• vortic@lemmy.world
    link
    fedilink
    English
    arrow-up
    55
    ·
    edit-2
    10 hours ago

    What an astoundingly stupid idea. I can’t think of many programs that deliver more value per dollar for everyone who develops or uses technology than the CVE program. This administration keeps raising the bar for stupidity.

    • taladar@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      14
      arrow-down
      1
      ·
      5 hours ago

      But CVE hurts Trump’s people, the scam artists and spammers and of course his buddies in Russia.

    • Brownboy13@lemmy.world
      link
      fedilink
      English
      arrow-up
      36
      arrow-down
      1
      ·
      9 hours ago

      DOGE tech bros 100% know what it is. But they’re also probably the kind of devs that hate fixing issues surfaced by CVE’s in dependencies. Have seen my fair share of these types of ‘engineers’. Same kind of folks who see qa and testing as the enemy.

      • Jiggle_Physics@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 hours ago

        I was more implying that if this blows up in the their face, the public statement will be it was a mistake, made from ignorance, to evade responsibility. Sorry if that didn’t come off clearly. Making sure implication gets across online sucks.

      • jonne@infosec.pub
        link
        fedilink
        English
        arrow-up
        14
        arrow-down
        1
        ·
        7 hours ago

        They’re script kiddies, they use CVE to figure out which hacking scripts to use to break into servers that haven’t been updated in years.

        • chingadera@lemmy.world
          link
          fedilink
          English
          arrow-up
          6
          arrow-down
          2
          ·
          6 hours ago

          I don’t think they’re this savvy, this is likely just another one of Putin’s orders.

  • Boomkop3@reddthat.com
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    2
    ·
    9 hours ago

    This is an oddly close timing with 4chan getting hacked and leaking a bunch of user and mod accounts with .gov emails in them

  • rpl6475@lemmy.ml
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    1
    ·
    7 hours ago

    Can the EU ‘buy’ Mitre and continue the programme in Europe away from Russo-American hands?

    • signalsayge@lemm.ee
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 hour ago

      No. MITRE is a federally funded research and development center (FFRDC). The only customer it’s allowed to have is the US government.

      • ricecake@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        29 minutes ago

        One of the benefits of it being such a widely used system is that we don’t need to make a special effort to do so. It’s already been aggregated and copied around as part of routine optimization by any number of security conscious engineers who aren’t trying to make the world a worse place.

        I’ve personally worked on at least three systems at two employers where making an automated copy of the data regularly was just an early optimization and matter of etiquette.

        It’s a good opportunity to learn how to do it though! You have or can get all the tools you need on your computer.