of the cows rather than with how it's
| pasteurized.
|
| [1] In practice this is just milk with the lactase enzyme
| added at some point during production.
| nindalf wrote:
| I have no doubt that milk that is 15 minutes old tastes
| great. My question is if that jug of milk was divided in
| two and one half was pasteurised, would people be able to
| tell the difference? You're saying yes, I'm saying I'd
| like to see blind tests of people tasting both.
| bluGill wrote:
| IF you read close you will see that I didn't say yes. I
| said that I don't know and am not willing to be part of
| such a blind test. I will state clearly that all the
| unpasteurized milk I had was less than an hour old and
| tasted great, while all the pasteurized milk was unknown
| age but likely at least a day old and tasted worse. Is it
| fresh or pasteurization that makes a difference is not
| something I know.
| numpad0 wrote:
| There is ultra pasteurization which is just gross.
|
| Are you referring to 120C 3-second ultra high temperature
| pasteurization? I don't see what would be so gross about
| it.
| bluGill wrote:
| I don't know the details about ultra pasteurization. I
| just know anything labeled ultra pasteurized states
| gross.
|
| Of course the above is subjective. Others have stated
| they prefer it. To each their own, but I will continue to
| maintain it makes milk taste gross.
| Nihilartikel wrote:
| I'd consider drinking raw milk only if I was on a first
| name basis with the cow that produced it.
|
| Otherwise I would at least demand it be fermented into
| kefir so the food microbes can muscle out the bad.
| bluGill wrote:
| That won't make a difference. Bacteria is something you
| cannot see and so you have no idea what is on/in the cow.
| xolox wrote:
| It sure can make a difference.
|
| Sickness caused by bacteria doesn't happen as soon as one
| bad bacteria (bacterium?) enters your body, a certain
| critical mass is usually required. This is very similar
| to the concept of "viral load" where a certain amount of
| viral genetic material needs to be exchanged before the
| viral infection can take hold.
|
| The "beneficial bacteria" on your skin and in your gut
| make it harder for bad bacteria to take root in many
| different ways, one of them simply being they provide
| competition, "crowding out the bad guys".
|
| Another way is that many, many, many types of antibiotics
| were originally discovered as metabolites produced by
| bacteria and fungi (examples include penicillin,
| streptomycin, chloramphenicol, and tetracycline).
|
| And for completeness sake, milk kefir contains many
| Lactobacillus species that are also a natural part of the
| mammal microbiome (which makes sense when you think about
| it; Lactobacillus are named for consuming lactose, an
| ingredient of mammal milk).
| mr_toad wrote:
| > Raw milk is delicious, my ancestors have been drinking
| it for millennia.
|
| Before refrigeration most milk was made into butter,
| cheese and other products. Unless your ancestors actually
| herded the animals themselves they probably didn't drink
| much raw milk.
| avisser wrote:
| Banning raw milk is for health. Banning research chemicals
| is mostly an extension of the war on drugs. They aren't the
| same.
| bbarnett wrote:
| Will all of these things be free of micro plastics and other
| contaminants?
|
| If so, is there a signup page?
| mulnz wrote:
| Wait these regulations haven't created total perfection?
| Better burn the whole thing down.
| fnord77 wrote:
| > regulated ...
|
| not for long
| scandox wrote:
| What people mean when they say this is that they don't want to
| engage in party political and/or tribal political discussions.
| They don't want to do this because it just means rehearsing
| talking points.
|
| People are not dumb. They know that politics is everywhere but
| they want to live and love and talk about things that are
| interesting.
| gedy wrote:
| Exactly, and on the flip side many people who want to "talk
| politics" mainly want to shout at the outgroup and pick
| public fights.
| belorn wrote:
| I view the archive.org, Wikipedia, CVE program, and Linux
| Kernel to all have had discussions on HN about how to they
| should be funded. Is that kind of politics the kind that people
| wish that HN stayed out from?
| diogocp wrote:
| No, but the "everything is political" people are not capable
| of making that distinction. Which is probably why everything
| seems political to them.
| lcnPylGDnU4H9OF wrote:
| > that distinction
|
| What is the distinction?
| atmosx wrote:
| This quote is essentially unworkable. Everything you say, or
| choose not to say, inevitably advances some political
| perspective over another.
|
| What we should really aim for is thoughtful, civilized, and
| maybe even aesthetically pleasing discourse. That's what
| educated people strive for.
|
| Trying to "avoid politics" is like collecting seashells while a
| tsunami is rolling in.
| surgical_fire wrote:
| Agreed. Those who don't care about politics are doomed to be
| ruled by those who care.
|
| Moreover, avoiding politics is impossible. It's all around
| you. Labor, entertainment, food, housing. Burying your head
| in the sand will only get you to have your ass in the air.
|
| Maybe "be polite" should be a better rule than "avoid
| politics".
| cjs_ac wrote:
| It's scary how widely this varies between different
| communities. On Reddit, /r/politics is mostly people acting
| like they're auditioning for the writers' room on one of
| those late-night talk shows, whereas /r/ukpolitics and
| /r/australianpolitics are almost exclusively people making
| insightful, analytic comments.
| elcritch wrote:
| > The ancient Greek understanding of an "idiot" referred to
| someone who was a private citizen or a person who did not
| actively participate in public life or politics.
| spacebanana7 wrote:
| To play devil's advocate - it's horrible when gaming,
| programming, business or even porn forums get overrun by
| politics.
|
| It's not that the political topics are unimportant but all my
| feeds just end up looking the same as each other and the same
| as a newspaper app. I hate election nights because of this.
| Titan2189 wrote:
| "porn forums" is a thing?
| 7bit wrote:
| Absolutely
| amarcheschi wrote:
| i would be surprised otherwise
| numpad0 wrote:
| http://twitter.com
| intuitionist wrote:
| They're so much a thing that they came back the other way
| and overran politics itself in the North Carolina
| governor's race last year
| nindalf wrote:
| Porn forums are a thing. For example, this politician lost
| what should have been an easy election because someone
| found his old comments on a porn forum - https://en.wikiped
| ia.org/wiki/2024_North_Carolina_gubernator.... Among other
| things he commented on the forum that he'd like to bring
| slavery back.
|
| Honestly did not believe that people commented on porn
| forums before this incident.
| acdha wrote:
| I miss that, too, but the way we get there is by re-
| establishing democratic norms and boundaries. The United
| States is flirting with fascism, and globally we are seeing
| the fallout from that and the cascading effects of climate
| change, not to mention the impacts of AI on employment,
| surveillance and censorship, social media, etc. Keeping
| politics out of forums like the ones you mentioned is like
| keeping oxygen out of a space station.
| jzb wrote:
| Flirting? That was years ago. Fascism has its shit in
| U-Haul and is ready to move in.
| pixl97 wrote:
| Ready to move in, are we sure it's wallet isn't on the
| nightstand and the keys are hanging beside the door?
| thfuran wrote:
| Nah, it's already almost done moving its stuff in.
| ivolimmen wrote:
| If you are American and you voted for this guy ->
| https://www.reddit.com/r/leapoardsatemyface/
| scoresomefeed wrote:
| Inverse devils advocate:
|
| But look at it this way: I see the us political spectrum
| melting down into authoritarianism and you're complaining you
| don't need to be reminded of it.
|
| A similar analogy would be if we are at your house, and it
| catches fire, and you complain that it is interfering with
| watching Netflix while I'm trying to call 911 for help.
|
| From my perspective you are ignoring your own demise and from
| your perspective I'm just being annoying.
| SkyBelow wrote:
| Politics are also never discussed with any level of depth. At
| best, it each side throwing in their opening arguments and
| nothing more. More often you don't even get that and instead
| have attacking people directly, stereotyping, straw manning,
| and all sorts of logical fallacies. Discussion in such a
| situation does not happens, so either it is an ongoing war or
| some side wins and pushes out the rest. None of these
| outcomes would seem beneficial for here, and while I do think
| there would be some slightly longer form discussions here
| compared to most places, I don't think it would be enough to
| avoid the eventual decay.
| keybored wrote:
| Apolitical person: Ugh politics is so dumb
|
| Same person: Why is the world organized in such a dumb way?
| pjmlp wrote:
| Technology without politics is a pipe dream, even the FOSS
| licenses depend on politics.
| bamboozled wrote:
| 100% agree, staying out of politics has been a luxury not
| everyone has, it's totally unavoidable now.
| pif wrote:
| There's politics and there are facts.
|
| Trump voters are stupid. This is a fact.
|
| Right or left leaning, that's politics.
| mrtksn wrote:
| The problem with discussing politics is that it gives you the
| kicks. Its very easy to get into a feedback loop and take
| things quite far off civility. I am also guilty of it, many
| times.
|
| IMHO there needs to be a mechanism for breaking the loop and
| then we can have civil online political discussions.
| Unfortunately most places just ban it or ban those who got into
| the loop, either way its ugly.
|
| IRL when discussing politics and things don't go badly its
| thanks to 3rd party who will moderate or calm down the heated
| debaters.
| kelsey98765431 wrote:
| No thank you. I am absolutely uninterested in civil
| discussions with people who literally want to kill me and
| deport my good friends to guantanamo bay cuba. When you
| accept nazism you throw the concept of civil discourse out
| the window.
| mrtksn wrote:
| See, its unlikely that its those people that you meet
| online and you won't be able to do anything to them anyway.
|
| %99.999 of the time its usually trolls or people with good
| intentions(with wrong solutions based on wrong information
| or understanding of the situation). Trolls can be fun when
| they play with hypothetical scenarios and edge cases,
| conducting thought experiments.
|
| You are also unlikely to change the views of the people
| with good intentions through discussion but they are very
| useful to understand what their motives so you can develop
| beter arguments or solutions. Also, you might find out that
| on some issues you are one of those with good
| intentions(but misguided understanding of the situation).
| bluGill wrote:
| Case in point: you have decided that those who disagree
| with you want to kill you, deport your friend, and are
| otherwise nazis. While a minority do, that isn't the
| majority.
| mulnz wrote:
| I am (un)lucky enough to live in an area where I don't
| have to decide this. People are willing to say it out
| loud.
| citizenkeen wrote:
| One the one hand, yes.
|
| On the other hand:
|
| "Historians have a word for Germans who joined the Nazi
| party, not because they hated Jews, but out of a hope for
| restored patriotism, or a sense of economic anxiety, or a
| hope to preserve their religious values, or dislike of
| their opponents, or raw political opportunism, or
| convenience, or ignorance, or greed.
|
| That word is 'Nazi.' Nobody cares about their motives
| anymore."
|
| - Julius Goat
| thrance wrote:
| We had a word for people that voted for Nazis, agreed
| with Nazis, talked like Nazis but claimed they weren't
| Nazis themselves in the 40s. It was "Nazi".
|
| What matters is that the current administration is
| disappearing people with no legal reasons, due process or
| possible recourse. Either you agree with them in which
| case fuck you, or you don't and you condemn them. There
| can be no compromise or civility when one side is so
| aggressive and dangerous.
| vultour wrote:
| This argument went out the window long ago. You're not
| absolved of responsibility just because you voted for
| someone who wants to hurt people instead of hurting them
| yourself.
| bluGill wrote:
| Quit turning the argument around. forget about "them" -
| what does it say about you when you cannot talk nice
| about people you disagree with?
|
| People who voted for Trump are not stupid. They have real
| concerns that they do not see being met and so they are
| turning to something that while maybe not ideal is at
| least a promise of maybe better. Maybe it will be worse,
| but they don't see things on the right track as they were
| either.
| crawsome wrote:
| Why can't we talk plainly to each other anymore? Can we
| not talk in loaded statements and projection?
|
| They have valid concerns, and taking steps to minimizing
| those concerns is just muddying the water in favor of
| those using political violence against people who don't
| deserve it.
|
| There's a lot of counter-intel campaigns flying around
| all at once, and a lot of them are curated to infect
| brains of people who are willing to accept fascism.
|
| "Well, they're not completely nazis... so you're wrong
| for likening them to nazis!"
|
| "Well, you've decided to shut off discussion to people
| opening your mind about the impending fascism. That must
| mean you're not fit for discussion"
| AlexandrB wrote:
| No thank you. I am absolutely uninterested in civil
| discussions with people who literally want to control
| everything I say and put my good friends into reeducation
| camps. When you accept communism you throw the concept of
| civil discourse out the window.
| btucker wrote:
| I understand you're trying to "both sides" an argument.
| What have you found that has achieved for you in the
| past? Do you change people's opinions with this?
| AlexandrB wrote:
| I have found that no amount of online discussion has ever
| changed anyone's mind on larger issues. We're all pissing
| in the wind here.
| btucker wrote:
| Then why did you post that?
| abvdasker wrote:
| Democrats haven't put anyone into a reeducation camp as
| far as I'm aware. Your enemies are imaginary while the
| parent comment's enemies are all too real.
| AlexandrB wrote:
| Yes, but the Republicans literally want to kill some
| minority groups. /s
|
| Do you know how crazy this all sounds once you're outside
| of a specific left echo chamber? How is the hyperbole I
| employed any more unbelievable than that of the poster I
| was replying to? Another sibling comment to yours says
| that Trump is rounding up political opponents for a
| gulag. Nevermind that he has only rounded up non-citizen
| (most of them in the US illegally) because that's all he
| _can_ do.
|
| If you look at my posting history, it's wildly left-wing
| as little as 2 years ago. I've become completely
| disillusioned with the left after noticing how self-
| contradictory some of those ideas are and how the
| language of crisis is deployed to constantly smear their
| political opponents. Everyone the left doesn't like is
| Hitler and every policy they don't like is fascism. Give
| me break.
|
| Edit:
|
| For a little more elaboration, look at the speech codes
| and compelled "DEI pledges" that American universities
| have employed in the last few years[1]. How is this not
| speech policing? You might argue that these are private
| institutions, and maybe that's fair enough, but when the
| government pulls funding for crap like this the hyperbole
| and outrage persist.
|
| Or look at Canada's bill C-63[2]. This bill aims to allow
| the possibility of life sentences for "hate speech"[3].
| To _me_ this is authoritarian. To many left wing
| commentators, it 's another day at the office, I guess -
| meanwhile the Canadian right wing party is regularly
| called fascist[4][5] despite being basically in line with
| US Democrats on many issues.
|
| [1] https://unsafescience.substack.com/p/the-last-four-
| years-wer...
|
| [2] https://www.parl.ca/DocumentViewer/en/44-1/bill/C-63/
| first-r...
|
| [3] https://bccla.org/2024/09/whats-in-bill-c-63-why-are-
| we-alar...
|
| [4] https://medium.com/pigeons-peculiarities/pierre-
| poilievres-p...
|
| [5] https://cultmtl.com/2025/02/pierre-poilievre-has-
| racked-up-e...
| thrance wrote:
| Oh good, "it's only non-citizens". Nevermind that they're
| still supposed to be protected by the constitution, then.
| Also, Trump said two days ago that he wishes to send
| citizens to El Salvador too [1]. Are we allowed to call
| them fascist or should we wait for that to be made
| illegal too?
|
| Trump does not care about the law. SCOTUS, in a historic
| 9-0 ruling, commanded him to bring back Kilmar Abrego
| Garcia from El Salvador. He unsurprisingly did not
| comply. Yet you're still insisting he can't legally do X
| or Y so everything is fine. When has that stopped him,
| like ever?
|
| If that's not fascism, then what is? What would it take
| for you to say "OK that's too much"?
|
| [1] https://apnews.com/article/trump-citizens-prison-el-
| salvador...
| frob wrote:
| What you are saying is the fantastical kool-aid Fox News
| and alt-right media spin to you.
|
| In the meantime, Trump is actually deporting people
| without due process to inhumane torture camps run by a
| dictator while openly bragging about it and defying court
| orders.
|
| These two things are not the same.
| AlexandrB wrote:
| > What you are saying is the fantastical kool-aid Fox
| News and alt-right media spin to you.
|
| What I'm replying to is the fantastical Kool-aid MSNBC
| and alt-left media spin. I'm pretty sure the Republicans
| are not going to be rounding up and killing minorities
| despite hyperbolic descriptions like "people who
| literally want to kill me and deport my good friends to
| guantanamo bay cuba".
|
| Wait, you're saying El Salvador is a dictatorship? From
| briefly glancing at Wikipedia I don't see any evidence of
| that. Why the need to smear another country just to make
| Trump look worse?
| miningape wrote:
| Any argument where you can change a few words and it
| suddenly makes the opposite point was never a good
| argument to begin with.
|
| In short: it doesn't convince you of anything, it merely
| reinforces your existing biases.
| thrance wrote:
| Insane talk. Where is that communist political force
| seeking to open gulags? The Democrats? Hahahahah
|
| Trump _has_ a gulag in El Salvador, _right now_ , that he
| uses to send his political opponents to. And you people
| are still making up fantasies to play the victim.
| Absolutely disgusting.
| DrillShopper wrote:
| > people who literally want to control everything I say
| and put my good friends into reeducation camps
|
| Then you shouldn't talk to Trump supporters as that's
| exactly what they want to do for anyone that disagrees
| with them, and last I checked, they're capitalists.
|
| They are planning on abducting people off the street,
| completely ignoring the courts and denying due process,
| and sending them to another country where they're being
| deprived of their rights, again, with no due process and
| no (effective) judicial review.
|
| I'd expect most right wingers would be against this, but
| the Orange in Charge's supporters seem to hew to the
| "well if you didn't do anything wrong you've got nothing
| to worry about" angle because it's something happening to
| people they think deserve it.
| AlexandrB wrote:
| > but the Orange in Charge's supporters seem to hew to
| the "well if you didn't do anything wrong you've got
| nothing to worry about" angle because it's something
| happening to people they think deserve it.
|
| This is _literally_ the left wing reply when people
| complain about losing their job or their family for
| voicing the wrong political belief. "They deserve it,
| they should 'do better'."
| DrillShopper wrote:
| There is a huge difference between losing your job and
| being black bagged, sent to El Salvador, and possibly
| killed.
|
| Let's keep that in perspective.
| enraged_camel wrote:
| I don't think any Democrat has ever put anyone into
| reeducation camps. I may be mistaken though - can you
| cite some examples?
| AlexandrB wrote:
| I don't think any Republican has advocated for a policy
| of killing minorities. The hyperbole of my post is the
| point.
| galangalalgol wrote:
| Having civil discussions with people who disagree isn't
| about politeness or acquiescence. Having political
| discussions per the same rules we use for technical
| debates, like steel manning, allows information to actually
| flow both ways. I'm up to four people now that I changed
| parties between 2020 and 2024. That doesn't seem like a
| lot, but if everyone was doing it it would make a
| difference. It took time. I had to non judgementally listen
| to their concerns and intuit the fears underneath. They
| were reasonable intelligent people operating off of
| propaganda mostly. The emotional hook had been set and used
| draw them further and further into false narratives that
| fed their fears and hopes. To think I am immune isn't
| realistic either. My triggers are getting used to pull me
| the other direction, to make me uncompromising, and to view
| those who disagree as inhuman. Some of that is game theory
| polarizing us, but some of it is the intentional result of
| the Kremlin's standard divide and conquer they have been
| using on us for over half a century. The antidote is calm
| conversations with voters who have been made scared about
| irrational things, and looking to see what fears we are
| being manipulated with as well.
| DrillShopper wrote:
| > Having civil discussions with people who disagree isn't
| about politeness or acquiescence. Having political
| discussions per the same rules we use for technical
| debates, like steel manning, allows information to
| actually flow both ways.
|
| What additional information do they need to get out there
| other than they want me and people like me dead? What
| additional information do I need to get out there other
| than I don't want them to do that?
| wins32767 wrote:
| The logical end state of this belief is a civil war. I
| assume that in lieu of trying to change minds you're
| buying guns and ammo and trying to organize like minded
| people into a militia to protect your safety? Cause if
| not, I don't really think you really believe that a
| significant fraction of the country wants people like you
| dead.
| DrillShopper wrote:
| I'm in the process of emigrating to Europe since it's not
| safe for me and my family here.
| galangalalgol wrote:
| Not sure which hated demographic you fall in, but I have
| friends that are suddenly being threatened by individuals
| who now feel free to expose their true selves. I can't
| believe almost half the population are like that though.
| Escape may be the best option for a lot of people at this
| point. My friend doesn't realistically have that option
| due to finances and skillset. I do think people who
| aren't in immediate danger can pull a lot of people
| supporting those fueled by hate away from their positions
| with calm dialogue.
| mrtksn wrote:
| In my experience as a chronic immigrant, most people are
| nice but there are some a-holes who would want to harm
| you or see you get harmed but they would not act unless
| they feel in power.
|
| Therefore, most of the time you can just ignore them and
| your experience wouldn't any different than the natives
| who would also encounter a-holes for different reasons.
| The problem starts when someone in power to affect your
| life is one of those but in normal times you still can
| push back by questioning their actions as they still seek
| approval from the larger society.
|
| The case with Trump seems to be the same with the case
| with Brexit: Those a-holes(not everyone who support those
| but a subset of them who are a-holes) start believing
| that they are in power and the society approves them
| therefore they can act on their instincts or plans.
|
| I was working in London on the Brexit referendum day,
| some of our Spanish developers had trouble with people
| from their neighborhood right after the referandum.
| crawsome wrote:
| The loop is intentionally being closed and sped-up by enemies
| of the USA who want to exhaust the USA in every way possible.
|
| After the infekktion of 2015, moderators of Right-leaning
| discussion boards started amping up their censorship. Left
| leaning and moderate discussion boards still tend to be more
| moderate, letting most discussions in and censoring less.
|
| Most of the time, one side is trying to play an equal field,
| while the other shits all over it and just yells "Winning!"
| deadbabe wrote:
| Not keeping politics out of our lives is the reason we've ended
| up with a totalitarian fascist dictatorship. If politics is
| forbidden, people have to just make up their own minds and vote
| for what makes sense to them, instead of banding together and
| slowly intensifying to the most radical extremes in bids to
| outdo each other.
|
| Everytime you discuss politics on the internet, you entrench
| the current administration.
| timacles wrote:
| Fascinating logic. The victims are at fault. If only they did
| something different the abusers would have never had to abuse
| them.
| Pxtl wrote:
| > the "I wish HN would stay out of politics" crew.
|
| Sadly, this crew includes the site's moderation.
| mardifoufs wrote:
| ah yes, losing the... CVE database is truly the wake up call to
| get engaged in politics.
|
| I mean sorry but I'm not sure if you're being ironic. It sounds
| like something you'd read on ngate
| orblivion wrote:
| HN can stay out of politics just fine for the most part. If a
| political topic comes into tech we can talk about it then, and
| stay out of other crap that insufferable people drag in because
| "there's no such thing as being neutral" or whatever.
| nodesocket wrote:
| I'm betting CVE will get sponsored by a security company or
| Cloudflare.
| gm3dmo wrote:
| Anyone feel confident that the companies who benefit massively
| from MITRE are even now planning to step in and provide
| significant funding?
| gabesullice wrote:
| As a newly minted cynic, this seems like a cynical play to save
| someone's budget.
|
| Step 1: Post discreetly to a forum with minimal information and
| an absurdly short deadline
|
| Step 2: Phone your friend, the former board member, to make your
| case on LinkedIn
|
| Step 3: Ring up a friendly journalist and give them a tip
|
| Step 4: Reference the insuing chaos as justification for keeping
| your project funded
|
| Note that the article carefully avoids pinning the blame on DOGE
| or the Whitehouse while heavily implying it. MITRE is technically
| a private entity, albeit a non-profit. And the very last
| paragraph of the article states:
|
| > A CISA spokesperson told CSO, "CISA is the primary sponsor for
| the Common Vulnerabilities and Exposure (CVE) program... Although
| CISA's contract with the MITRE Corporation will lapse after April
| 16, we are urgently working to mitigate impact and to maintain
| CVE services on which global stakeholders rely."
|
| To be clear, the point isn't to say that the CVE program isn't
| valuable, nor is it to say that it's _good_ for a shenanigan like
| this to be necessary.
|
| The point is that, unless you're directly involved in this
| subject (not impacted--involved), it's probably best to maintain
| a "wait and see" attitude rather than succumb to catastrophizing
| this news.
| girvo wrote:
| Have you seen proof that this is what has been happening? Your
| explanation is much more convoluted than "DHS cut funding, like
| the administration has said it is going to do".
| gabesullice wrote:
| These explanations are not mutually exclusive.
| jl6 wrote:
| So is this going to instantly break a bunch of tools like Trivy?
| wengo314 wrote:
| vibe coding could not have come at a worse moment.
| sgt wrote:
| Just tell the AI: "Make this code secure" /s
| redleader55 wrote:
| I see this as the perfect moment to get into consulting -
| either development, or security. People were not sure what jobs
| AI will create: "GenAI babysitting" is one of them.
| skirge wrote:
| only one country pays but all benefit from it. It should be
| funded by all who benefit like UN.
| goku12 wrote:
| I'm sure that a hundred other countries will step up to fund
| it. But have you given any thought about why the US was so
| willing to sponsor it alone in the past?
| jowea wrote:
| I thought most people in the US wanted the UN to have less
| control over this stuff? Remember the talk about moving control
| of the Internet to the ITU (International Telecommunication
| Union)?
| hubabuba44 wrote:
| The real irony here is that a lot of ycombinator founders and the
| people reading HN were exactly the ones making this possible and
| now start to wonder why the snake eats its own tail.
| cantrecallmypwd wrote:
| Sorry, I made the mistake of installing PyPy.
| hubabuba44 wrote:
| I assume that this comment should go somewhere else or I'm
| not able to decipher the message ;)
| jampekka wrote:
| PyPy's logo is a snake eating its tail.
| hubabuba44 wrote:
| Cool thanks!
| cantrecallmypwd wrote:
| Sorry and thanks GP. ;o)
|
| Your nerd card had been validated for today. Go forth,
| ethically.* :D
|
| * Oops, I introduced 2 more programming languages, my
| bad.
| this15testingg wrote:
| exactly; I hope ycombinator and its proponents can enjoy living
| in the ancap fantasy land where you have to pay to be alerted
| for a climate change fueled mega hurricane (also caused by this
| _exact same_ reckless, unregulated greed) because NOAA was
| disbanded. Billionaires shouldn 't exist, but neither should
| millionaires.
| sebstefan wrote:
| You don't need MITRE
|
| For-profit private journaling is working really well for
| academia!
| ourmandave wrote:
| Will they have a free tier where I can sit through 30 second
| ads? =(
| j-krieger wrote:
| The missing funding is something like 2 million dollars. Any US
| company could make this issue go away in an instant.
| hubabuba44 wrote:
| We will see. I understand that money shouldn't be an issue
| but trust might be, no?
| Sonnigeszeug wrote:
| Its not a money problem, its a understanding problem.
|
| Shouldn't the most powerful country has something like this?
| Being even in the forefront of it?
|
| The USA was doing cyberprotection against Russia and
| cyberattacks across the world.
|
| Now suddenly it doesn't need it anymore?
|
| Like just did Russia go away (or has russia won and sits now
| in the white house)?
| drstewart wrote:
| You're right.
|
| I don't understand why the EU wasn't funding it and isn't
| funding it now. I thought they're united against Russia?
| lentil_soup wrote:
| because they already do? https://euvd.enisa.europa.eu/
|
| please, stop spreading your weird anti-europe views
| drstewart wrote:
| Great. Then there's no loss here. What's the big deal?
| sweezyjeezy wrote:
| Your comments feel a bit incoherent - just extend your
| reasoning for why you think Europe should want to fund
| this back to the US again.
| drstewart wrote:
| Can you extend your reasoning for why you think the US
| should want to continue to fund this for the EU?
| sweezyjeezy wrote:
| "for"? You realise this is a homeland security matter for
| the US as well as the EU?
| testbjjl wrote:
| The GP sounds like one of these people who describe
| themselves as self made, or libertarian, where history
| begins where you like it and coalitions are only worthy
| when you're the biggest benefactor. Best to ignore and
| let the leopards find them.
| sweezyjeezy wrote:
| haha, sage advice
| nosianu wrote:
| Or they wanted this, because this could be part of the
| privatization of many government functions. They, or at least
| some of them, could see this as controlling this function for
| money. It's a regular stream too, the valuable subscription
| model and customers who really need the service (and if they
| don't, just add a new law in the name of IT security forcing
| firms to sign up).
| hubabuba44 wrote:
| To me it looks too chaotic to be a planned privatization plan
| but who knows.
| voxic11 wrote:
| I think its part of the tried and true strategy of causing
| chaos then blaming the government for it and presenting
| privatization as the solution.
| testbjjl wrote:
| Move fast and break things as we say.
| rcarmo wrote:
| Now would be a great time for a major tech company to support
| them (or, even better, a consortium).
| basemi wrote:
| For now, historical CVE records will be available at GitHub:
|
| https://github.com/CVEProject
| InsideOutSanta wrote:
| This makes me wonder what other stuff most people don't know
| exists but is important to our society has quietly disappeared in
| the last few weeks. We know about this one because we know it's
| important. What are the things we don't know about?
| jeroenhd wrote:
| https://www.project2025.observer/ lists a few. Of course, those
| are only the agencies the Trump people know about and
| explicitly want to destroy, but it's a start.
| knowaveragejoe wrote:
| The cheerleaders don't care. Americans' relative certainty and
| quality of life is backstopped by institutions they either
| barely understand or have never heard of. Let them touch the
| stove, I guess.
| jl6 wrote:
| It's a reckless move to cut funding so abruptly, but taking a
| step back from the short-term chaos, it probably _is_ an anomaly
| that this was government funded. All of private tech relies on
| it, and private tech is big enough to pay for it. I hope that the
| trillion dollar babies consider this an opportunity to pool
| together to form a foundation that funds this, and a bunch of
| other open source projects run by one random person in Nebraska.
| kbumsik wrote:
| > it probably is an anomaly that this was government funded
|
| Companies can definitely fund it. But to be fair the gov,
| including NIST, also relies on CVE.
| chasontherobot wrote:
| ah yes, let private entities pay for it. then when there is a
| vulnerability with one of those entities' software, they can
| pay a bit more to bury it!
| padjo wrote:
| Ah yes the old "well can't concerned citizens band together,
| form a committee, collect revenue and fund things that are in
| the common interest" answer you hear from small government
| types that makes me think you lot don't really understand what
| government actually is.
| JCharante wrote:
| > it probably is an anomaly that this was government funded.
| All of private tech relies on it, and private tech is big
| enough to pay for it.
|
| I mean doesn't big tech and the people they give salary money
| to pay taxes? Ground transportation companies rely on public
| roads and but we fund it because having the infrastructure is
| an economic multiplier.
|
| I'm not arguing in favor of funding the CVE program, I just
| don't think that's a good reason.
| jl6 wrote:
| Opinions vary on what the purpose of government is, but if
| you take the view that the government's priorities should be
| providing services that are impossible, inefficient, or
| unethical to provide privately, then I don't see the CVE
| program making the cut, when the tech industry is
| collectively flush with resources and has every incentive to
| form an industry consortium to take it over.
|
| A modern Open Group, perhaps?
| bspammer wrote:
| The US government itself uses the database, so there is a
| strong national security interest in it not being in private
| hands.
| phillipcarter wrote:
| Considering the large number of government agencies that have
| sponsored the program, no, I don't think it was an anomaly:
| https://www.cve.org/About/History
| bslanej wrote:
| Just seeing HN mad like this makes things like these so much
| worth it.
| goku12 wrote:
| Oh! It will be even more fun when the entire infotech and
| infosec industry starts seething soon. Then the rest of the
| world will just make alternative arrangements and move on,
| leaving the US behind because they can't be trusted anymore.
| HN's reaction is just a small taste of things to come.
| karel-3d wrote:
| Phew, no new annoying CVE reports in my Docker images from today
| dhx wrote:
| The latest contract[1] (I hope this is the right one) for MITRE's
| involvement with CVE and CWE programs was USD$29.1m for the
| period 2024-04-17 to 2025-04-16 with optional extension of
| expenditure up to USD$57.8m and to an end date of 2026-04-16.
|
| Seemingly MITRE hasn't been advised yet whether the option to
| extend the contract from 2025-04-16 to 2026-04-16 will be
| executed. And there doesn't appear to be any other publicly
| listed approach to market for a replacement contract.
|
| [1]
| https://www.fpds.gov/ezsearch/jsp/viewLinkController.jsp?age...
| gwd wrote:
| I can't figure out why the hue and cry wasn't raised until the
| very last minute. Did they not know a month ago that they were
| running out of time? Is it standard practice for the government
| not to say they're going to extend the contract until the day
| beforehand or something?
| sq_ wrote:
| Right now, yes. You can pretty easily have a scenario where
| you're talking to the agency you're working with and they're
| saying "we want to renew this, but we don't know if they'll
| give us the money in the end".
|
| So you'll get a bunch of "hopefully this week" up until it
| expires.
| pjmorris wrote:
| I was at VulnCon last week, and an NIST representative said
| that there were no plans to cut CVE funding.
| Brosper wrote:
| Europe needs to save the world!
| kesor wrote:
| Good, less government involvement is better for everyone.
| NilayK wrote:
| > A coalition of CVE Board members launched a new CVE Foundation
| "to ensure the long-term viability, stability, and independence
| of the Common Vulnerabilities and Exposures (CVE) Program."
|
| > https://www.thecvefoundation.org
|
| https://mastodon.social/@serghei/114346660986059236
| hahajk wrote:
| So if the govt stops paying them they'll continue to do the
| work for free?
| lou1306 wrote:
| More likely they will seek funding from companies and other
| organizations, as every other foundation/consortium of this
| kind does.
| pantropy wrote:
| The way their letter is worded it seems that they have a
| rainy day fund constituted to ride out the stormy next few
| week and I'm fairly certain they'll come back with more
| details as to how they'll be acquiring funding from now on in
| the next few days. Maybe paid access to an API, maybe
| donations from large companies that use the system, maybe
| something else ::shrug:: Hopefully a project as important as
| this doesn't just dissapear completely because of government
| pressure.
| jmcgough wrote:
| They're converting to a nonprofit, so instead of federal
| funding they will need funding from big tech companies.
| panzagl wrote:
| MITRE is already a not-for-profit.
| delfinom wrote:
| How else will they continue burning out open source
| maintainers with bullshit?
| gnfargbl wrote:
| This kind of a consortium needs to explicitly avoid being
| captured by both the product vendors (who could be incentivised
| to manipulate the CVE issuance process to support their own
| remediation timescales), and by security companies (who could
| be incentivised to obtain a competitive advantage via
| preferential access to the CVE database).
|
| It isn't impossible for a commercially-funded organisation to
| avoid this kind of capture, but it isn't easy either. My mind
| immediately jumps to the relationship between the Mozilla
| Foundation and Google.
| transpute wrote:
| Then there were two: https://gcve.eu
|
| Plus the proposed "Foundation for Standards and Metrology
| (FSM)" to build on NIST, https://democrats-
| science.house.gov/bills/the-expanding-part...
| tbrownaw wrote:
| Don't some projects already issue their own CVEs?
| detaro wrote:
| yes, but it's a hierarchy. If you disagreed with their
| judgement you could always go up the chain, and MITRE can
| take the privilege away again if they think a vendor is
| misusing it.
| gnfargbl wrote:
| CNAs [1] are assigned blocks of CVEs and then assign from
| within that block, but the system only works if there is
| overall administration of the CVE Program [2].
|
| My concern is that a capture of the administration would
| become a capture of the entire programme. Looking at the
| structure, it seems possible that CISA are in a position to
| prevent any such capture but, given some of the recent
| positions taken by the US government, we'll need to wait
| and see how that plays out.
|
| [1] https://www.cve.org/ProgramOrganization/CNAs
|
| [2] https://www.cve.org/ProgramOrganization/Structure
| pama wrote:
| This smells like a quick attempt to enable phishing for
| vulnerabilities, and not a legit way to make progress. The
| comment is from a person that runs a security startup and the
| site is a google site that people can report to google as a
| scam. (Edit: downvote as you like it-- perhaps my language was
| too harsh to help make the point clear. It is interesting how
| easy non-sec people fall for names and quotes and authority..
| building trust does not come overnight, in fact it is never
| fully there, and infosec experts would not fall for such supply
| chain redirections with questionable future. Hopefully we will
| not have to test this idea soon, though some level of
| reliability and long-term automation would be welcome. We need
| technical, generally agreed upon systems, not a "foundation").
| londons_explore wrote:
| How much was this contract worth?
|
| If it was $5000/yr it's very different to if it's $5M/year for
| what amounts to little more than an instance of mediawiki.
| harisec wrote:
| $44M/year?
|
| https://www.usaspending.gov/award/CONT_AWD_70RCSJ23FR0000015...
| londons_explore wrote:
| Totally worth cancelling then.
|
| Some volunteer will set up a GitHub pages and mailing list to
| fulfill the same duties.
| Peanuts99 wrote:
| Or 10 people will create that list and nobody will use any
| of them. The whole point here is that the CVE program had
| the network effect of being the defacto list of issues but
| now that's been pissed away.
| anilakar wrote:
| Let me guess: Trump is going to make China pay for it.
| jibal wrote:
| Bad guys helping out bad guys--it's what mobsters do.
| mzhaase wrote:
| Long term its probably good to have a less US-centric world.
| jeroenhd wrote:
| This is a chance for the EU to step up and take over. If the US
| government won't pay for the CVE program, the EU surely could.
| Many EU countries already run a program like this to server
| their own interests, and I believe the EU does as well.
|
| If the US is willing to give up influence and control over the
| cybersecurity sector, we should accept that gift and use it to
| our advantage.
| moomin wrote:
| I'm sure a much better private sector alternative will appear any
| day, in line with conservative dogma.
| rvba wrote:
| Why cant wikipedia foundation step in? They have millions of
| dollars.
| drdrek wrote:
| LOL this is Amazing... Holy shit
| gorbachev wrote:
| I wonder what would happen to CVE program funding if Tesla and
| SpaceX would be zero-dayed to hell and back.
| redleader55 wrote:
| We will soon find out, probably.
| phtrivier wrote:
| I'm really curious about the "soon" part, though. What is the
| timeline for something very visible to happen, and still be
| directly relatable to DOGE ?
|
| Just imagine if it happens in three years, after the midterms
| - someone will be able to blame the Dems for it :) !
| dools wrote:
| Uh oh did someone CVE grok or twitter?
| WillAdams wrote:
| FWIW, I've never understood why this sort of thing wasn't just
| directly handled by the NSA --- aren't they the group which
| should be tasked with cybersecurity?
|
| I always suspected that "Department of Homeland Security" would
| lead to Banana-republic-like shenanigans --- could we defund
| them?
| donohoe wrote:
| I don't think anyone trusts the NSA to run a program like this.
| dfedbeef wrote:
| "National Security" doesn't mean you personally. It's the
| government only. There's a conflict of interest that
| immediately arises if a part of the DoD (who owns cyberwarafe,
| which uses vulns) maintains a public vuln database.
|
| (Edited to be less salty, sorry)
| thih9 wrote:
| I can't see any long term benefits for the US. It looks like the
| current administration is fine with chaos and disruption on an
| unprecedented scale.
| donatj wrote:
| Practically speaking, how much could it cost to maintain the CVE
| database?
|
| Given its enormous value, isn't this something that the
| community, especially FAANG (MAANA?) could step up and fund as a
| nonprofit?
| uptownfunk wrote:
| Seems like a big miss on the part of DOGE?
| i_love_retros wrote:
| At this point it's not crazy to believe Russia is running the
| country
| dfedbeef wrote:
| This level of stupidity seems pretty American to me
| paulmendoza wrote:
| Anyone who voted for Trump voted for this type of dumb action.
| This is a major loss for society and safety.
| jnovacho wrote:
| It looks like the decision has been reverted, for now at least:
| https://www.forbes.com/sites/kateoflahertyuk/2025/04/16/cve-...
| jeff_carr wrote:
| The contract with MITRE has been extended.
|
| https://www.forbes.com/sites/kateoflahertyuk/2025/04/16/cve-...
|
| My guess indefinitely.
|
| DOGE might be a bunch of idiots, but in the entire DOD, there are
| non-idiots.
| metalliqaz wrote:
| not just idiots... _malicious idiots_
| lenerdenator wrote:
| Malicious idiots surrounded by sheepish intelligent people.
| fennecfoxy wrote:
| Hasn't that always been the case for society at large? From
| Wernher Von Braun to Oppenheimer.
| xpe wrote:
| > Malicious idiots surrounded by sheepish intelligent
| people.
|
| Prefixing people with "sheepish intelligent" is bound to
| oversimplify this. Many of the non-DOGE employees who
| directly see wrongdoing are likely making calculated
| decisions on what to do. It depends on many factors,
| including the law and whistleblower protections.
|
| Many of them are responding in various ways that they hope
| will have an impact. Some resign in protest. Others file
| lawsuits. Others leak to the press.
|
| Could they do more? Yes. So let's help them.
|
| What can we do? Just to give two relatively middle-of-the-
| ground recommendations: First, donate to legal-protection
| funds for whistleblowers. Second, call your representatives
| and demand reinstatement of the inspectors general.
| tomrod wrote:
| Per news reporting, not just malicious idiots but foreign
| agents.
| tlogan wrote:
| My guess is that they'll be phased out next year. The long-term
| goal seems to be transitioning the CVE program into something
| more like an industry-led consortium. (If you did not notice
| they operate zero budgeting approach: cut everything and if
| something is very important reverse it. But you cut first and
| then ask questions.)
|
| It's worth noting that MITRE is a DoD contractor (with minor
| contracts from other agencies like this one). Having the CVE
| program operated by a company funded by the U.S. military
| raises valid concerns about conflicts of interest--especially
| in an ecosystem that depends on neutrality and global trust.
| nxobject wrote:
| I'm a little hesitant to trust a CVE database operated by
| private industry on the grounds of conflict of interest for
| that reason, too.
| ThinkBeat wrote:
| I am quite hesitant to trust the DOD to keep track of
| software vulnerabilities. Some parts are developing and
| exploiting vulnerabilities. And given a fresh feed of what
| people find, and usually a delay from notification until
| publication, which may sometimes just be a bit longer of a
| delay, would allow the DOD to weaponize the vulnerability
| for their own use as well.
| j16sdiz wrote:
| CVE Numbering Authorities (CNA) have lots of control over
| those.
| derektank wrote:
| This contract is funded by CISA, which is an agency
| within the Department of Homeland Security, not DoD. As
| far as I'm aware, there are no components of DHS with
| Title 10 or Title 50 authorities to conduct cyber
| operations, unless you count the Coast Guard but they
| normally operate under Title 14. So there really should
| be no conflicts of interest as no one in the DHS is
| authorized to exploit vulnerabilities as part of cyber
| operations.
| tylermw wrote:
| MITRE is a Federally Funded Research and Development Center
| (FFRDC), which is a distinct type of federal contractor
| with strict conflict of interest regulations. They are
| owned by the federal government, but operated by
| contractors and are specifically structured and regulated
| to minimize conflicts of interest, so are distinct from
| "private industry" in many regards.
|
| You can read a congressional report by the CRS describing
| FFRDCs and their role here: https://www.congress.gov/crs-
| product/R44629.
| guerrilla wrote:
| They were talking about AFTER that when it is privatized.
| That's what the comment they're responding to was talking
| about, not it's current state.
| stonogo wrote:
| MITRE is absolutely not an FFRDC. It's a regular old
| 501(c)(3) which happens to _manage_ FFRDCs.
| derefr wrote:
| I'm the opposite -- and I think this might be the "4D
| chess"+ interpretation of this move as well.
|
| In peacetime, I think everyone is generally alright with
| something centralized like the CVE database.
|
| But in what increasingly seems like _the lead-up to
| wartime_... I 'm hesitant to trust a CVE database operated
| _or funded_ unilaterally by a single government -- or even
| multilaterally, if the governments are all ones that all
| would end up on the same side of a hot war.
|
| (Why? Strategic censorship of reports while the DB's patron
| takes advantage of the exploit, for one. Such a database
| becoming a high-priority cyberwar target, for another.
| Strategic wasting of enemy cybersecurity resources with
| false announcements, for a third.)
|
| IMHO, the ideal form for the organization managing CVE, is
| one analogous to IANA and its Regional Internet Registries
| (RIRs).
|
| IANA slices up the keyspace of IPs to assign to RIRs, and
| arbitrates disputes -- but both at such a high level that
| their work is effectively in a de-facto state of "done
| until something comes up". The RIRs do all the actual
| everyday work.
|
| This means that in a hot war that different RIRs end up on
| opposing sides of, where at least some of the RIRs can no
| longer trust the ownership of IANA to act in their best
| interests, the RIRs can just ignore IANA for a while, and
| keep on doing their own thing (managing allocations from
| their previously-agreed parts of the IP keyspace), and
| everything will still work.
|
| And RIRs that control parts of IP space contended over by
| opposed states? They can just be split up, under obvious
| rules (every current allocation goes to the sub-RIR
| associated with the state that controls the
| gov/mil/corp/org entity currently holding that allocation.)
|
| That's not the case with the CVE database under its current
| ownership. There's no established way to namespace it, no
| obvious way to split it up and keep it all working.
|
| And I think that this problem would be obvious to the DoD.
| Which is precisely why paying to host a single-source-of-
| truth CVE database loses its lustre when that same DoD is
| aware that such a split _might_ soon have to happen.
|
| ---
|
| + I dislike the term "4D chess", because it implies one
| chess master who's really good at predicting non-obvious
| outcomes -- rather than an entire military-industrial-
| complex acting as "see something, say something" inputs to
| an intelligence apparatus that does a lot of hard work and
| simulation analyzing potential outcomes, to produce easily-
| digested suggestions and action items. There just needs to
| be _one guy_ in the Pentagon / the military / wherever,
| who realized this and sent a (classified MILNET) email
| about it.
| numbsafari wrote:
| ... and that industry led consortium will have a board all
| paid princely sums, and an executive leadership team that is
| conflicted to the hilt and paid kingly sums, and they will
| charge exorbitant rents in order to keep the lighthouse lit.
|
| There's flaws with every approach, but I much prefer the
| approach where this sort of thing is treated as a public
| good, rather than as yet another soon-to-be walled garden.
| bunderbunder wrote:
| I keep thinking of that time Wisconsin's state government
| privatized a bunch of IT stuff in the interest of
| "government efficiency", and the cost taxpayers paid for
| those specific functions increased by several hundred
| percent while quality of service went down.
|
| At that same time, though, I worked for a contractor that I
| do believe saved states money compared to doing things in-
| house. The work we did really required specialists. But no
| one state had enough of the work to keep one busy all year.
| So sharing a pool of people to do the work among many
| states meant there was room for both saving the states
| money and allowing some profit for the company.
|
| The idea that you can just blanket assume that private
| industry is inherently more efficient than public works
| really needs to die. There doesn't seem to be any more
| evidence to support it than there is to support the idea
| that it's inherently _less_ efficient. Life just isn 't
| that simple. It's all case by case.
| dimitrios1 wrote:
| For every example of privatization going wrong, there's
| least one example (if not two) of it going right.
|
| But serious question -- what is the difference these days
| anyways? Our entire government is effectively privatized
| anyways from the local level up to the federal. We rely
| on contractors for almost everything that matters. We
| just maintain this facade that they are not privatized.
| sollewitt wrote:
| I've never seen one that worked long term. The basic
| premise is "what was done for $X dollars with no profit
| motive can be done for <$X dollars with profit motive
| doesn't hold up - you make something private, it wants to
| make more profit.
|
| Just for the most ready to hand example for me, PG&E in
| SF vs public electricity utilities on the peninsula - the
| privatized electricity costs twice as much per kWh - and
| of course it does because the PG&E CEO needs to make $17M
| from somewhere, the share price needs to go up etc. the
| rich need to skim from the top, that makes the cost
| higher.
|
| If you have an essential industry the cynical play is to
| privatize to save cost, then do a bad job and then
| effectively make your losses public through bail-outs
| while still making profit.
| derektank wrote:
| >The basic premise is "what was done for $X dollars with
| no profit motive can be done for <$X dollars with profit
| motive doesn't hold up - you make something private, it
| wants to make more profit.
|
| No, the basic premise of privatization is that, assuming
| the product or service has multiple potential customers,
| private industry can operate at scale which, alongside
| competition from other companies, drives down the price
| and the government can purchase it "off the shelf" at the
| prevailing commercial rate. Those assumptions don't
| always hold, utilities being a great example of this, but
| it's not inherently blind or naive to consider
| privatizing some components of government function. We
| don't expect the government to operate its own vehicle
| assembly lines even if the government needs cars; they
| just go buy one from Ford or GM.
| bunderbunder wrote:
| I'd add that that, for this calculus to work out in a
| straightforward way, a competitive market is necessary
| but not sufficient. You also need other factors that help
| drive economies of scale, such as the thing in question
| being a manufactured good that can be sold to many
| people, or the production requiring expensive and
| specialized equipment that can be used for more than just
| that one thing.
|
| I'm no expert, but I'd guess that these factors are more
| likely to line up in manufacturing and construction, or
| even R&D, than they are for things like maintenance of
| specialized IT systems or administration of services.
| sollewitt wrote:
| Answer for your serious question: hiring contractors
| isn't "privatized" - that's outsourcing. The thing you're
| saving on is the ongoing cost of having permanent staff.
|
| The difference is the government and public entities like
| mayoral offices or parliaments get to decide how the
| entity (doing the contracting) is run and approve costs,
| and the entity is under no obligation to return a profit.
| taeric wrote:
| Would love to see a list on both sides. It is easy to win
| an argument when you get to gesture at evidence without
| being specific.
|
| For your question, the difference is if a government
| spend succeeds, it should lead to more things that the
| people can do. If a private company succeeds, it largely
| funds just the company.
|
| And, ideally, it should be fine that both the
| government/nation gets benefits while rewarding
| successful contractors. Nothing wrong with that.
|
| This is hilariously viewable with Musk. People love to
| point out how he risked so much on Tesla. Ignoring all of
| the capital that the government risked in the same
| venture.
| dimitrios1 wrote:
| I am not here to argue for a "side", to win an argument,
| nor provide a thesis defense with citation and references
| -- this is an answer you can easily get from ChatGPT.
| There's quite literally hundreds.
|
| To add a wrench to both "sides" some of the most
| effective have been state/federal-owned /state/federal
| controlled corporations -- or generally, arrangements
| where you still maintain capitalistic economic incentives
| and drivers, but have government oversight and
| (effective) regulation. I think everyone would that is
| good, but sometimes it takes different forms.
| jmull wrote:
| > The long-term goal seems to be...
|
| Where do you get that from?
|
| I've seen no sign of long-term goals, much less any
| mechanisms being put in place for follow-through on those
| goals.
|
| It seems like people keep making the mistake of believing
| there's a detailed plan, while all evidence tells us there
| isn't. I guess it's the normal human tendency to see order in
| the chaos.
| tlogan wrote:
| Project 2025 lays out a clear vision for the privatization
| and decentralization of federal functions. It's not subtle
| --it explicitly calls for it.
|
| Separate from whether we support this or not:
|
| Trump is doing--or promising to do--exactly what he said he
| would. We can disagree with the policies, but it's not
| accurate to say he or his team are directionless or
| incompetent. They have a coherent (if controversial)
| agenda.
|
| So rather than dismissing them as clueless or idiots, it's
| more productive to debate this:
|
| - Why is outsourcing CVE program to private consortia a bad
| idea?
|
| - Could a model exist where a private consortium is
| supported by federal grants, but maintains accountability
| and public interest safeguards?
| chowchowchow wrote:
| Actually Trump repeatedly said he didn't know about
| project 2025. He's so scattered in his campaigning that
| it's possible to pretty much justify any action as "what
| he said he would do." But saying executing project 2025
| is exactly what he SAID he would do defies all reality.
| It may be what intelligent observers expected him to do
| but it is not what he said.
|
| Edit: good lord people I'm not defending Trump I'm saying
| he lies about everything including that he lied and said
| he wasn't going to do project 2025. Read the post I'm
| responding to!
| pstuart wrote:
| > Actually Trump repeatedly said he didn't know about
| project 2025 * He said he'd end the war
| in a day. * He said he had a better health care
| plan. * He said he'd drop the price of eggs.
| * ... * He said lots of things that were not true.
| chowchowchow wrote:
| That's exactly right and what I said. The guy above said
| Trump is doing what he said he would. He isn't.
| sigzero wrote:
| Which doesn't mean Trump saying he has nothing to do with
| Project 2025 a lie.
| pstuart wrote:
| I've never been in the room, but it's a safe assumption
| that he was lying.
| ranger_danger wrote:
| _Someone_ is clearly pushing that agenda whether it 's
| (knowingly) Trump or not.
|
| Project 2025 is 42% complete, 3 months in.
|
| https://www.project2025.observer/
| SlightlyLeftPad wrote:
| People have got to learn how to read between the lines
| with Trump and those around him. When the things he says
| he is going to do and the things he's actually doing are
| exactly the things laid out in project 2025, the
| connection to the project is immediately clear and
| establishes that he was lying about knowing nothing about
| it.
| chowchowchow wrote:
| Obviously
| jmull wrote:
| Trump said he was _not_ going to follow the project 2025
| plan.
|
| So you're making two immediately contradictory claims
| that Trump is doing what he said he would, and is
| following the project 2025 plan. That's not coherent.
|
| You're suggesting a privatization plan exists, and want
| to debate its merits, but I see no sign such a plan is
| being adopted. E.g. who is enacting the plan? When is the
| comment period? Who do we send our feedback to? _You_ may
| have a plan, but what does that have to do with the
| people in charge? If it 's not their plan it doesn't
| matter one bit. Despite your assurances, I see no sign
| they aren't acting without a plan (or, as you put, as
| clueless idiots).
| acdha wrote:
| > Trump said he was not going to follow the project 2025
| plan.
|
| He didn't convincingly reject it, though, and his
| distancing was only convincing to people who were looking
| for an excuse to ignore it with the way he pretended not
| to know the people behind it when 31 of the 38 authors
| were members of his first administration, his campaign
| was in close contact throughout, and he certainly didn't
| put much effort into rejecting specific policy proposals.
|
| I think this is a case where different audiences got
| different messages. The hardcore base knew he was lying
| since it had all of their red meat issues, informed
| Democrats knew he was lying because actions speak louder
| than vague denials (e.g. if you don't agree with
| someone's policies, you wouldn't let them have a role in
| your campaign and you'd be able to say what you'd do
| differently), but he gave the media and casual voters
| just enough to make it harder for Biden/Harris to land
| attacks which we now know were fully accurate.
| jmull wrote:
| Yes, he was obviously lying, as he has done about so many
| things.
|
| Well, it's obvious to some us, anyway.
| danaris wrote:
| There seems to be a lot of hay being made over whether
| Trump is
|
| - deliberately following Project 2025 to the letter, or
|
| - completely ignorant of Project 2025 and not doing what
| it says
|
| ...when it seems _very_ likely that the truth is
| somewhere between.
|
| Trump himself is doing things the way he always does: in
| a mixture of long-standing bigotry and idiocy, his own
| whims, and whatever someone said to him 10 minutes ago
| (or he saw on Fox & Friends, or whatever).
|
| His _administration_ is heavily populated with people who
| either helped write Project 2025 or are close with those
| who did.
|
| DOGE is only loosely connected with the latter, and it's
| DOGE that has been instrumental in wrecking federal
| agencies--and while that destruction largely aligns with
| Project 2025's goals, it's not clear to me that they're
| _specifically_ following its playbook. Rather, I think
| they 're doing things their own way with high-level
| guidance from the people who care about Project 2025.
| It's very possible that their goals could end up
| conflicting, depending on what Musk wants.
|
| Edit to add: It's also true that Trump said he knew
| nothing about Project 2025. Whether or not this is true,
| he said it _during the campaign_ , when Project 2025 had
| just been widely reported on as a negative thing. I don't
| think we can read much into Trump's campaign statements
| intended to publicly distance himself from something he
| sees as unpopular.
| nrdvana wrote:
| In most of the video clips I saw, he was saying "I don't
| know anything about that", which could be entirely true.
| Often I see hints that he's attempting to play the Aes
| Sedai game of "speak no word that is untrue" but he's too
| dumb to do it well. Anyway, as an extension, both
| comments can be true, that Trump himself has no plan and
| is an idiot, but that his administration is enacting
| Project 2025.
| agloe_dreams wrote:
| > Having the CVE program operated by a company funded by the
| U.S. military
|
| ...Yep, we're done as a democracy. Pack it up, boys.
|
| Edit: I know it is doom and gloom but the CVE program could
| easily delay information and leave holes on purpose.
| absker wrote:
| MITRE is a non-profit company that operates Federally Funded
| Research and Development Centers (FFRDCs), which are owned
| and funded by the federal government and contracted out to
| companies like MITRE to operate them.
|
| While MITRE does have contracts with DoD (and many other
| agencies across the federal government as part of the FFRDCs
| they operate), they are not the same as a stereotypical DoD
| contractor as their non-profit status motivates them to work
| in the public interest.
| jhelps wrote:
| I can see how govt funding was needed to help bootstrap the
| CVE program before people saw the value of it.
|
| But now that CVEs form the basis of a very lucrative
| ~$16b/year industry[0], wouldn't it make sense to let those
| companies take over?
|
| Privatizing the Internet enabled much more innovation than if
| it had stayed govt-funded.
|
| 0: https://www.grandviewresearch.com/industry-
| analysis/security...
| butterlover wrote:
| It's probably more accurate to describe mitre as a publicly
| funded non profit operating for public benefit like the post
| office or PBS.
|
| It's a stretch to describe it as an arm of the government.
| lynndotpy wrote:
| This is good news, but in general. We can not rely on the DoD
| to make smart decisions.
|
| Ultimately, Pete Hegseth, with a career as a Fox News
| character, calls the shot.
| EgregiousCube wrote:
| A bit disingenuous; he also had a career as a soldier.
| lynndotpy wrote:
| Ok, and he is not someone you should rely on to make
| exclusively good decisions.
| bclemens wrote:
| Of course! It's easy to forget he was a guard at one of
| America's most notorious concentration camps, Guantanamo
| Bay. It's foolish to think of him only as a Fox News
| personality.
| typesarecool wrote:
| Not defending him as a person, but he earned a bronze
| star serving in Iraq.
| boston_clone wrote:
| Bronze stars without a V device are automatically awarded
| to O3s / O4s for a deployment. Knowing that, it sounds
| like you're defending him as a person.
| SV_BubbleTime wrote:
| If you are interested in facts, as a uniformed officer,
| Hegseth held a higher rank than anyone in Obama's
| cabinet.
| boston_clone wrote:
| can you image that? people will just go on the internet
| and _lie_?
|
| https://en.wikipedia.org/wiki/Eric_Shinseki
| KineticLensman wrote:
| There is a massive difference between having a career as a
| soldier and knowing how to lead one of the world's largest
| organisations (the DOD)
| plasma_beam wrote:
| This is DHS, not DOD.
| lynndotpy wrote:
| Yes, I was responding to someone who was talking about the
| DoD. Noem is likewise not someone I would depend on to make
| good decisions.
| plasma_beam wrote:
| It doesn't appear to have posted to FPDS yet:
| https://www.fpds.gov/ezsearch/fpdsportal?q=PIID%3A%2270RCSJ2...
|
| The contract expired today, but had an option period through
| March of 2026. DHS just needed to exercise the option.
|
| Edit: Note the contract ended today April 16 - so performance
| would stop midnight tonight if the option wasn't exercised.
| Government contracts routinely go down to the wire like this,
| and often are late getting exercised. Why the uproar over this
| one? Did CISA signal to MITRE that they weren't going to
| exercise the option?
| marcusb wrote:
| > Did CISA signal to MITRE that they weren't going to
| exercise the option?
|
| An internal letter sent to CVE board members was making the
| rounds yesterday warning the current contract ("contracting
| pathway") would expire. The letter was authenticated by Brian
| Krebs[0]. Once Krebs authenticated the letter, people more or
| less assumed CISA was pulling funding, at least based on the
| infosec social media posts I saw.
|
| CISA officials responded to multiple media inquiries
| (including the OP) with a statement that more directly said
| the contract _would expire_ : Although CISA's
| contract with the MITRE Corporation will lapse after April
| 16, we are urgently working to mitigate impact and to
| maintain CVE services on which global stakeholders rely.[1]
|
| 0 - https://krebsonsecurity.com/2025/04/funding-expires-for-
| key-...
|
| 1 - https://www.csoonline.com/article/3963190/cve-program-
| faces-...
| andreygrehov wrote:
| But the article says, quote:
|
| > It's unclear what led to DHS's decision to end the contract
| after 25 years
|
| and then suddenly it gets extended. What does it have to do
| with DOGE?
| marcusb wrote:
| MITRE has been hit with DOGE-branded cuts[0] earlier this
| month. CISA has been impacted[1]. It seems reasonable to
| assume they were involved in this.
|
| 0 - https://virginiabusiness.com/nova-govcon-firm-mitre-to-
| lay-o...
|
| 1 - https://techcrunch.com/2025/03/11/doge-axes-cisa-red-
| team-st...
| andreygrehov wrote:
| That's a pretty big leap. Ending a 25-year contract and
| laying off ~600 employees are two very different scales of
| impact. While DOGE-related cuts might have influenced some
| decisions, assuming they directly caused DHS to initially
| let the CVE contract lapse seems like a stretch. Just
| because two things happen near each other doesn't mean one
| caused the other - this feels more like another chance to
| take a swing at DOGE, since that's the bandwagon everyone's
| riding right now.
| hatly22 wrote:
| Maybe Europe should charge the US for access to their CVE
| databases.
| jovial_cavalier wrote:
| I didn't realize that CVE was funded by the DHS. Isn't it better
| for it to be independent and not funded by an intelligence
| agency?
|
| It's enough of a public good to have a common advisory for
| vulnerabilities that FAANG should just kick it a few million a
| year. How much can it possibly cost to run this anyway?
| trothamel wrote:
| Does anyone know what the CVE program was costing per year? I
| searched around a bit, but wasn't able to find the number.
| m4r71n wrote:
| The title of this article is simply false. The CVE Program is a
| separate entity from MITRE and is most definitely not ending. The
| CVE Program has been acquiring assets from MITRE for years now.
| That is why the main site shifted from cve.mitre.org to cve.org.
| MITRE has always simply been the workhorse of the program, and
| now that is being shifted to others (CVE foundation, which has
| global representation).
| gcollard- wrote:
| Forget everything you know and consider that it might be a
| misguided and risky negotiation tactic.
|
| Disclaimer: This is not business advice and should be read using
| Cartman's voice.
|
| Step 1: Announce publicly that you are not renewing your
| contract.
|
| Step 2: If the market has viable alternatives or the service you
| are negotiating isn't that hard to replicate, other actors will
| manifest to fill in the gaps, especially if your business is
| attractive. (E.g., The top comment is building an alternative;
| other comments point to alternative services.)
|
| Step 3: Congratulations, you now have leverage for a significant
| discount with your previous provider because they face the real
| prospect of losing your business entirely to a competitor. If the
| competitor is private, you can even double dip by investing in
| their company before attributing them the contract.
| Aperocky wrote:
| There's always a cost even if there doesn't seem to be one,
| credibility is measurable in markets and when it bite I think
| we'll all be in rough times.
| ThinkBeat wrote:
| There seems to be little reason for the US government to pay for
| this since it is vital information that a lot of companies rely
| upon.
|
| Some form of a foundation or NGO could be given a reasonable
| endowment from the industry to operate the CVE program.
|
| O am quite hesitant to trust the DOD to keep track of software
| vulnerabilities. Some parts are developing and exploiting
| vulnerabilities. And given a fresh feed of what people find, and
| usually a delay from notification until publication, which may
| sometimes just be a bit longer of a delay, would allow the DOD to
| weaponize the vulnerability for their own use as well.
| froggertoaster wrote:
| Believe me when I say that DOGE is filled with smart people (I
| know a few of them).
|
| Just because they're scattershot cutting doesn't mean they're
| stupid.
| raegis wrote:
| I guess I'm naive, but given the current situation, wouldn't a
| smart person resign from DOGE? If I were smart and highly
| employable, like these guys, I would not want to be associated
| with all the indiscriminate firings of DOGE.
| froggertoaster wrote:
| I guess it depends on what you value.
|
| I think it speaks a lot about a person who assumes "a smart
| person would resign from DOGE".
| p0w3n3d wrote:
| One man appears at one position and so many things stop working
| in so little time
| Alifatisk wrote:
| Yet, he is still praised and cherished. I can't comprehend how.
| RKFADU_UOFCCLEL wrote:
| Including this as a prime example, the overall trend seems to be
| that we're going back to the bad old days where a kid gets to
| code the entire security infrastructure because the CEO thinks
| he's smart and then the bugs are covered up with legal threats
| (because they were able to mislead the courts), obfuscation,
| while being easily discoverable by 3rd parties. Another example
| is the way the bug bounty gimmick is run and most researchers
| never disclose their findings nor are they patched in any
| consistent manner, plus the companies threaten to sue you for
| disclosing even if it's 100 years later.
| blindriver wrote:
| How much does CVE cost to maintain and why must the US fund the
| entire thing?
| manmal wrote:
| The bureaucracy of internationalizing it would likely be more
| expensive than the current cost.
| andrehacker wrote:
| Maybe change the headline now ? As-is the headline is click-
| baity. (spoiler alert: the contract has been extended)
| rbolla wrote:
| Important update April 16, 2025: Since this story was first
| published, CISA signed a contract extension that averts a
| shutdown of the MITRE CVE program.
___________________________________________________________________
(page generated 2025-04-16 17:01 UTC)