January 2, 2023
-
-
-
-
-
https://mastodon.social/@onthisday/109615646598105439Today in 1983, 40 years ago: The ARPANET officially changes to using TCP/IP, the Internet Protocol, effectively creating the Internet.
-
https://dev.to/yawaramin/the-human-toll-of-log4j-maintenance-35ap https://mastodon.scot/@simon_brooke/109616718918442031"#OpenSource maintainers are effectively unpaid outsourcing teams for giant corporations. The Alibaba engineer told the log4j team: 'Please hurry up'. Meanwhile, let's remember that Alibaba has a market cap of $348 billion" – Yawar Amin
-
https://hachyderm.io/@Di4na/109610607017869856As a maintainer of OpenSource libraries and packages, there is something that kept feeling off in the whole Software Supply Chain discourse. I think this comes down to something simple.
I am not a Supplier.
You can read more explanation there https://www.softwaremaxims.com/blog/not-a-supplier
%
Key point:
[T]here is no supply chain here. [T]here is no supplier. I am not providing you something [through a transaction]. There is no relationship.
I put something online because I wanted to. The fact you made your product depend on it is *your responsibility*. Not mine. Not [any] of the providers.
We provide libraries. We do not supply them.
You are not buying from a supplier, you are a raccoon digging through dumpsters for free code.
-
-
It's 70(!) pages of technical details covering each malware's: 🔎 IoCs 💉 Infection 💾 Persistence 📡 Capabilities + ☣️ Sample for download Read: "The Mac Malware of 2022" objective-see.org/blog/blog_0x71…-