Tag: FOIA
-
How Much Lipstick Can That CVE Pig Wear?

Preface When I started writing this, I was still on the CVE editorial board, which I was removed from in 2018. That means I have been taking notes and working on this blog for over eight years. It’s a case of more and more evidence piling up and me not having time to pick a…
-
NSA, Theft, and the Original Quantum Lazlo

Back in November, 2009, Attrition.org staff (including me) finally got around to finalizing the name for our new mascot (archive.org), the angry squirrel firmly associated with Attrition and myself. In a cheeky letter from the mascot, it was signed ‘Lazlo’. Since that date, the mascot has seen a wide variety of iterations as Lazlo was…
-
CISA Weekly Bulletins FOIA Results

Did you know that CISA publishes a weekly bulletin of “new vulnerabilities”, and has for a long time? They tend to have anywhere from 350 up to almost 1,000 vulnerabilities depending on the volume of CVEs published. The bulletins are entirely based on CVE IDs being published, not when the disclosures happened (just like CVE…
-
2024 NIST / ANALYGENCE FOIA Results

On June 5, 2024, I sent a FOIA request to National Institute of Standards and Technology requesting a copy of the contract between the National Vulnerability Database (NVD) and ANALYGENCE, a contractor that had been retained to help with the NVD backlog. This was one of two trying to determine how much the U.S. Government…
-
DHS & Your Tax Dollars
[This was originally published on the OSVDB blog.] Full Article Through its Science and Technology Directorate, the department has given $1.24 million in funding to Stanford University, Coverity and Symantec to hunt for security bugs in open-source software and to improve Coverity’s commercial tool for source code analysis, representatives for the three grant recipients told…
-
2005 CVE Program FOIA Results

I submitted a Freedom of Information Act (FOIA) request to the Department of Homeland Security (DHS) on February 8, 2005, asking for funding information for the Common Vulnerability Enumeration (CVE) program run by MITRE. I eventually received a lengthy document that had the information I had requested, and a lot more. My FOIA request: I…