Hi, Shrewd!        Login  
Shrewd'm.com 
A merry & shrewd investing community
Best Of MacroBest OfAll BoardsThe Shrewd’m WeeklyLearn to InvestHow to Become Shrewd
Search
Shrewd'm.com Merry shrewd investors
Search
Best Of MacroBest OfAll BoardsThe Shrewd’m WeeklyLearn to InvestHow to Become Shrewd


The week's question
In December 2024, in the thread "Re: BRK: Why Not XOM?", BreckHutHigh asked the members: "What about the long road trips with kids?" This week it is put to everyone again. The button below opens the small thread re-asking it - read what others have said so far, then give your own answer as an ordinary reply.
Answer this questionContinue to Shrewd'mThis note won't appear again
Personal Finance / Macroeconomic Trends & Risks
Unthreaded | Threaded | Whole Thread (3) |
Author: ajm101   😊 😞
Number: of 4460 
Subject: US turning off CVE program?
Date: 04/15/25 10:13 PM
Post New | Post Reply | Report Post | Recommend It!
No. of Recommendations: 9
I didn't expect to post again today, and if I had I wouldn't have suspected it would have been a second post on information security.

But astonishingly it just broke that the US government is ending funding of the Common Vulnerabilities and Exposures program, or CVE as most people in the field refer to it.

theregister.com - Homeland security funding for cve has details. To excerpt

"While the whole world's vulnerability management efforts aren't going to descend into chaos overnight, there is a concern that in a month or two they may. The lack of US government funding means that, unless someone else steps in to fill the gap, this standardized system for naming and tracking vulnerabilities may falter or shut down, new CVEs may no longer be published, and the program's website may go offline.

Not-for-profit outfit MITRE has a contract with the US Department of Homeland Security to operate the CVE program, and on Tuesday the group confirmed this arrangement has not been renewed. This comes as the Trump administration scours around the federal government for costs to trim."


If anyone remembers the Heartbleed exploit, it was also technically referred to as CVE-2014-0160, which was the id in the programs database. This is a cornerstone of the security community. Everyone will be less secure for this if funding cannot be found.

Maybe private industry will step up and collectively fund this, but it benefited the US and is another shocking example of the shortsightedness - at best - of this administration.

I thought I'd planned around some bad outcomes and I was nowhere near pessimistic enough.
Post New | Post Reply | Report Post | Recommend It!
Print the post
Members reply directly to ajm101 here — and replies get answered. Reading is free; so is joining the conversation. Join Shrewd'm »
This community has written 4,454 posts about Macroeconomic Trends & Risks. The article-length ones it recommended most:
AI Tarpits · 36 recs · 2026
End of an era - profit slowdown · 36 recs · 2023
Control Panel: Trend changes in 2026 · 34 recs · 2026
From the Oregon Bay Area (a blogger) · 33 recs · 2025
Lerner Symmetry Theorem · 32 recs · 2025
Unthreaded | Threaded | Whole Thread (3) |


Announcements
Macroeconomic Trends & Risks FAQ
Contact Shrewd'm
Contact the developer of these message boards.

Best Of Macro | Best Of | Favourites & Replies | All Boards | Followed Shrewds | Open Questions | Moving a community