Listen

Listened to Open Source Security Podcast: Episode 438 - CISA's bad OSS advice vs the Whitehouse good advice
Post details
and talk about two documents from the US government that discuss open source in very different ways. The CISA document lays out a way to measure open source, but we take issue with the idea of trying to measure which open source projects are "good". The Whitehouse on the other hand takes an approach that is very open source, get involved. Trying to measure open source isn't producing anything actionable, but getting involved is very actionable, and very much how open source works. Show Notes

 Repost

Reposted raganwald 🍓 (@raganwald@social.bau-ha.us)
Post details
I used to just block ads and leave it up to others to handle the Digital Panopticon. But now I ask myself, “Why am I giving these people oxygen? If they feel their creativity is best presented with a popup that is surrounded by a blur to force you to interact with it, and then when you make it go away there are header and footer ads, and every two paragraphs there is an ad… I can take a moment and find a different page.” I no longer link to pages that are ads interrupted with content. 🚫

 Like

Liked StillIRise1963 (@StillIRise1963@mastodon.world)
Post details
Just texted with my super pessimistic kid who now actually has hope for the future. They said young people are “extremely animated” and that there would be "massive turnout if the momentum keeps up." They said they had great hopes for down ballot candidates. The other twin said he’d never been politically optimistic in his adulthood before. They’re 29.

 Like

Liked Terence Eden (@Edent@mastodon.social)
Post details
A decade ago, I successfully lobbied the UK Government to adopt an Open Standard. https://shkspr.mobi/blog/2014/07/how-i-got-the-uk-government-to-adopt-odf/ That then accidentally kicked off a new career for me as I became a dedicated standards policy wonk. I wonder what the next decade will bring?

 Like

Liked Tane Piper (@tanepiper@tane.codes)
Post details
I have a theory that for the last 10 years #faang companies who prefer Code Golf solutions in job interviews means they only end up hiring people who learned to beat the interview, and not actually have software engineering or critical thinking ability. At the same time the need for infinite growth, which is the only basic model SV understands, had driven profits over being a good landlord on the web. https://toot.cafe/@slightlyoff/112833989608905813

 Repost

Reposted Martin Seeger (@masek@infosec.exchange)
Post details
**Concerning CrowdStrike:** We are now at t+26h. Please compare how much we knew about the xz-attack after less than a day with what we know about the chain of events of giant outage yesterday. If something similar had been caused by an OSS component, we would see congress discussing a ban on open software in critical infrastructure already.

 Note

Strong dislike that #Linkedin's native Web view no longer allows you to copy the URL, or open it in other browsers, and generally making it very hostile to folks who want to ie share the link with someone else, or move it to a read-it-later app

 Repost

Reposted OpenUK (@openuk@hachyderm.io)
Post details
Attached: 1 image In 6 months to 30 April number of people whos code was accepted into open source projects (committers) from the UK increase increased by 1,600 compared to 1,700 in the previous 12 months. Read the OpenUK report to understand OpenUK's plan to build more contributors to open source projects from the UK and our Skills ask of the government. https://openuk.uk/stateofopen/state-of-open-the-uk-in-2024-phase-2-the-open-manifesto #opensource #theopenmanifesto #openuk

 Like

Liked Kubernetes: Which node is a pod on? | Mark Needham
Post details
When running Kubernetes on a cloud provider, rather than locally using minikube, it’s useful to know which node a pod is running on. The normal command to list pods doesn’t contain this information: $ kubectl get pod NAME READY STATUS RESTARTS AGE neo4j-core-0 1/1 Running 0 6m neo4j-core-1 1/1 Running 0 6m neo4j-core-2 1/1 Running 0 2m I spent a while searching for a command that I could use before I came across Ta-Ching Chen’s blog post while looking for something else.

 Repost

Reposted Dave Anderson (@danderson@hachyderm.io)
Post details
Also, quick note for crowdstrike execs: everyone can see you looking over at that bus, considering your options, limbering up your throwing arm... Just a note that the people you probably want to hire are watching reeeally closely how you're going to handle this, and are taking notes. The shareholders may be into human sacrifices, but the people you need to run your business aren't. Choose wisely.