ravirockks, to random

Latest piece of guidance from the NSA and friends on securing the software supply chain has dropped.

This edition is on OSS and SBOMs.
https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3613105/nsa-and-esf-partners-release-recommended-practices-for-managing-open-source-sof/

kkarhan,

@ravirockks I've had not read them yet but I'd say that one should always archive dependencies and aim to only have reproducible builds.

Something that I work on OS/1337.

Now granted @os1337 is NOT built with security in mind at all, but that's due to it's specific goals.

But archiving releases and mirroring repos is an important way to keep things secure.

And in high-security envoirments and should be mandatory to the point that only and no are legal.

nytpu, to random

Dunno why anyone is surprised that Technology Connections is aggressively anti-FOSS considering that he made a video on his second channel following up on digitizing analog video, and he went on a whole rant about tangentially related FOSS project when people kept asking for (& suggesting) alternatives to “do all the postprocessing in Premiere”, as if it's your fault if you can't afford $300/year for that shit. (Really contradicts his analogy about people suggesting FOSS software “suggesting you should buy a house when someone complains about their landlord)

kkarhan,

@nytpu I think that's really sad to see, because isn't a solution to the of and the of companies like who decided to axe any when they were forced to accept their customers' right to sell ...

I'm really disappointed about him, because does solve the issue...

ronanmcd, to random
@ronanmcd@mastodon.green avatar

Opening software anytime before about 2015 - Open.

Opening software now - This software has auto-updated, here is a list of functions that no longer work

kkarhan,

@ronanmcd only.with shitty do you get that regularly..

jorge, (edited ) to linux
@jorge@hachyderm.io avatar

Linux users are so garbage to developers, no wonder everyone hates you. Seriously most of you deserve the desktop.

EDIT: I had to cut out the picture of the person being trashed. That's how garbage these people are.

kkarhan,

@grimmy @jorge @pidgin also sadly most users refuse to do with what promises:

  • Pay someone to implement it.

The only reason @AsahiLinux exists is because it got extensive funding from several people via among other channels...

skip, to infosec

This won't end well.

"The European Union's Cyber Resilience Act's requirement to disclose vulnerabilities within 24 hours of exploitation could potentially expose organizations to attacks from adversaries or government surveillance."

https://www.darkreading.com/edge/security-pros-warn-that-eu-vulnerability-disclosure-rule-is-risky

kkarhan,

@skip The problem is that it doesn't stipulate the requirement for vendors to fix their trash in a timely manner, cuz unlike which doesn't have the €€€€€€€ to do so often, they have exclusive control over the source code.

Also @EU_Commission doesn't require CCSS to become and void it's once the maintainers don't provide and anymore.

Cuz that should be made law.

kkarhan,

@skip @EU_Commission At least for where this is feasible.

Also I think should mandate and for everything wothout exceptioms, including the requirement to provide free, unrestructed and non-paywalled that are dpculented to interface with required systems.

Because neither nor or anyone else should have the de-facto national as and Software!

SheHacksPurple, to Cybersecurity

If you could wave a magic wand, and "solve" 3 security problems, what would they be? And why?

kkarhan,

@SheHacksPurple

  1. Force people to manage login credentials properly.
  2. Make #TechLiteracy mandatory.
  3. Mandate #OpenStandards that ain't #paywalled unlike [#ISO norms] and only allow #decentralized #MultiVendor & #MultiProvider solutions aka. Ban #CCSS without exceptions.
neurovagrant, to random
@neurovagrant@masto.deoan.org avatar

deleted_by_author

  • Loading...
  • kkarhan,

    @vathpela Yes, I do value standards.

    I just think that as commonly implemented is still a and in almost all devices (in fact I know none where the is fully - including @frameworkcomputer 's devices!)...

    But maybe I just think that a lot of should be axed.

    cassidy, to linux
    @cassidy@blaede.family avatar

    I’m gonna dip my toes into volunteering as a Flatpak/Flathub developer advocate—basically, providing a human contact at a real company that can help larger apps/companies get their apps in front of Linux (and thus Steam Deck!) users.

    What are some of the biggest apps you think are missing from Flathub—or for apps already there, which are the ones you’d like to see verified?

    kkarhan,

    @fuchsiii @cassidy nodds in agreement

    Espechally since it's and you can't even reproduce the builds so the only good way to obtain these if directly from the company that made the software...

    smallcircles, to foss
    @smallcircles@social.coop avatar

    This is nice to see..

    A student can't afford to pay the $8 per month for sync, so builds a alternative. Then posts to HN and says "I probably violate ToS, so will take down the repo if asked".

    Then the Obsidian CEO replies. Explains they aren't VC-funded and the $8 bucks subscription keeps the light on. Applauds the work of the student, points to other open ways that content sync can be handled and gives advice "if you rename, there's no ToS problem". 👍

    https://news.ycombinator.com/item?id=37247767

    kkarhan,

    @TheOneSwit @pettter @edafe @pavelzinoviev @smallcircles @obsidian if you go by the shit, then that's true.

    on the other hand can be done in a way that just works and respects both users' human rights to privacy as well as getting stellar support and documentation that goes beyond what offers...

    tod, to random
    @tod@hci.social avatar

    The entire city of #Yellowknife is being evacuated. This is unprecedented and terrifying.

    And thousands of citizens aren’t aware because Meta continues to block news in the country.

    This is what happens when citizens are convinced to use an American multinational corporation as their community’s primary communications channel — a corporation that couldn’t give two shits about anything except its “fiduciary duty” to shareholders.

    https://www.cbc.ca/news/canada/north/nwt-wildfire-emergency-update-august-16-1.6938756

    kkarhan,

    @JustinLachance as I am contractually obligated to stay up to date and my job literally is to be the in terms of and what is being used.

    I forcibly migrate to @ubuntu because I don't get paid enough to deal with shit like .

    And those that need some proprietary get a machine with or a / session to a or that has been rackmounted.

    ian, to random

    I love when a company who built their whole business on top of open source developed by others (Linux, Ruby, Go, etc) decry "vendors who take advantage of pure OSS models, and the community work on OSS projects, for their own commercial goals" switch to a proprietary license rather than a copyleft that actually codifies the culture of reciprocal sharing.

    https://www.hashicorp.com/blog/hashicorp-adopts-business-source-license

    kkarhan,

    @natsume_shokogami @ian

    When we look at and other like and or even the correct reaction to horrible is simple:

    Refuse to use them in lieu of alternatives.

    Espechally since there is no legal mandate to use then!
    https://mastodon.world/

    animemer, to random

    hey, in a debate with @thecatcollective

    over parents being delusional,

    can you list any open source software that has become the industry standard, so far i got

    • obs- video-streaming
    • android
    • Linux and BSD on servers
    • both chrome and firefox are
      based on open source
    kkarhan,

    @animemer @thecatcollective in.shirt, the only still surviving exists solely due to 4 reasons:

    1. Toxic Lock-In (i.e. Microsoft & Apple) and weaponization of Patents (also espechally both!)

    2. Lazy Users that rather accept being mistreated amd milked for cash than mograting away. (All products!)

    3. Lack of investment in FLOSS Competitiors. (See by Blackmagocdesign)

    4. State-endorsed support and preferential treatment of CCSS over for the same bad reasons!

    aetus, to technology

    There was a time when I loved working by computer. But apps are so dodgy it's hard to get anything done reliably. MS Word constantly flashes extraneous page thumbnails & bits of garbage as I compose. Warns me it can't sync with cloud then it can. So distracting. Adobe rushes out updates that mess up so bad I spend a day fixing it. Chrome & any apps relying on it crash continuously. Can I go back to buying software & have it run w/o the cloud. I hate this future.

    kkarhan,

    @libreoffice @avon_deer @aetus yeah, that"s because basically gave the original devs the middle finger and they hard-forked to .

    And then Oracle made it basically so it ended up at the Apache Foundation...

    Similar to vs. but both are and don't share any codebase whatsoever!
    https://www.youtube.com/watch?v=S-3wEC6Fj_8
    https://fosstodon.org/@libreoffice/110859652971988010

    gamingonlinux, to random
    @gamingonlinux@mastodon.social avatar

    What is an actually controversial Linux opinion you hold?

    kkarhan,

    @gamingonlinux

    Just one?

    is the major preventor of becoming the norm since literally brick shit with minor updates, and the outright ignores the the fact that exist and not everything is and that people should not have to recompile their stuff!

    Otherwise everything that has been touched or associated with / is tainted and him being reinstated will continue to damage for years to come.

    kkarhan,

    @bitpirate @gamingonlinux
    So for any #CCSS that isn't locked to a specific #LTS #Distro and -Version if not Hardware (i.e. #Linux Version of #Autodesk #Maya required proof of eligible System [i.e. HP z-Series] & Supported OS [Subscription] i.e. [#RedHat #RHEL Workstation 5.0]) before you can even purchase any #License the most stable #APIs are those supported by #Proton (#Wine + #DXVK)...

    AND i wished this wasn't the case and we'd not have to rely on #Win32 / #Win64 #Userland to get shit done.

    kkarhan,

    @bitpirate @gamingonlinux I mean don't get me wrong, it really shines in compatibility as @fuchsiii has shown me several times: Even ancient games will run better than under Windows...

    But personally I think that / / should be transitional mechanisms and not be turned into a perpetual crutch...

    Not that I dislike it per-se but is the reason most (incl. ) doesn't get |ly-running !

    nichtich, to opensource
    @nichtich@openbiblio.social avatar

    #OpenSource is bad, seductive and cunning: each time I find and start to use a great OS project, soon I get ideas to improve it (starting with documentation) and end up becoming a contributor. With closed source I'd just complain and work around existing limitations.

    kkarhan,

    @nichtich you're doing it wrong!

    With #CCSS you'll pay to have someone do the contribs for you...

    donelias, to random Spanish
    @donelias@mastodon.cr avatar

    Desde la por defensa de la

    thelinuxcast, to random
    @thelinuxcast@fosstodon.org avatar

    So back on Firefox.

    Did an update and got this in @Vivaldi

    Your updates can't break things completely. Especially not on the stable branch.

    kkarhan,

    @fuchsiii @thelinuxcast @Vivaldi yeah, #glibc makes long-term support outside of #LTS distros like #RHEL, #SLES / #SLED, #OracleLinux and #Ubuntu LTS basically impossible unless one is a hardcore #Stallmanist and hates everything not #GPL-licensed and would rather want to see #Users suffer than accept that #CCSS is as valid to exist as #FLOSS...

    yura, to random
    @yura@udongein.xyz avatar

    @torvalds be like:

    kkarhan,

    @lunaa @yura @torvalds I know...

    There's a reason Distros like , and almost all systems using or want to get rid of if not replace it with something like , ,or another ...

    Because glibc bricking stuff with minor updates kills any and any non- that can't be recompiled.

    And what RMS et. al. may see as intentional, I think is the biggest issie that prevents from dominating |s!

    kkarhan,

    @lunaa @yura @torvalds because as much as we all want our favorite to run first, there will always be some that can't be replaced.

    That's why ( + ) are seen as "necessary" (not even evil at all) mechanisms so people can even do basic on , because prevents people from playing old Linux games that ain't FLOSS'd!

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • ngwrru68w68
  • everett
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • rosin
  • GTA5RPClips
  • Durango
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • provamag3
  • tacticalgear
  • osvaldo12
  • tester
  • cubers
  • cisconetworking
  • mdbf
  • ethstaker
  • modclub
  • Leos
  • anitta
  • normalnudes
  • megavids
  • lostlight
  • All magazines