The government will continue funding the Common Vulnerabilities and Exposures (CVE) program. In a statement to The Verge, US Cybersecurity and Infrastructure Agency (CISA) spokesperson Jared Auchey said it “executed the option period on the contract to ensure there will be no lapse in critical CVE services” last night.

https://archive.ph/V7zF4

    • pdxfed@lemmy.world
      link
      fedilink
      English
      arrow-up
      30
      arrow-down
      1
      ·
      3 days ago

      Clown shows can be funny. This is like watching pallbearers drop caskets at a children’s hospital funeral.

    • db2@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      ·
      edit-2
      3 days ago

      I hope they don’t drop it now.

      autocorrect is so worthless now

  • withabeard@lemmy.world
    link
    fedilink
    English
    arrow-up
    36
    ·
    3 days ago

    At this point … what stops the CVE foundation moving on as a foundation and working to find an alternative funding model?

    • Maestro@fedia.io
      link
      fedilink
      arrow-up
      38
      ·
      3 days ago

      Nothing. They should do exactly that. As usual the US government has proven that it cannot be trusted or relied on.

      • vermaterc@lemmy.ml
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        1
        ·
        3 days ago

        So… the US government doesn’t have to fund it anymore? So that is an advantage for them in this situation, what is the disadvantage? Or was that their goal all along?

        • taladar@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          17
          ·
          3 days ago

          Usually the goal when funding stuff like this is to buy some influence to control major decisions. I wouldn’t put it beyond an independent foundation, to take just one example, to drastically reduce the deadlines between confidential disclosure and public release where some government or corporate controlled organization might set some that are more made for the slow speed of large org bureaucracy.

  • Warl0k3@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    ·
    edit-2
    3 days ago

    I know it’s the whole point of them doing this shit but it’s getting so hard to cope with the constant fucking around. What in the fuck are we going to do? At least for now they’ve realized how spectacularly stupid this move was, I guess.

  • twinnie@feddit.uk
    link
    fedilink
    English
    arrow-up
    5
    ·
    3 days ago

    There’s already alternatives, why not just let them take over? Trump complained about the US giving up DNS, now he’s complaining about CVE. He wants to control everything but doesn’t want to pay for it.