Dependabot's implementation of Go modules continues to be poor.
FWIW, I recommend Go projects just turn it off, run govulncheck in a scheduled GitHub Action for security updates, and otherwise update dependencies manually when it makes sense in their release cycle.
14.03.2025 09:01 โ ๐ 101 ๐ 14 ๐ฌ 8 ๐ 0
This thread (and the answers) are a small gem, covering an almost forgotten piece of history of the security field.
06.03.2025 06:38 โ ๐ 19 ๐ 3 ๐ฌ 0 ๐ 0
1. Three new bad practices on use of known insecure or outdated cryptographic functions, hardcoded credentials, and product support periods.
2. Additional context added to the memory safety section.
3. Added additional examples of recommended actions to prevent SQL injection vulnerabilities.
4. Added additional examples of recommended actions to prevent command injection vulnerabilities.
5. Clarified timelines for patching Known Exploited Vulnerabilities (KEVs).
6. Added language for multi-factor authentication (MFA) specific to operational technology products.
7. Added that software manufacturers should support phishing-resistant MFA.
8. Other updates to phrasing throughout.
The FBI has released version 2.0 of its Product Security Bad Practices
PDF: www.ic3.gov/CSA/2025/250...
The changes are detailed in the image below
19.01.2025 18:39 โ ๐ 14 ๐ 6 ๐ฌ 0 ๐ 0
Oui oui, when in France!
05.12.2024 20:35 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
New era of slop security reports for open source
I'm on the security report triage team for CPython, pip, urllib3, Requests, and a handful of other open source projects.
I'm also in a trusted position such that I get "tagged in" to other open sou...
Seth Larson, the maintainer of several crucial Python projects, says he is seeing an increase in "extremely low-quality" security reports submitted by bug hunters, suggesting researchers are using AI/LLM tools to discover vulnerabilities and put together reports.
sethmlarson.dev/slop-securit...
05.12.2024 15:45 โ ๐ 30 ๐ 13 ๐ฌ 2 ๐ 2
All thatโs left is Giphy integration!
21.11.2024 14:43 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0
If it sounds like a duck and looks like a duck, its probably not a duck
21.11.2024 12:05 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
Iโve experienced similar and bsky feels to be ticking all the boxes for me at least. This feels like Twitter of 2014(in a good way)
21.11.2024 10:30 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0
๐๐๐๐ botb was/is something useful in this spaceโฆ
19.11.2024 17:23 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0
Wow so is bsky really maybe potentially becoming a thing now?
14.11.2024 14:01 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0
Ok, where are the South African hackers at? Post handles in replies if you see this please, and Iโll attempt a starter pack.
cc
@leonjza.bsky.social
@haroonmeer.canary.love
13.11.2024 19:01 โ ๐ 7 ๐ 3 ๐ฌ 5 ๐ 0
Once you are specifically targeted, chances are very good you will continue to see attempts to breach your defenses. APTs come for a purpose and thereโs a reason the Persistent part of the name was chosen.
11.10.2023 11:35 โ ๐ 7 ๐ 2 ๐ฌ 0 ๐ 0
This could be gnarly if your proxychains setup is somewhat exposed..which it shouldnโt
11.10.2023 13:45 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
So everybody from Musk's site seems to be here, yet my feed feels a bit anemic. What's a good trick to synch follows?
02.10.2023 11:51 โ ๐ 7 ๐ 2 ๐ฌ 2 ๐ 0
Total blast from the pastโฆ
15.09.2023 18:15 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
In January, the Bluesky app began with a few hundred users. Weโve since grown past 1 million. Iโm proud of what our team has accomplished in the last 9 months: weโve open sourced the protocol and app, introduced self-verification via custom domains, and enabled algorithmic choice with custom feeds.
12.09.2023 22:50 โ ๐ 2999 ๐ 373 ๐ฌ 91 ๐ 34
Tale as old as time: hackers hack stalkerware company because stalkerware is low-quality crap.
techcrunch.com/2023/08/26/b...
29.08.2023 04:06 โ ๐ 65 ๐ 12 ๐ฌ 1 ๐ 0
Now thatโs a flex to aim for
21.08.2023 20:07 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
NEW: Several attendees at Def Con saw mysterious alerts on their iPhones.
A researcher claimed responsibility and said it was a research project to teach people to turn off Bluetooth and "to have a laugh."
https://techcrunch.com/2023/08/14/researcher-says-they-were-behind-iphone-popups-at-def-con/
14.08.2023 20:01 โ ๐ 8 ๐ 3 ๐ฌ 0 ๐ 1
Today in 2000, 23 years ago, we introduced libcurl into the world. curl 7.1 was the first release featuring a separate library for Internet transfers, that curl was then made to use.
Today we estimate 20 BILLION installations worldwide.
07.08.2023 07:03 โ ๐ 14 ๐ 3 ๐ฌ 1 ๐ 0
Worse than npm or pip etc?
03.08.2023 07:52 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
Wait, itโs summer camp next week already? #itsbeenawhile
01.08.2023 16:06 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
01.08.2023 09:48 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
Code Kept Secret for Years Reveals Its Flawโa Backdoor
A secret encryption cipher baked into radio systems used by critical infrastructure workers, police, and others around the world is finally seeing sunlight. Researchers say it isnโt pretty.
For 25+ yrs police, military, intel agencies and critical infrastructure around the world relied on the TETRA radio standard to secure critical communications. But now Dutch researchers have examined secret algorithms used in TETRA and found something startling - an intentional backdoor, and more
24.07.2023 10:17 โ ๐ 33 ๐ 20 ๐ฌ 0 ๐ 3
Ask @patrick.risky.biz to go on vacation?
27.06.2023 11:22 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
This is valuable insight, thanks for sharing. How are you defining downturn? And what kind of timescales would you see as not crazy?
17.06.2023 17:52 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
Yeah definitely thatโd be great, let me know when youโre in London again!
30.05.2023 10:36 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
Howsit bru!
26.05.2023 06:49 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0
K8s SIG Security Co-Chair
container escape artist
goose in the machine
chaotic good
Minneapolis. They/them.
Stay punk ๐ด
Berkeley professor, former Secretary of Labor. Co-founder of @inequalitymedia.bsky.social and @imcivicaction.bsky.social.
Substack: http://robertreich.substack.com
Buy my new book: https://sites.prh.com/reich
Visit my website: https://rbreich.com/
it's a website (and a podcast, and a newsletter) about humans and technology, made by four journalists you might already know. like and subscribe: 404media.co
Original news, reviews, analysis of tech trends, and expert advice on the most fundamental aspects of tech.
since 1985
https://phrack.org
HashiCorp helps you automate multi-cloud and hybrid environments with Infrastructure and Security Lifecycle Management.
Together, we can do cloud right.
Founder and creative director of Bellingcat and director of Bellingcat Productions BV. Author of We Are Bellingcat.
software developer, founder of actorle.com and whichcountrytomoveto.com
Founder and Chief Swig at PortSwigger. Creator of Burp Suite and the Web Security Academy. Author of The Web Application Hacker's Handbook.
Work like hell,
Share all you know,
Abide by your handshake,
Have fun. - Dan Geer
Securing open source software, together
GP&CTO @blueyard.com
Author, musician, speaker, developer
https://chadfowler.com/
I'm on Germ DM ๐
anchr://ger.mx/A4ThL8vo6C6uygkNTQKyjHTSc9ZUaQWU0s5aVU3Io2s4#did:plc:4qsyxmnsblo4luuycm3572bq
Startup CEO at @miren.dev
Organic bio-electric pattern matching grid.
Amanda Katz said this was the cool kids table.
Professor of Marketing at NYU Stern School of Business, serial entrepreneur, and host of the Prof G and Pivot Podcasts.
yeah, like it says in the display name, Iโm also on Mastodon now too as travis@mastodon.mit.edu
I want you to win and be happy. Code, OSS, STEM, Beyoncรฉ, T1D, open source artificial pancreases, Portland, 3D printing, sponsorship http://hanselminutes.com inclusive tech podcast! VP of Developer Community @ Microsoft ๐ฎ
http://hanselman.com/about
Co-founder and CTO of Oxide Computer Company. According to Field of Schemes, "tech exec and Oakland A's fan" -- but more of an Oakland Ballers fan now.