While many things have not changed since this paper was published in 2002, the landscape around #CVE and open source software has, in my opinion.

This paper mainly contemplates official patches and bulletins from commercial vendors, or at least a CVE that was reviewed by a panel of editors. It rightly calls out that the quality of fixes varies widely.

However, today a CVE in a FOSS package may mean little to nothing in context of a production product or system.
#FOSS
@smb @adamshostack

I definitely recommend folks read the paper linked in the first post. Here's a TL;DR summary in the form of Figure 1: " "A hypothetical graph of risks of loss from penetration and from application of a bad patch. The optimal time to apply a patch is where the risk lines cross."

#CVE#OSS #FOSS #FLOSS #OpenSource #FreeSoftware #InfoSec

@smb @adamshostack

I too am tired of seeing this ridiculous waiting page of security theatre. it's not professional to have that load during a presentation with global teams who don't want to see catgirls — if you're going to waste our time, at least don't put your inside jokes and cutsie nonsense on the loading page — it only serves to make OSS look unprofessional and juvenile.

- https://hackaday.com/2025/08/22/this-week-in-security-anime-catgirls-illegal-adblock-and-disputed-research/

#oss #infosec

I too am tired of seeing this ridiculous waiting page of security theatre. it's not professional to have that load during a presentation with global teams who don't want to see catgirls — if you're going to waste our time, at least don't put your inside jokes and cutsie nonsense on the loading page — it only serves to make OSS look unprofessional and juvenile.

- https://hackaday.com/2025/08/22/this-week-in-security-anime-catgirls-illegal-adblock-and-disputed-research/

#oss #infosec

My friends, I'm so excited and happy to introduce a new project: the illumos Cafe!

The positive and constructive spirit of the BSD Cafe, created and maintained by all the friends who participated from day one in building a strong and friendly community, deserves to spread to other operating systems. Because there are other OSes that deserve attention, certainly more than they're getting right now.

Operating systems based on illumos (like SmartOS, OmniOS, Tribblix, OpenIndiana, etc.) are mature, stable, secure, and perfectly usable for a wide range of tasks. ZFS is native, zones are an excellent method for containerization, and bhyve and kvm coexist beautifully - and so much more, too much to list in a single post.

So from today, the illumos Cafe will stand alongside the BSD Cafe in creating a positive, respectful, and growth-oriented (but also relaxing!) environment, starting right here in the Fediverse with a Mastodon instance and a snac one.

I've written an introductory article about the project, including some technical details. I invite everyone interested to read it: https://it-notes.dragas.net/2025/08/18/introducing-the-illumos-cafe/

Choose your table, take a seat and enjoy your time at the illumos Cafe!

#SysAdmin#IT#BSDCafe #illumosCafe#Community#OpenSource#OSS #illumos#SmartOS#OpenIndiana#ZFS #bhyve #kvm#Fediverse#Mastodon #snac#ITNotes

muppeth
muppeth liked this activity

My friends, I'm so excited and happy to introduce a new project: the illumos Cafe!

The positive and constructive spirit of the BSD Cafe, created and maintained by all the friends who participated from day one in building a strong and friendly community, deserves to spread to other operating systems. Because there are other OSes that deserve attention, certainly more than they're getting right now.

Operating systems based on illumos (like SmartOS, OmniOS, Tribblix, OpenIndiana, etc.) are mature, stable, secure, and perfectly usable for a wide range of tasks. ZFS is native, zones are an excellent method for containerization, and bhyve and kvm coexist beautifully - and so much more, too much to list in a single post.

So from today, the illumos Cafe will stand alongside the BSD Cafe in creating a positive, respectful, and growth-oriented (but also relaxing!) environment, starting right here in the Fediverse with a Mastodon instance and a snac one.

I've written an introductory article about the project, including some technical details. I invite everyone interested to read it: https://it-notes.dragas.net/2025/08/18/introducing-the-illumos-cafe/

Choose your table, take a seat and enjoy your time at the illumos Cafe!

#SysAdmin#IT#BSDCafe #illumosCafe#Community#OpenSource#OSS #illumos#SmartOS#OpenIndiana#ZFS #bhyve #kvm#Fediverse#Mastodon #snac#ITNotes

My friends, I'm so excited and happy to introduce a new project: the illumos Cafe!

The positive and constructive spirit of the BSD Cafe, created and maintained by all the friends who participated from day one in building a strong and friendly community, deserves to spread to other operating systems. Because there are other OSes that deserve attention, certainly more than they're getting right now.

Operating systems based on illumos (like SmartOS, OmniOS, Tribblix, OpenIndiana, etc.) are mature, stable, secure, and perfectly usable for a wide range of tasks. ZFS is native, zones are an excellent method for containerization, and bhyve and kvm coexist beautifully - and so much more, too much to list in a single post.

So from today, the illumos Cafe will stand alongside the BSD Cafe in creating a positive, respectful, and growth-oriented (but also relaxing!) environment, starting right here in the Fediverse with a Mastodon instance and a snac one.

I've written an introductory article about the project, including some technical details. I invite everyone interested to read it: https://it-notes.dragas.net/2025/08/18/introducing-the-illumos-cafe/

Choose your table, take a seat and enjoy your time at the illumos Cafe!

#SysAdmin#IT#BSDCafe #illumosCafe#Community#OpenSource#OSS #illumos#SmartOS#OpenIndiana#ZFS #bhyve #kvm#Fediverse#Mastodon #snac#ITNotes

♻️ Please boost! ♻️

Looking for frontend devs for volunteer open-source team at a humanitarian aid org! As a Frontend Developer at Distribute Aid (https://distributeaid.org), you’ll create new pages for our website and update/maintain existing ones, often working closely with our designers and other devs. Looking for mid/long-term commitment. Main goal is to finally get our website relaunched. Volunteer commitment is ~5h/week.

Stack: NextJS, TypeScript, Strapi, Radix UI

We’re looking for experienced devs who are reliable, organised, and can communicate well. You do not need to know the full stack you’ll be working with. You just need to know how to learn and ask for help if you need it. Previous open source experience is nice but not strictly necessary. If you learn quickly and willingly, we can help you get started

It would be good if you have some availability overlapping with Central European Time and can make it to at least 1x tech hang per month and 1x sprint meeting per quarter (that’s ~4 meetings a month)

Our tech hangs are every Wednesday and Thursday from 6 to 8 pm CET/CEST and sprint meetings are during tech hang on the first Wednesday of each month

Our tech team is international and diverse—most of our team members are in some way marginalised—and leadership is fully queer/trans.

If you’re interested, please get in touch via tech@distributeaid.org. That comes directly to me as the Technical Program Manager. If you have any questions, you can ask me here too :)

#Developers #frontendDevs #frontend#OSS#FOSS #volunteering#NextJS #typescript#Strapi

♻️ Please boost! ♻️

Looking for frontend devs for volunteer open-source team at a humanitarian aid org! As a Frontend Developer at Distribute Aid (https://distributeaid.org), you’ll create new pages for our website and update/maintain existing ones, often working closely with our designers and other devs. Looking for mid/long-term commitment. Main goal is to finally get our website relaunched. Volunteer commitment is ~5h/week.

Stack: NextJS, TypeScript, Strapi, Radix UI

We’re looking for experienced devs who are reliable, organised, and can communicate well. You do not need to know the full stack you’ll be working with. You just need to know how to learn and ask for help if you need it. Previous open source experience is nice but not strictly necessary. If you learn quickly and willingly, we can help you get started

It would be good if you have some availability overlapping with Central European Time and can make it to at least 1x tech hang per month and 1x sprint meeting per quarter (that’s ~4 meetings a month)

Our tech hangs are every Wednesday and Thursday from 6 to 8 pm CET/CEST and sprint meetings are during tech hang on the first Wednesday of each month

Our tech team is international and diverse—most of our team members are in some way marginalised—and leadership is fully queer/trans.

If you’re interested, please get in touch via tech@distributeaid.org. That comes directly to me as the Technical Program Manager. If you have any questions, you can ask me here too :)

#Developers #frontendDevs #frontend#OSS#FOSS #volunteering#NextJS #typescript#Strapi

Okay, I know it’s appalling that I keep forgetting this place exists (tbf I’ve had some really weird as shit interactions with randoms last time I tried) and that it took @LauraLangdon to remind me that THIS is where all the OSS/FOSS people hang out. But here I am now. And maybe it’ll stick this time.

Not much has changed and yet everything has changed. @finnporter and I moved to Galicia in Spain about 4 months or so ago. We’re loving it so far. I think we’ve just been lucky with the weather this year because it’s nowhere near as hot as I feared. The beach is a 7 minute walk from our flat. And because it’s the Atlantic it’s also nice and chilly, which I’m delighted by.

Chronic health stuff has… not been too great, but the Spanish healthcare system seems to actually be one of the few still functional ones, at least here in Galicia. So I’m waiting for referrals to an allergist for MCAS dx and probably to internal medicine for potential hEDS dx. Not thrilled I likely have these conditions but at least I may actually get to access care for them. I’m still too medically traumatised to actually believe it lol but so far everyone in the medical field here has been pretty great. Also, being trans is absolutely zero trouble here which is a delightful change for us.

I’m keen to connect to some covid conscious folks in Northern Spain if there are any around since it’s hard to make friends. Oh and we’re also looking for frontend devs for our volunteer open-source tech team at Distribute Aid. But I’ll just post about that separately so it’s easy to boost 😊

Alright, I guess it’s good to be back. Hopefully I’ll stick around this time.

#Spain#NorthernSpain#Galicia #oss #foss#DeveloperContent #frontend #trans #2SLGBTQIA#LGBTQIA #spoonies#chronicIllness

🚯 No More Markdown 🚯

Well, it's certainly not going away any time soon, but it doesn't have to be the default. While it's easily a majority of the docs formats that I have to use, it's not my favorite.

Perhaps in an ideal world it would be AsciiDoc or LaTeX All The Time, but we don't live in that world, oh well 💋

In the interim, here's someone who wrote about the topic which seems worth sharing. Interesting points, ja?

- Why You Shouldn’t Use “Markdown” for Documentation: https://ericholscher.com/blog/2016/mar/15/dont-use-markdown-for-technical-docs/

#engineering #software #oss #foss #markdown #documentation

🚯 No More Markdown 🚯

Well, it's certainly not going away any time soon, but it doesn't have to be the default. While it's easily a majority of the docs formats that I have to use, it's not my favorite.

Perhaps in an ideal world it would be AsciiDoc or LaTeX All The Time, but we don't live in that world, oh well 💋

In the interim, here's someone who wrote about the topic which seems worth sharing. Interesting points, ja?

- Why You Shouldn’t Use “Markdown” for Documentation: https://ericholscher.com/blog/2016/mar/15/dont-use-markdown-for-technical-docs/

#engineering #software #oss #foss #markdown #documentation

Looking for a consulting gig working on a cool open-source interoperability project? Consider responding to this RFP from the Lyrasis Organizational Home for Community Supported Techologies! https://lyrasis.org/wp-content/uploads/2025/08/Lyrasis-Interoperability-Project-RFP-2025.pdf
#glam #oss #interoperability#fedihire