Discussion
Loading...

#Tag

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Andrew Nesbitt boosted
Josh Bressers
@joshbressers@infosec.exchange  ·  activity timestamp last week

This episode of #OpenSourceSecurity I chat with Alex Zenla from Edera about the #TARmageddon vulnerability they found

I've coordinated a lot of vulnerabilities in my day, but never have I had to even think about something as difficult as this one. Alex fills us in on how it was found, what the coordination looked like, and some things to think about as we manage these incredibly complex supply chains

https://opensourcesecurity.io/2025/2025-12-tarmageddon-alex/

  • Copy link
  • Flag this post
  • Block
Josh Bressers
@joshbressers@infosec.exchange  ·  activity timestamp last week

This episode of #OpenSourceSecurity I chat with Alex Zenla from Edera about the #TARmageddon vulnerability they found

I've coordinated a lot of vulnerabilities in my day, but never have I had to even think about something as difficult as this one. Alex fills us in on how it was found, what the coordination looked like, and some things to think about as we manage these incredibly complex supply chains

https://opensourcesecurity.io/2025/2025-12-tarmageddon-alex/

  • Copy link
  • Flag this post
  • Block
Andrew Nesbitt boosted
Josh Bressers
@joshbressers@infosec.exchange  ·  activity timestamp 3 weeks ago

On this episode of #OpenSourceSecurity I chat with @hughsie about the Linux Vendor Firmware Service (LVFS)

While it's amazing we can update firmware from Linux now, it was a ton of work to get us here

If you have gear that doesn't work with LVFS, make sure you ask the vendor why not (and support the hardware folks who do support LVFS)

https://opensourcesecurity.io/2025/2025-11-lvfs-richard-hughes/

  • Copy link
  • Flag this post
  • Block
Josh Bressers
@joshbressers@infosec.exchange  ·  activity timestamp 3 weeks ago

On this episode of #OpenSourceSecurity I chat with @hughsie about the Linux Vendor Firmware Service (LVFS)

While it's amazing we can update firmware from Linux now, it was a ton of work to get us here

If you have gear that doesn't work with LVFS, make sure you ask the vendor why not (and support the hardware folks who do support LVFS)

https://opensourcesecurity.io/2025/2025-11-lvfs-richard-hughes/

  • Copy link
  • Flag this post
  • Block
Andrew Nesbitt and 1 other boosted
Josh Bressers
@joshbressers@infosec.exchange  ·  activity timestamp last month

This week on #OpenSourceSecurity I talk to @ottok about his blog post about detecting an attack like xz in Debian

It's a fascinating conversation about a very complicated topic

There are things that could be detected, but this one would have been very very difficult

https://opensourcesecurity.io/2025/2025-11-xz-debian-otto/

Open Source Security

Detecting XZ in Debian with Otto Kekäläinen

In this episode, Josh and Otto dive into the world of Debian packaging, exploring the challenges of supply chain security and the importance of transparency in open source projects. They discuss Otto’s blog post about the XZ backdoor and how it’s a nearly impossible attack to detect. Otto does a great job breaking down an incredibly complex problem into understandable pieces. Episode Links Otto Could the XZ backdoor have been detected with better Git and Debian packaging practices? This episode is also available as a podcast, search for “Open Source Security” on your favorite podcast player.
  • Copy link
  • Flag this post
  • Block
Josh Bressers
@joshbressers@infosec.exchange  ·  activity timestamp last month

This week on #OpenSourceSecurity I talk to @ottok about his blog post about detecting an attack like xz in Debian

It's a fascinating conversation about a very complicated topic

There are things that could be detected, but this one would have been very very difficult

https://opensourcesecurity.io/2025/2025-11-xz-debian-otto/

Open Source Security

Detecting XZ in Debian with Otto Kekäläinen

In this episode, Josh and Otto dive into the world of Debian packaging, exploring the challenges of supply chain security and the importance of transparency in open source projects. They discuss Otto’s blog post about the XZ backdoor and how it’s a nearly impossible attack to detect. Otto does a great job breaking down an incredibly complex problem into understandable pieces. Episode Links Otto Could the XZ backdoor have been detected with better Git and Debian packaging practices? This episode is also available as a podcast, search for “Open Source Security” on your favorite podcast player.
  • Copy link
  • Flag this post
  • Block
Stefano Marinelli boosted
FreeBSD Foundation
@FreeBSDFoundation@mastodon.social  ·  activity timestamp 4 months ago

How do you secure thousands of open-source projects?

At the June 2025 FreeBSD Developer Summit, Michael Winser shared three years of lessons from the Alpha-Omega project—covering supply chain risk, rapid audits, and sustainable funding.

📺 Watch here: Lessons From Funding Open Source Security Over the Past 3 Years, What’s Ahead
https://youtu.be/6DoT-eFH6tY?si=M_zlAfXFrCrvj36_

#BSDCan2025#OpenSourceSecurity#AlphaOmega#FreeBSD

Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this post
  • Block
FreeBSD Foundation
@FreeBSDFoundation@mastodon.social  ·  activity timestamp 4 months ago

How do you secure thousands of open-source projects?

At the June 2025 FreeBSD Developer Summit, Michael Winser shared three years of lessons from the Alpha-Omega project—covering supply chain risk, rapid audits, and sustainable funding.

📺 Watch here: Lessons From Funding Open Source Security Over the Past 3 Years, What’s Ahead
https://youtu.be/6DoT-eFH6tY?si=M_zlAfXFrCrvj36_

#BSDCan2025#OpenSourceSecurity#AlphaOmega#FreeBSD

Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this post
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-alpha.8 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login