Listened to
a post on geeking-out.simplecast.com
Post details
Listened to
On-call was just the beginning—reflecting on Q1 2024 at incident.io by The Debrief by incident.io

Post details
Q1 2024 is officially behind us. So we figured that it was a great time for a bit of reflection on the exciting start to the year. In this episode, we sit down with our founders, Stephen, Chris, and Pete, to get a bit of perspective on how the last three months played out. We chat about On-call, our AI launch, and the hundreds of other features, bug fixes, and bits of polish and delight that we've shipped over the last 12 weeks. We also chat about the state of the company as a whole, our growth, and ultimately what's on the horizon.

I may be attending .
Listened to
Building a unified API on the shoulders of OSS with Robin Guldener from Nango

Post details
Robin Guldener from Nango talks to Mike about building an open, unified API, the value of building on top of Open Source products, and building a growing product team on this episode of the podcast.

Listened to
XZ Bonus Spectacular Episode
by and
Post details
Josh and Kurt talk about the recent events around XZ. It’s only been a few days, and it’s amazing what we already know. We explain a lot of the basics we currently know with the attitude much of these …
Listened to
The undercover generalist featuring Adolfo Ochagavía (Changelog & Friends #37)

Post details
Which is smarter: specializing in a particular tech or becoming more of a generalist? It depends! Which is why Jerod invited “undercover generalist” Adolfo Ochagavía on our “It Depends” series to weigh the pros & cons of each path.

Reposted
Miss Americana and the Heartbreak 𝚙𝚛𝚒𝚗𝚝()s (@quephird@tech.lgbt)

Post details
Attached: 1 image One of my friends from $BIRBSITE posted this and I am dyingggggggg

Reposted
Mike Lynch (@mikelynch@aus.social)
Post details
Content warning: my take on the xz backdoor
Reposted
Royce Williams (@tychotithonus@infosec.exchange)
Post details
Corollary: Your adversaries' SBOMs and dependency graphs *for your infrastructure* are better than yours.
Reposted
Will Dormann (@wdormann@infosec.exchange)
Post details
That sound you hear is a flurry of people asking ChatGPT to write a business plan to monetize the XZ incident.
Reposted
Zach Leatherman :11ty: (@zachleat@zachleat.com)
Post details
tech companies donate their april fools’ day joke budget to open source maintainers challenge 2024
Reposted
mhoye (@mhoye@mastodon.social)
Post details
Polite reminder about the Jia Tan XZ hack: if an organization is so well run and well funded that it's able to play that long a game to that degree of depth and sophistication, that organization does not have all its eggs in one basket.
Reposted
HarriettMB. (@harriettmb@mastodon.ie)
Post details
When Elon Musk, JK Rowling and the cops are unhappy, you know it’s a good law that will protect people. https://www.bbc.co.uk/news/uk-scotland-68703684
Reposted
Marko Karppinen (@karppinen@mastodon.online)
Post details
There’s a combo hot take brewing in my head about the #xz and #redis debacles. It goes something like: When the shit hits the fan and part of the reason appears to be an overworked and underpaid maintainer, lots of people come out of the woodwork to demand more respect and money for them. But when a maintainer recognizes that they’re in an unsustainable situation and dares to make a proactive change, well FUCK THAT GUY. WHO THE HELL DOES HE THINK HE IS?
Reposted
Matthew Garrett (@mjg59@nondeterministic.computer)
Post details
nation state actor maintenance of an open source project may introduce a lot of backdoors, but it also helps a lot of PRs get merged, so, it;s impossible to say if its bad or not,
Reposted
kf (@kf@666.glitchwit.ch)
Post details
being forced to mute the word “backdoor” is queerphobic
Reposted
lcamtuf :verified: :verified: :verified: (@lcamtuf@infosec.exchange)
Post details
I think the most important lesson from the xz incident is that if you're losing an online argument about the quality of your open-source project, you can now safely accuse the opponents of being state-sponsored sock puppets and drop the mic
Reposted
the clownward spiral (@ieure@retro.social)
Post details
Happy Transgender Day of Visibility and Easter. May your eggs crack.
Reposted
Dgar (@dgar@aus.social)
Post details
Them: What’s the dumbest thing you’ve ever done? Me: Awfully bold of you to assume I’ve peaked.
Reposted
Terence Eden (@Edent@mastodon.social)
Post details
I wrote this ⬆️ a few years ago. As the fallout from the #XZ hack reverberates, expect to see people calling for a "real name" policy for contributors to critical infrastructure. But, as I explain, there are several practical problems with that. https://shkspr.mobi/blog/2021/02/whats-my-name-again/ That's before we get to the ethical and privacy issues. Oh, and making it *easier* for attackers to target named individuals.
Reposted
cathos (@cathos@merveilles.town)

Post details
Maintenance is more important than innovation. This xz debacle is a symptom of a system that prioritizes lots of things above maintenance. Take this as a reminder to rest, to mend things & pay attention to what needs mending in yourself. Do the radical thing of working slowly and making all things more whole.
Week Notes 24#13 (4 mins read).
What happened in the week of 2024-03-25?
Listened to
Cup o' Go | 🚲 Bikeshedding about bikeshedding, and Go Community Roundup

Post details
Proposals(re)accepted: add slices.Repeat functionaccepted: report use of too-new standard library symbols with go vetFrom around the communityBlog: Context-induced performance bottleneck in Go by Gabriel AugendreNew community Q&A site: godev.com, powerd by Apache AnswerBlog: Go Enums Still Suck...

Listened to
Jacob Kaplan-Moss on Compensating Open Source Maintainers (but not that way)
by

Post details
Jacob talks about the backlash against open source maintainers seeking compensation, ethical use of software, financial support for maintainers, and complexities in licensing.

Reposted
Aral Balkan (@aral@mastodon.ar.al)
Post details
Personally, I’d rather celebrate a day about real living people than a fictitious magic zombie.
Bookmarked
Optimizing SQLite for servers

Post details
SQLite is often misconceived as a "toy database", only good for mobile applications and embedded systems because it's default configuration is optimized for embedded use cases, so most people trying it will encounter poor performances and the dreaded SQLITE_BUSY error. But what if I told you that by tuning a

Reposted
Luis Villa (@luis_in_brief@social.coop)

Post details
Attached: 1 image This text is not something we wrote in a rush this morning to meet the moment. We've had variations on this on our site from day 1. I believed it then and I believe it now.

Reposted
Mike Sheward (@SecureOwl@infosec.exchange)
Post details
people are saying the xz backdoor is likely the work of a nation state actor, and given that it appears to been slow rolled for a couple of years and immediately became obsolete before it was fully launched - you do have to admit it bears the hallmarks of a government IT project
Reposted
Neil Brown (@neil@mastodon.neilzone.co.uk)
Post details
New blogpost: _**[It is about trust, not software](https://neilzone.co.uk/2024-03-30-it-is-about-trust-not-software.html)**_ My reflections on the `xz` situation. > This isn't about software, it's about trust, and trust, especially *digital* trust, is easy to misplace...
Reposted
Aaron Patterson ✅ (@tenderlove@mastodon.social)
Post details
"open source needs more funding!" *nation state pays for backdoor* "not like that!"
Listened to
SoCal Linux Expo with SCaLE attendees (Ship It! #97)

Post details
Justin & Autumn take you with them to the 2024 SoCal Linux Expo where they asked six fellow attendees about their favorite open source projects and their least favorite commands.

Bookmarked
Everything I Know About the Xz Backdoor
by
Post details
stateunstableinblogdate3/29/2024 😖 Unstable Updating at the speed of light, blink once and a word could be gone! These nodes are eratic, unstable, dangerous, but that's why they are fun. Please note: …
Reposted
Hynek Schlawack (@hynek@mastodon.social)
Post details
I know nobody wants to admit it, but security shit shows like heartbleed, log4shell, or xzgate are kinda exciting times to live thru. 🤓 Also I’m afraid it’s the only way to prove the problems we’ve been droning about for years are real and not made up by greedy maintainers.
Reposted
Gabe Kangas (@gabek@social.gabekangas.com)

Post details
My heart goes out to xz. A single maintainer, who was clearly in a rough place with mental health, screaming out to the world for some help and additional contributions, and somebody shows up wanti...
Reposted
James Smith 💾 (@Floppy@mastodon.me.uk)

Post details
Attached: 1 image @bob

Reposted
ROTOPE~1 :yell: (@rotopenguin@mastodon.social)
Post details
@0xabad1dea@infosec.exchange that's a warning to malware state actors - do not get between a db guy and performance. They will fuck you up.
Reposted
yossarian (1.3.6.1.4.1.55738) (@yossarian@infosec.exchange)
Post details
my only contribution to the xz discourse: absolutely none of the supply chain stuff we're currently doing, including the things i like, would have stopped this. the only things that can stop this are (1) compulsively treating all code as untrusted, and (2) way, way stronger capability checks and restrictions in running systems. (1) is economically infeasible (the world runs on free labor from OSS), and (2) has had only very limited practical success.
Reposted
Jonathan Corbet (@corbet@social.kernel.org)

Post details
Random, unordered, probably useless thoughts on today's apocalypxze... Part of the success in getting this into Debian may be the result of there being no xz maintainer there. It is "maintained" ...

Reposted
Geoffrey Thomas (@geofft@mastodon.social)
Post details
@glyph @eb@social.coop I'm frustrated that big tech's efforts to increase core library security are "your project is too popular, you must use 2FA" and "the best reverse engineers in the world will find your bugs and put you on a 90 day disclosure deadline" and not "here is $100K/year and benefits to keep doing what you're doing at your own pace."
Reposted
Glyph (@glyph@mastodon.social)
Post details
@eb@social.coop I really hope that this causes an industry-wide reckoning with the common practice of letting your entire goddamn product rest on the shoulders of one overworked person having a slow mental health crisis without financially or operationally supporting them whatsoever. I want everyone who has an open source dependency to read this message https://www.mail-archive.com/xz-devel@tukaani.org/msg00567.html
Reposted
Soldier of FORTRAN :ReBoot: (@mainframed767@infosec.exchange)

Post details
Attached: 1 image #xz #CVE #cve20243094 #Linux

Reposted
danielle 🏳️🌈 (@endocrimes@toot.cat)
Post details
It’s not surprising that a major security vulnerability is once again caused by maintainer burnout and someone stepping in to take over. We’ve all been talking about that risk for years. Sadly it’s also unsurprising that OSS teams still are going to need to plead with management to stay funded, and paid OSS maintainers will still do unpaid overtime to work with volunteers. 🙃.
What can we learn about the backdooring of xz/liblzma, using OpenSSF Security Scorecards and dependency-management-data? (6 mins read).

Looking at how the recent CVE-2024-3094 vulnerability could provide insight into other cases of risk in dependencies and their lack of code review.
Listened to
13% of the time, Devin works every time (JS Party #317)

Post details
Jerod, KBall & Nick discuss the latest news: Devin, Astro DB, The JavaScript Registry, Tailwind 4 & Angular merging with Wiz. Oh, and a surprise mini-game of HeadLIES!

Listened to
A RedMonk Conversation: Engaging with Developers on Hacker News (With Dan Moore) | PodServe.fm

Post details
Join RedMonk analysts James Governor and Kate Holterhoff as they chat with Dan Moore about Hacker News, the social news website for developers. This conversation digs into significant questions concerning this network that include not only what makes it unique, but also the special sauce that makes developers flock there. Moore suggests strategies for vendors hoping to successfully engage this community, and more general best practices for becoming involved. This RedMonk Conversation was originally published in video form on March 28, 2024.

Reposted
Josh Simmons (@josh@josh.tel)
Post details
Love to see forks emerge when a company gets greedy and transitions to source-available after years of accepting third party contributions and establishing market share under an open source license.
Reposted
Rob Ricci :real: (@ricci@discuss.systems)
Post details
Hey, with people in the news getting sentenced to prison, facing the possibility of prison time, etc., just a reminder: it is not desirable, nor funny, that violence in prison (including sexual violence), be a part of someone's punishment. Even people you really, really do not like who have done really super bad things. It is to the United State's shame that violence in prison is part of our carceral system, and we should not celebrate it, ever. We should seek to eliminate it.
Reposted
CatSalad🐈🥗 (D.Burch) :blobcatrainbow: (@catsalad@infosec.exchange)

Post details
Attached: 1 image Going to need slightly bigger [truth table](https://en.wikipedia.org/wiki/Truth_table)... :calculator:

Listened to
#72 - Give People What They Came For, with Jerod Santo

Post details
Today I got the pleasure to chat with Jerod Santo, the Managing Editor at Changelog Media. Picture this – a podcast that not only uncovers the intricacies of Jerod's career but also shares some unconventional lessons learned from his work. From navigating the ever-evolving tech landscape to spearheading Changelog, Jerod brings a wealth of experience that transcends your typical engineer expectations and taps into the heart of what it means to build a sustainable developer community.
