Hacker News new | ask | show | jobs
by tylermw 427 days ago
MITRE is a Federally Funded Research and Development Center (FFRDC), which is a distinct type of federal contractor with strict conflict of interest regulations. They are owned by the federal government, but operated by contractors and are specifically structured and regulated to minimize conflicts of interest, so are distinct from "private industry" in many regards.

You can read a congressional report by the CRS describing FFRDCs and their role here: https://www.congress.gov/crs-product/R44629.

2 comments

MITRE is absolutely not an FFRDC. It's a regular old 501(c)(3) which happens to manage FFRDCs.
Yes, you are correct, I should have typed "runs". But the point is that MITRE runs the U.S. National Cybersecurity FFRDC that maintains the CVE system, and FFRDCs are deliberately structured to minimize potential conflicts of interest (GP comment) and are definitely distinct from private industry (parent comment).
They were talking about AFTER that when it is privatized. That's what the comment they're responding to was talking about, not it's current state.