US abruptly turns off funding for CVE program (www.theregister.com)
from floofloof@lemmy.ca to cybersecurity@sh.itjust.works on 16 Apr 02:29
https://lemmy.ca/post/42370753

cross-posted from: lemmy.bestiver.se/post/328810

Comments

#cybersecurity

threaded - newest

atzanteol@sh.itjust.works on 16 Apr 02:49 next collapse

Trump was so right - I’m very sick of “winning”.

dohpaz42@lemmy.world on 16 Apr 03:02 next collapse

Goddamnit.

IllNess@infosec.pub on 16 Apr 03:22 next collapse

All part of the plan to let Russian hackers take whatever they want.

Telorand@reddthat.com on 16 Apr 05:23 collapse

China: Don’t mind if I do!

Jiggle_Physics@sh.itjust.works on 16 Apr 03:22 next collapse

Let me guess, DOGE bros didn’t know what it was?

Brownboy13@lemmy.world on 16 Apr 04:09 next collapse

DOGE tech bros 100% know what it is. But they’re also probably the kind of devs that hate fixing issues surfaced by CVE’s in dependencies. Have seen my fair share of these types of ‘engineers’. Same kind of folks who see qa and testing as the enemy.

jonne@infosec.pub on 16 Apr 06:00 next collapse

They’re script kiddies, they use CVE to figure out which hacking scripts to use to break into servers that haven’t been updated in years.

whostosay@lemmy.world on 16 Apr 07:02 next collapse

I don’t think they’re this savvy, this is likely just another one of Putin’s orders.

weirdboy@lemm.ee on 18 Apr 02:14 collapse

If that were the case, they’d want to keep it going.

Jiggle_Physics@sh.itjust.works on 16 Apr 11:17 next collapse

I was more implying that if this blows up in the their face, the public statement will be it was a mistake, made from ignorance, to evade responsibility. Sorry if that didn’t come off clearly. Making sure implication gets across online sucks.

expr@programming.dev on 16 Apr 12:19 collapse

I’m honestly not so sure, they are really clueless when it comes to technology.

Waldo82@sh.itjust.works on 16 Apr 19:50 collapse

They absolutely know, they want to avoid the accountability of acknowledging and fixing vulnerabilities, which is why they’re trying to kill CVE.

Photuris@lemmy.ml on 16 Apr 03:23 next collapse

This is awful.

Vorticity@lemmy.world on 16 Apr 03:26 next collapse

What an astoundingly stupid idea. I can’t think of many programs that deliver more value per dollar for everyone who develops or uses technology than the CVE program. This administration keeps raising the bar for stupidity.

taladar@sh.itjust.works on 16 Apr 08:05 collapse

But CVE hurts Trump’s people, the scam artists and spammers and of course his buddies in Russia.

Semi_Hemi_Demigod@lemmy.world on 16 Apr 04:08 next collapse

“Stupid face, you don’t need that nose!” - America

Boomkop3@reddthat.com on 16 Apr 04:14 next collapse

This is an oddly close timing with 4chan getting hacked and leaking a bunch of user and mod accounts with .gov emails in them

rpl6475@lemmy.ml on 16 Apr 06:01 next collapse

Can the EU ‘buy’ Mitre and continue the programme in Europe away from Russo-American hands?

whostosay@lemmy.world on 16 Apr 07:02 next collapse

The site needs to be scraped asap, and a clone needs to happen asap.

ricecake@sh.itjust.works on 16 Apr 13:00 collapse

One of the benefits of it being such a widely used system is that we don’t need to make a special effort to do so. It’s already been aggregated and copied around as part of routine optimization by any number of security conscious engineers who aren’t trying to make the world a worse place.

I’ve personally worked on at least three systems at two employers where making an automated copy of the data regularly was just an early optimization and matter of etiquette.

It’s a good opportunity to learn how to do it though! You have or can get all the tools you need on your computer.

signalsayge@lemm.ee on 16 Apr 12:17 collapse

No. MITRE is a federally funded research and development center (FFRDC). The only customer it’s allowed to have is the US government.

rpl6475@lemmy.ml on 16 Apr 16:25 collapse

Fair enough. They should scrape all data, and fork a new version then.

Tiger@sh.itjust.works on 16 Apr 08:26 next collapse

This is one of the worst acts of DOGE, fucking assholes.

exposable_preview@slrpnk.net on 16 Apr 10:49 next collapse

they have actually prepared for this

www.thecvefoundation.org

recursive_recursion@lemmy.ca on 18 Apr 01:57 collapse

Thanks for sharing!🤗

pineapplelover@lemm.ee on 18 Apr 02:09 next collapse

What’s more free than exposing all your vulnerabilities?

MURICAAAAAA baby

starkzarn@infosec.pub on 18 Apr 02:52 collapse

No one has mentioned anything about how CISA – as gutted as they are – has stepped up to ensure funding for the next 11 months. CVEs aren’t going anywhere.