logoalt Hacker News

jrochkind1today at 4:39 PM2 repliesview on HN

The federal government ought to be funding NIST sufficiently to actually do sufficient analysis. Do we care about funding civil "cyber" defense or not?

(Obviously the answer is not, we only care about funding offensive capabiltiies).


Replies

Plutoberthtoday at 5:38 PM

This is obviously impractical. With the volume of bug reports that are generated and such a wide breadth of software no single agency will be able to handle all reports. And honestly? It doesn't matter, even today. CVE should serve as a reasonably deduped identifier of specific vulnerabilities. It was never interesting and practical to care about 100% of vulnerabilities in a specific deployment, and it's not interesting today.

inigyoutoday at 4:54 PM

The federal government defunded the CVE program last year, I think, because it was woke.