TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

House passes bill that DoD software can’t have any CVEs

19 pointsby andreialmost 3 years ago

7 comments

ytpetealmost 3 years ago
It looks like the policy isn&#x27;t as rigid as this tweet suggests – the next couple bullets in the bill appear to say you <i>can</i> have known vulnerabilities so long as they&#x27;re explicitly disclosed and have a mitigation plan. The full text is at <a href="https:&#x2F;&#x2F;www.congress.gov&#x2F;bill&#x2F;117th-congress&#x2F;house-bill&#x2F;7900&#x2F;text" rel="nofollow">https:&#x2F;&#x2F;www.congress.gov&#x2F;bill&#x2F;117th-congress&#x2F;house-bill&#x2F;7900...</a>, heading &quot;SEC. 6722. DHS SOFTWARE SUPPLY CHAIN RISK MANAGEMENT.&quot;<p>The wording is left a little ambiguous though since there&#x27;s no &quot;and&quot;s &amp; &quot;or&quot;s to join those bullets (1)-(3). I&#x27;ve never understood why they can&#x27;t use more standardized boilerplate in legal text for and&#x2F;or&#x2F;xor logical clauses, to eliminate that kind of issue.<p>For that matter, I also don&#x27;t get why this official congress.gov site can&#x27;t manage to support basic anchor links! Or even better yet, links that automatically resolve references like &quot;subsections (b)(1)&quot; in the text of the bill...
elmerfudalmost 3 years ago
Just what I thought security policies and standards couldn&#x27;t get any worse now we have Congress trying to dictate what a secure is.
thesuperbigfrogalmost 3 years ago
Time to buy slide rules.
water8almost 3 years ago
House should pass bill that congress can&#x27;t have any equities
Ekarosalmost 3 years ago
Now, I wonder what about the vulnerabilities that NSA knows, or have introduced. Then again those are only known to them. So it is probably fine.
pannyalmost 3 years ago
Big tech lobbyists will kill it in the Senate. What they should have done is make it so &quot;no warranties&#x2F;liablity&quot; in software licenses don&#x27;t apply to damages caused by known CVEs. Then everyone is protected, not just DoD.
评论 #32505156 未加载
jeanloualmost 3 years ago
Am I the only one to wonder what CVEs are?
评论 #32506415 未加载