omkhar's Avatar

omkhar

@omkhar.net.bsky.social

Security guy. Website: https://omkhar.net Scholarship: https://skscholarship.com Twitter/X: https://x.com/_omkhar Mastodon: https://infosec.exchange/@Omkhar Bluesky: https://bsky.app/profile/omkhar.net LinkedIn: https://linkedin.com/in/omkhar

453 Followers  |  55 Following  |  441 Posts  |  Joined: 25.06.2023  |  2.2426

Latest posts by omkhar.net on Bluesky

Open source built the internet. It’s still holding it together with duct tape and goodwill.

Let’s treat it — and the people behind it — like the $8.8 trillion miracle it is.

#aislop #opensourcesoftware #security #cybersecurity #touchgrass

07.07.2025 12:44 — 👍 1    🔁 0    💬 0    📌 0

* Using OSS personally? Thank a maintainer. Donate. Contribute. Even fixing a typo in the README helps.

07.07.2025 12:44 — 👍 3    🔁 3    💬 1    📌 0

* Using OSS in your business? Chances are, you are. Time to give back — with funding, sponsorships, or actual engineering help.

07.07.2025 12:44 — 👍 2    🔁 0    💬 1    📌 0

So, what can you do?

* Using AI to vibe-code security bugs? Please stop. Seriously. Shut the laptop. Go touch grass. Maybe talk to a human.

07.07.2025 12:44 — 👍 0    🔁 0    💬 1    📌 0
Unsupported Browser | HackerOne

Want a peek into his inbox of doom?
1. HackerOne cURL Hacktivity hackerone.com/curl/hacktiv...
2. Filter by: status = not applicable
3. Feel: 😬 existential dread

This is what happens when people feed vibe-code into an LLM, squint, and hit “submit.”

07.07.2025 12:44 — 👍 0    🔁 0    💬 1    📌 0
Unsupported Browser | HackerOne

Enter the AI Slop Era.

Take Daniel Stenberg — creator and lead maintainer of cURL and libcurl — two of the most widely used OSS projects in existence. Instead of sipping margaritas on a beach somewhere (as he should be), he's busy triaging nonsense AI-generated “exploits” reported via HackerOne.

07.07.2025 12:44 — 👍 1    🔁 0    💬 1    📌 0
Unsupported Browser | HackerOne

Let that sink in. Open source software is quietly propping up the global economy like a tired BOFH running on coffee and unpaid emotional labor.

And how do we reward open source maintainers, the unsung heroes keeping the digital world upright?

07.07.2025 12:44 — 👍 1    🔁 0    💬 1    📌 0
Unsupported Browser | HackerOne

It’s not light reading, but here’s the TL;DR:

* Supply-side value of creating and maintaining popular open source software? About $4.15 billion.

* Demand-side replacement cost if companies had to rebuild that OSS themselves? A casual $8.8 trillion.

07.07.2025 12:44 — 👍 0    🔁 0    💬 1    📌 0
All modern digital infrastructure runs on a project some random person in Nebraska has been maintaining since 2003

All modern digital infrastructure runs on a project some random person in Nebraska has been maintaining since 2003

$8.8 trillion. Yes, with a T.

In 2024, my friend Frank Nagle (et al.) at Harvard Business School dropped a paper titled The Value of Open Source Software

www.hbs.edu/ris/Publicat...

07.07.2025 12:44 — 👍 3    🔁 1    💬 1    📌 0
Post image

Happy 4th of July!

Taken at my citizenship ceremony, years ago.

04.07.2025 13:15 — 👍 1    🔁 0    💬 0    📌 0

The Citizen Lab has an excellent write up here : citizenlab.ca/2025/06/a-pr...

David Fraser has an excellent YouTube play list regarding C-2, and his concerns here : www.youtube.com/playlist?lis...

#canadaday #civilrights #privacy

01.07.2025 12:25 — 👍 0    🔁 0    💬 0    📌 0

Let’s not sleepwalk into surveillance. We deserve better.

If you're a Canadian resident, contact your Member of Parliament : www.ourcommons.ca/members/en - remember, it's their elected job to represent you.

I've posted more about C-2 here: bsky.app/profile/omkh...

01.07.2025 12:25 — 👍 0    🔁 0    💬 1    📌 0
Find Members of Parliament - Members of Parliament - House of Commons of Canada Find Members of Parliament - Members of Parliament - House of Commons of Canada

C-2 is an incredibly violation of civil rights. It must be stopped.

I don’t expect legislators to understand software engineering, that’s why software engineers need to advocate against this.

01.07.2025 12:25 — 👍 0    🔁 0    💬 1    📌 0
Find Members of Parliament - Members of Parliament - House of Commons of Canada Find Members of Parliament - Members of Parliament - House of Commons of Canada

Canada

Happy Canada Day!

As we celebrate Canada's birthday, I appeal to all patriotic Canadians to speak to your member's of parliament to get rid of Bill C-2.

01.07.2025 12:25 — 👍 0    🔁 0    💬 1    📌 0

omkhar PSA's ahead of the holiday week:

1) Price of oxtail is too high.
2) Plural of oxtail, is "oxtail dem"

Thank you for listening.

29.06.2025 17:54 — 👍 1    🔁 0    💬 0    📌 0
Find Members of Parliament - Members of Parliament - House of Commons of Canada Find Members of Parliament - Members of Parliament - House of Commons of Canada

PPS If you're a Canadian resident, find your Member of Parliament here: www.ourcommons.ca/members/en

27.06.2025 13:47 — 👍 0    🔁 0    💬 0    📌 0
Preview
Unspoken Implications: A Preliminary Analysis of Bill C-2 and Canada’s Potential Data-Sharing Obligations Towards the United States and Other Countries - The Citizen Lab On June 3, 2025, the Canadian government tabled Bill C-2, omnibus legislation that, if passed, would introduce a wide array of new federal agency and law enforcement powers, and would significantly re...

PS The Citizen Lab has an excellent write up citizenlab.ca/2025/06/a-pr...

27.06.2025 11:51 — 👍 1    🔁 0    💬 1    📌 0

#PrivacyMatters #BillC2 #Canada #DigitalRights #Policy #CivicEngagement

27.06.2025 11:32 — 👍 0    🔁 0    💬 1    📌 0
Preview
Government Bill (House of Commons) C-2 (45-1) - First Reading - Strong Borders Act - Parliament of Canada Government Bill (House of Commons) C-2 (45-1) - First Reading - Strong Borders Act - Parliament of Canada

If you're concerned (and you should be), reach out to your Member of Parliament. Let them know you oppose C-2 and support real protections for Canadian privacy and civil rights.

You can read the full bill here:

www.parl.ca/DocumentView...

Let’s not sleepwalk into surveillance. We deserve better.

27.06.2025 11:32 — 👍 0    🔁 0    💬 1    📌 0

Free societies are built on the principle that the law protects the innocent—not that we must prove we have nothing to hide.

27.06.2025 11:32 — 👍 0    🔁 0    💬 1    📌 0

I keep seeing arguments like, “If you’re not doing anything wrong, you have nothing to worry about.”

Let me be clear: that’s not how rights work.

27.06.2025 11:32 — 👍 0    🔁 0    💬 1    📌 0

All accessed more easily under vague “exigent circumstances”

As a person who’s been accosted based on “reasonable suspicion” due to…. existing, I’m concerned that this bill expands surveillance powers and erodes due process protections that Canadians have long relied on.

27.06.2025 11:32 — 👍 0    🔁 0    💬 1    📌 0

It lowers the threshold for law enforcement to access your private data—without a warrant. All it takes is "reasonable suspicion."

What kind of data?

* Internet and cellphone metadata

* Your location and activity logs

* Information shared across borders with foreign agencies

27.06.2025 11:32 — 👍 0    🔁 0    💬 1    📌 0

Canadians, pay attention: Bill C-2 is a quiet threat to your privacy and civil liberties.

With so much happening around the world, it’s easy to miss what’s going on in our own backyard. But Bill C-2, now in the House of Commons, deserves your attention.

27.06.2025 11:32 — 👍 1    🔁 0    💬 1    📌 1

Oh hey, I'm speaking at that! Come one, come all, USENIX Security is a fantastic conference and I'm so excited that there's an Enigma track for talks about big ideas in security.

(I'm planning to talk about a bunch of lessons I learned the hard way after I left academia, but open to suggestions!)

25.06.2025 02:07 — 👍 27    🔁 4    💬 0    📌 0
Microsoft Forms

If you’re interested in joining and plan to be in NYC, register here to attend by June 10: forms.office.com/pages/respon...

We can't wait to see you!

#UNOpenSourceWeek #ai #opensourcesoftware #futureofwork

02.06.2025 19:51 — 👍 0    🔁 0    💬 0    📌 0

Zack and I have the honor of hosting an official side event on Jun 17, 2024 at our offices at the Empire State Building in conjunction with our friends at the United Nations.

02.06.2025 19:51 — 👍 0    🔁 0    💬 1    📌 0

The United Nations Office for Digital and Emerging Technologies and the United Nations Office of Information and Communications Technology are collaborating to bring you an exciting Open Source Week 2025, June 17-20 2025.

02.06.2025 19:51 — 👍 0    🔁 0    💬 1    📌 0
Post image

Do you want to hear about AI, open source and the future of work at the Empire State Building?

02.06.2025 19:51 — 👍 0    🔁 0    💬 1    📌 0

Thank you Christine for providing me the opportunity to spend time with these amazing young people today at WIT [In]spire Day!

#Leadership #CareerAdvice #WITInspireDay #FutureOfWork #Graduates #Motivation #LinkedIn

15.05.2025 15:54 — 👍 2    🔁 0    💬 0    📌 0

@omkhar.net is following 20 prominent accounts