Security Leftovers
-
Open-source security successes, learnings and new money reported by OpenSSF’s Alpha-Omega | VentureBeat [Ed: 'Linux' Foundation pushing the Microsoft line; Jim Zemlin speaks more for Microsoft than he speaks to people who -- unlike him -- actually use Linux]
Open-source security has taken multiple steps forward in 2022, thanks in no small part to multiple efforts led by the Open Source Security Foundation, aka OpenSSF.
-
AWS container image repository vulnerability addressed [Ed: "Clown" computing means that security breaches are assured, set aside privacy violations (spooks get access to everything)]
Amazon Web Services has addressed a vulnerability in the Amazon Elastic Container Register Public Gallery, a public container image repository used by Amazon Linux, Ubuntu, NGINX, and HashiCorp Consul, reports The Record, a news site by cybersecurity firm Recorded Future.
Threat actors could leverage the flaw, discovered by Lightspin Director of Security Research Gafnit Amiga, to facilitate ECR Public image, layer, and registry and repository tag creation, deletion, and updates.
-
Reimagining Democracy - Schneier on Security
My perspective, of course, is security. I want to create a system that is resilient against hacking: one that can evolve as both technologies and threats evolve.