RIP Cert.org
riskbasedsecurity.com
riskbasedsecurity.com
I'm sure good people work there now, and they'll be fine. If all of CERT's public web presence goes away, I won't miss them.
VMU has been heavily involved in quite a bit of what has become mainstream in federal government InfoSec. They were the ones who built out US-CERT originally, they have had a hand in helping set up many of the CSIRT/SOC operations within the federal government, and they continue to play a role in helping train/evaluate these teams. Although I suspect that many people outside of (gov) InfoSec are aware of this history.
The only thing that merged was www.cert.org got pulled into the broader www.sei.cmu.edu web site.
(I work there.)
It's unclear if the vulnerability database will continue to function in the long term but so far it survives, it's just the website that's redirecting.
In the article, it says CERT.org costs $1.8B/y. How is that possible? That sounds bogus to me -- the article doesn't link to the full FOIA response, so it's hard to fact-check. The 2008 budget apparently earmarked $242M for CERT <http://www.zdnet.com/article/federal-budget-recommends-us-ce.... Anyone have more links to factcheck this statement?
It still seems like a huge amount of money, but at least it's plausible. Research grants, things like that I assume.
Also the funding model isn't quite that straightforward. As an FFRDC they receive a certain static amount every year (in the low millions) as some kind of federal grant. Everything else is income from customer work like you'd find at any other contractor. In terms of revenue, most of the big bucks probably come from DoD and not DHS.
Seems like not many people from the FFRDC community read or post on HN.
https://ncsesdata.nsf.gov/datatables/ffrdcrd/2016/html/FFRDC...
Exactly what benefit does "but blockchain!" bring?
What’s in danger is the work required to coordinate such efforts in the future, and rubbing blockchain on it doesn’t help.
(I know you weren’t advocating it, I just get tired of people who don’t understand the amount of effort that goes into “free” content.)