NVD project funding at US NIST
NVD project funding at US NIST
Posted Nov 12, 2024 14:19 UTC (Tue) by raven667 (subscriber, #5198)Parent article: The top open-source security events in 2024
A rhetorical question, but how is it possible that a government service relied upon by many commercial vendors just stops working an no one can get an official response as to why, or even an unofficial one? That seems like a lot of risk in the supply chain for security tools that use this data, is no one paying attention to ensure that the agency has funding and a legal mandate to continue this work. In theory we all pay taxes so we should be able to fund shared services like NVD without too much trouble, but failing that some of the companies which rely on it should fund some lobbyists to bribe officials so they prioritize this service, or they to fund a vendor consortium where security companies pool their efforts to fund a central non-profit which provides enrichment data to them all?
