Trump defunded the CVE program, the global de facto standard for software vulnerability tracking

mikeymikec

Lifer
May 19, 2011
19,943
14,214
136

brycejones

Lifer
Oct 18, 2005
29,050
29,159
136
so was this waste, fraud, or abuse?

Right now while the orange monkey distracts everyone Voight and his minions are breaking as much shit as they can.
 

hal2kilo

Lifer
Feb 24, 2009
25,384
11,787
136


The mind boggles.
Let's throw away all of the locks, build a wall that has no real purpose, and make friends with our enemies. Traitor in the WH.
 

UNCjigga

Lifer
Dec 12, 2000
25,252
9,725
136
Just playing devil’s advocate here—but this program is pretty well established and I assume ISVs (especially MS, Facebook, Google, Amazon, Apple etc.) are more than capable of funding the program as an ongoing concern. Will this really change anything?
 

mikeymikec

Lifer
May 19, 2011
19,943
14,214
136
Just playing devil’s advocate here—but this program is pretty well established and I assume ISVs (especially MS, Facebook, Google, Amazon, Apple etc.) are more than capable of funding the program as an ongoing concern. Will this really change anything?
I would want tech vulnerability tracking managed by an impartial body, rather than a company deciding to move the goalposts, play revisionism games, or deprioritize requests from competitors in a way that it considers to be personally beneficial, which is almost never beneficial to anyone else. Furthermore, most software companies believe that information transparency and security are mutually exclusive elements, which goes against the very core of an open vulnerability reporting system.

Government backing (normally, GQP bizarroverse aside) adds stability, the body doesn't have to worry about funding.
 
Jun 18, 2000
11,191
765
126
Just playing devil’s advocate here—but this program is pretty well established and I assume ISVs (especially MS, Facebook, Google, Amazon, Apple etc.) are more than capable of funding the program as an ongoing concern. Will this really change anything?

Does it make sense to have software companies control the purse strings of an organization tasked with finding and reporting CVEs in those company's software?
 
Reactions: KompuKare

UNCjigga

Lifer
Dec 12, 2000
25,252
9,725
136
Does it make sense to have software companies control the purse strings of an organization tasked with finding and reporting CVEs in those company's software?
An individual company, no—but as a collective, there are tons of industry consortia that set standards for everything and are not truly regulated. I just thought this would be one instance where government funding/control isn’t necessary.

Sounds like that’s what’s happening in this case—https://www.thecvefoundation.org/home

I agree this was a ham-handed way to abruptly cancel funding without adequate warning, a public comment period, or contingency plans to properly transition to an independent foundation.
 

manly

Lifer
Jan 25, 2000
12,869
3,644
136
An individual company, no—but as a collective, there are tons of industry consortia that set standards for everything and are not truly regulated. I just thought this would be one instance where government funding/control isn’t necessary.

Sounds like that’s what’s happening in this case—https://www.thecvefoundation.org/home

I agree this was a ham-handed way to abruptly cancel funding without adequate warning, a public comment period, or contingency plans to properly transition to an independent foundation.
You're right that they could easily pivot away from the status quo (didn't the feds already reverse this inane decision?). Even so, they won't drop the announced plans for a CVE Foundation. Trump admin is totally untrustworthy and incompetent. In the scope of the federal budget, this program doesn't even amount to bread crumbs. It's probably equivalent to the money they'll spend on a powder room for Pete Hegseth.

In semi-related news, didn't an important DoD cybersecurity group resign en masse?

Daddy Vladdy must be so proud of his lapdog Trump and we're not even 100 days in yet.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |