Hi, Shrewd!        Login  
Shrewd'm.com 
A merry & shrewd investing community
Best Of Macro | Best Of | Favourites & Replies | All Boards | Post of the Week!
Search Macro
Shrewd'm.com Merry shrewd investors
Best Of Macro | Best Of | Favourites & Replies | All Boards | Post of the Week!
Search Macro


Personal Finance Topics / Macroeconomic Trends and Risks
Unthreaded | Threaded | Whole Thread (3) |
Post New
Author: ajm101   😊 😞
Number: of 1020 
Subject: US turning off CVE program?
Date: 04/15/2025 10:13 PM
Post Reply | Report Post | Recommend It!
No. of Recommendations: 9
I didn't expect to post again today, and if I had I wouldn't have suspected it would have been a second post on information security.

But astonishingly it just broke that the US government is ending funding of the Common Vulnerabilities and Exposures program, or CVE as most people in the field refer to it.

https://www.theregister.com/2025/04/16/homeland_se... has details. To excerpt

"While the whole world's vulnerability management efforts aren't going to descend into chaos overnight, there is a concern that in a month or two they may. The lack of US government funding means that, unless someone else steps in to fill the gap, this standardized system for naming and tracking vulnerabilities may falter or shut down, new CVEs may no longer be published, and the program's website may go offline.

Not-for-profit outfit MITRE has a contract with the US Department of Homeland Security to operate the CVE program, and on Tuesday the group confirmed this arrangement has not been renewed. This comes as the Trump administration scours around the federal government for costs to trim."


If anyone remembers the Heartbleed exploit, it was also technically referred to as CVE-2014-0160, which was the id in the programs database. This is a cornerstone of the security community. Everyone will be less secure for this if funding cannot be found.

Maybe private industry will step up and collectively fund this, but it benefited the US and is another shocking example of the shortsightedness - at best - of this administration.

I thought I'd planned around some bad outcomes and I was nowhere near pessimistic enough.
Print the post


Author: jerryab   😊 😞
Number: of 1020 
Subject: Re: US turning off CVE program?
Date: 04/15/2025 10:29 PM
Post Reply | Report Post | Recommend It!
No. of Recommendations: 2
Give it a bit of time (1 day to two weeks) and the White House will be hacked--over and over again. Where was DOGEboy? Cutting security costs.... Make HIM pay.
Print the post


Author: weatherman   😊 😞
Number: of 1020 
Subject: Re: US turning off CVE program?
Date: 04/16/2025 9:35 AM
Post Reply | Report Post | Recommend It!
No. of Recommendations: 1
yep. MAGA is tired of american citizens freeloading on federal protection against foreign state-sponsored cybercrime.
we should all be spending 10% of our AGI on personal cybersecurity efforts for the privilege of being online.

given MAGA support of crypto, there can be no clearer message.
global B2B cybercrime will be growing exponentially, and picking off individuals will be a bonus.

Print the post


Post New
Unthreaded | Threaded | Whole Thread (3) |


Announcements
Macroeconomic Trends and Risks FAQ
Contact Shrewd'm
Contact the developer of these message boards.

Best Of Macro | Best Of | Favourites & Replies | All Boards | Followed Shrewds