Secure at every step: How GitHub’s dependency graph is generated ⌘ https://github.blog/2020-08-04-secure-at-every-step-how-githubs-dependency-graph-is-generated/
GitHub joins the Open Source Security Foundation ⌘ https://github.blog/2020-08-03-github-joins-the-open-source-security-foundation/
Maintainer spotlight: How to secure your project with one of the world’s top open source tools ⌘ https://github.blog/2020-07-30-maintainer-spotlight-how-to-secure-your-project-with-one-of-the-worlds-top-open-source-tools/
How to secure your GitHub organization and enterprise account ⌘ https://github.blog/2020-07-23-how-to-secure-your-github-organization-and-enterprise-account/
Securing your open source dependencies with GitHub dependency insights ⌘ https://github.blog/2020-07-16-securing-your-open-source-dependencies-with-github-dependency-insights/
How organizations can tackle securing the world’s code ⌘ https://github.blog/2020-07-15-how-organizations-can-tackle-securing-the-worlds-code/
Network Time Security ⌘ https://hack.org/mc/blog/nts.html
Better-than-nothing security ⌘ https://hack.org/mc/blog/btns.html
Looking back on the GitHub Security Lab Capture The Flag: CodeQL and chill ⌘ https://github.blog/2020-06-30-looking-back-on-the-github-security-lab-capture-the-flag-codeql-and-chill/
“Security scandal around WhatsApp shows the need for decentralised messengers and digital sovereignty” https://fsfe.org/news/2020/news-20200228-01.html
Cryptee | Private, Secure, Encrypted Photos and Encrypted Documents ⌘ https://crypt.ee/
Implicit flow in the Security BCP draft -14 ⌘ https://aaronparecki.com/2020/02/12/49/implicit
@mdosch@mdosch.de Apple refuses to ship GPLv3 software. bash has security bugs that Apple doesn’t want to backport. So they’ve switched default shells again, this time to zsh. (bash and the previous default, tcsh, still ship with the OS.)
Casino Screwup Royale: A tale of “ethical hacking” gone awry | Ars Technica https://arstechnica.com/information-technology/2019/03/50-shades-of-greyhat-a-study-in-how-not-to-handle-security-disclosures/
Facebook Stored Hundreds of Millions of User Passwords in Plain Text for Years — Krebs on Security https://krebsonsecurity.com/2019/03/facebook-stored-hundreds-of-millions-of-user-passwords-in-plain-text-for-years/
Errata Security: A basic question about TCP https://blog.erratasec.com/2019/02/a-basic-question-about-tcp.html
People love to talk about the potential security impact of exotic state-of-the-art shit like GPT-2 and deepfakes, but they’re neither convincing nor the lowest-effort effective way to create disinfo. Spinners scale better than GPT-2.
Can we trust Huawei with 5G? - The Verge ⌘ https://www.theverge.com/2019/2/7/18214166/huawei-security-china-fcc-5g-cybersecurity
Schneier on security: “There’s no good reason to trust blockchain technology” https://www.wired.com/story/theres-no-good-reason-to-trust-blockchain-technology/
Hackers hijack thousands of Chromecasts to warn of latest security bug – TechCrunch https://techcrunch.com/2019/01/02/chromecast-bug-hackers-havoc/
GitHub - trimstray/the-book-of-secret-knowledge: A collection of awesome lists, manuals, blogs, hacks, one-liners, cli/web tools and more. Especially for System and Network Administrators, DevOps, Pentesters or Security… https://github.com/trimstray/the-book-of-secret-knowledge
Errata Security: Some notes about HTTP/3 https://blog.erratasec.com/2018/11/some-notes-about-http3.html#.W_vnQUfav0M
“Mill vs. Spectre: Performance and Security” by Ivan Godard - YouTube https://www.youtube.com/watch?v=8E4qs2irmpc
Q: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible? - YouTube https://www.youtube.com/watch?v=ajGX7odA87k
Detecting the use of “curl | bash” server side | Application Security https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/
Supply-Chain Security - Schneier on Security https://www.schneier.com/blog/archives/2018/05/supply-chain_se.html
If we added up all the time spent in airport security in the past seven years, how many average human lifespans would it be?
So, the GCHQ has released a statement backing up Amazon & Apple’s denials. What do you bet the implant is 5eyes tech and not chinese at all? https://www.reuters.com/article/us-china-cyber-britain/uk-cyber-security-agency-backs-apple-amazon-china-hack-denials-idUSKCN1MF1DN
Request Information from Others Securely with Lockbin Add-in for MS Outlook ⌘ Read more…
In the grim dark future of 2020, nobody goes outside without first applying temporary tattoos of additional eyes to their face. Positioning of these additional eyes must be rotated every few hours for security purposes.
When Will Security Go Back to Normal? | Philosophy Tube - YouTube https://www.youtube.com/watch?v=yyzd_a6vLWY
@freemor@freemor.homelinux.net This is completely contrary to what people want. People don’t care about how something works. They want to use something that’s premade and that they can use without learning anything about it. Decentralization is a technical Detail, nobody cares about. Just like security or freedom. It’s all nice to have if it comes for free, no time investment and no convenience cuts. So the only way to establich decentralization is by making it better, cheaper and easier to use than centralized services. #sadtruth
@metamurks@www.metamurks.org I can understand this is annoying when you have a very bad connection, but I would sign Mike Loukides’ comment on that site.
Russian Censorship of Telegram - Schneier on Security https://www.schneier.com/blog/archives/2018/06/russian_censors.html
Band name of the day: the securities of ontotheology
Maliciously Changing Someone’s Address - Schneier on Security https://www.schneier.com/blog/archives/2018/05/maliciously_cha.html
The most interesting thing about https://www.fastly.com/blog/headers-we-dont-want is the indication that the culture of the web is a cargo-cult one where we will waste kilobytes per response on redundant headers that were deprecated 20 years ago or present possible security problems
In The Mesh - Scuttlebutt, A Decentralized Alternative To Facebook https://www.inthemesh.com/archive/secure-scuttlebutt-facebook-alternative/
Another meltdown
Someone is having another meltdown.
The Mueller probe should never have been started in that there was no collusion and there was no crime. It was based on fraudulent activities and a Fake Dossier paid for by Crooked Hillary and the DNC, and improperly used in FISA COURT for surveillance of my campaign. WITCH HUNT!
😂
Now, there is a [background](https://www.washingtonpost.com/world/national-security/after-mccabe-fir … ⌘ Read more
As a software engineer, being ignorant of sociology & psychology is just as bad as being ignorant of cryptography. Treat toxic communities the way you would treat any other security vulnerability: as an emergency.
- companies figure out that humans are expensive security risks and start doing without↵2. machine economy does not turn on humans, it just increasingly ignores them, humanity watches at the sidelines/bottom of the gravity well while the solar system lights up
Dymaxion: Please Stop Writing Secure Messaging Tools https://dymaxion.org/essays/pleasestop.html
How I Socially Engineer Myself Into High Security Facilities - Motherboard https://motherboard.vice.com/en_us/article/qv34zb/how-i-socially-engineer-myself-into-high-security-facilities
GitHub - RandomAdversary/Awesome-AI-Security: #AISecurity https://github.com/RandomAdversary/Awesome-AI-Security
Meet the Nomad Who’s Exploding the Internet Into Pieces With "Secure Scuttlebutt" - The Atlantic https://www.theatlantic.com/technology/archive/2017/05/meet-the-counterantidisintermediationists/527553/
How I learned to stop worrying (mostly) and love my threat model | Ars Technica https://arstechnica.com/security/2017/07/how-i-learned-to-stop-worrying-mostly-and-love-my-threat-model/
The Dark Architecture of the National Security State - CityLab https://www.citylab.com/design/2017/06/the-dark-architecture-of-national-security/529302/