Hacker News new | past | comments | ask | show | jobs | submit
OP suggests something at NIST changed in 2024, where they stopped doing as much verification as they did before.

To be sure, the suggestion is not funding cuts, but an increase in workload with same funding.

Here is the 2024 NIST announcement OP links to: https://nvd.nist.gov/general/news/nvd-program-transition-ann...

> Currently, we are prioritizing analysis of the most significant vulnerabilities. In addition, we are working with our agency partners to bring on more support for analyzing vulnerabilities and have reassigned additional NIST staff to this task as well.

The OP described this as "NIST effectively hit pause on deep analysis. "

It does sound like they stopped doing something they used to do in 2024. I personally have definitely not spent a lot of time directly interfaced with NIST on cybersecurity in decades past, I know nothing about it, just what I read in OP.

Are you saying the OP was wrong to call what NIST used to do "deep analysis", and/or that the thing NIST stopped doing was "purely ministerial/clerical" in a way that it would not have caught fake reports anyway, contradicting the OP? Or other?

Again, to be sure, the OP's suggestion was not that this was caused by NIST funding cuts, but by "a massive surge in vulnerability reports,"

The main point is NIST is _downstream_ of CVE issuance. Yes, they can — and still do — add disputed/rejected tags to CVEs, but in many cases by then it's already "too late." The CVE has an ID and a lifespan of its own.

NIST does not and did-not/cannot/never-has unilaterally "retracted" CVEs or prevented their issuance.

But yes, NIST's situation is not good for the world. The services they provide are hugely valuable.

loading story #49160551