200
submitted 3 months ago* (last edited 3 months ago) by zaxvenz@lemm.ee to c/technology@lemmy.world

The government will continue funding the Common Vulnerabilities and Exposures (CVE) program. In a statement to The Verge, US Cybersecurity and Infrastructure Agency (CISA) spokesperson Jared Auchey said it “executed the option period on the contract to ensure there will be no lapse in critical CVE services” last night.

https://archive.ph/V7zF4

top 15 comments
sorted by: hot top controversial new old
[-] Rooskie91@discuss.online 69 points 3 months ago
[-] pdxfed@lemmy.world 19 points 3 months ago

Clown shows can be funny. This is like watching pallbearers drop caskets at a children's hospital funeral.

[-] cellardoor@lemmy.world 37 points 3 months ago* (last edited 3 months ago)

Too little too late. The CVE Foundation is now a thing. Link

[-] db2@lemmy.world 6 points 3 months ago* (last edited 3 months ago)

I hope they don't drop it now.

autocorrect is so worthless now

[-] gibmiser@lemmy.world 30 points 3 months ago

I guess they'd rather have control than let it become nonprofit

[-] withabeard@lemmy.world 27 points 3 months ago

At this point ... what stops the CVE foundation moving on as a foundation and working to find an alternative funding model?

[-] Maestro@fedia.io 27 points 3 months ago

Nothing. They should do exactly that. As usual the US government has proven that it cannot be trusted or relied on.

[-] vermaterc@lemmy.ml 3 points 3 months ago

So... the US government doesn't have to fund it anymore? So that is an advantage for them in this situation, what is the disadvantage? Or was that their goal all along?

[-] taladar@sh.itjust.works 7 points 2 months ago

Usually the goal when funding stuff like this is to buy some influence to control major decisions. I wouldn't put it beyond an independent foundation, to take just one example, to drastically reduce the deadlines between confidential disclosure and public release where some government or corporate controlled organization might set some that are more made for the slow speed of large org bureaucracy.

[-] kubica@fedia.io 25 points 3 months ago

I hope the alternative new foundation comes on top.

Edit: I found a link with more info. https://www.heise.de/en/news/After-the-impending-CVE-ban-EU-vulnerability-database-goes-live-10354564.html

[-] salacious_coaster@infosec.pub 24 points 3 months ago

They're scream testing the whole government, one piece at a time.

[-] Gerudo@lemm.ee 13 points 3 months ago

I can't keep going to the doctor with all this whiplash.

[-] henfredemars@infosec.pub 10 points 3 months ago
[-] Warl0k3@lemmy.world 7 points 3 months ago* (last edited 3 months ago)

I know it's the whole point of them doing this shit but it's getting so hard to cope with the constant fucking around. What in the fuck are we going to do? At least for now they've realized how spectacularly stupid this move was, I guess.

[-] twinnie@feddit.uk 1 points 3 months ago

There’s already alternatives, why not just let them take over? Trump complained about the US giving up DNS, now he’s complaining about CVE. He wants to control everything but doesn’t want to pay for it.

this post was submitted on 16 Apr 2025
200 points (99.0% liked)

Technology

72790 readers
1064 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS