rss-mstdn.studiofreesia.com is part of the decentralized social network powered by Mastodon.
RSSフィードの内容を投稿するbotアカウント用のサーバーです。 アカウント登録はできませんが、リモートフォローはウェルカム🤗🤗🤗

Server stats:

448
active users

Learn more

#cybersecurity

9 posts9 participants1 post today

Information about the UK #cybersecurity Bill coming out today:

Missing:

* Protections for encryption
* Explicit discussion of #digitalsovereignty and the need to transition to #opensource #foss
* Safeguards against future self inflicted cybersecurity disasters through hiding vulnerabilities leading to incidents like WannaCry

@openrightsgroup will be making the case for these changes

gov.uk/government/publications

GOV.UKCyber Security and Resilience Bill - policy statement

Watch Sachin Bhakar's session "Open Source Security by Design: Standards & Policies" at #FOSSASIASummit2025 to explore how security-first design principles, standards, and policies can strengthen open-source software from the ground up.

🔗 Click here youtu.be/2dH3AU02MFo?si=XoPM88 to watch on the FOSSASIA YouTube channel

XYZ 0.2.22 is released today - ivarch.com/programs/xyz.shtml

This release adds a check that all directories in the path have appropriate permissions, and extends the range of utility functions available to extensions.

XYZ is a lightweight #CyberSecurity tool for administrators to check a GNU/Linux or BSD system for common faults that could cause sensitive information or interfaces to be exposed, such as service accounts without a password, SSH private keys or GPG secret keys without passphrases, or lax permissions on configuration files.

XYZ uses the resources of the Codeberg platform - codeberg.org - for free software development.

ivarch.comivarch.com: XYZXYZ is a lightweight security tool to check for common configuration faults that could cause sensitive information or interfaces to be exposed, such as SSH private keys or GPG secret keys without passphrases, or service accounts without a password.

Keep in mind that just because an application is open source doesn't mean it's safer. If nobody checks its code for bugs or malware, it could be worse than other software.

----

We have so many questions that are making us feel a bit uneasy: ❓

In what ways can you be certain that a particular open-source software solution is secure?

What factors do individuals with an IT background consider when making decisions about open source software safety?

Certain open source software solutions have extensive code bases. Consequently, it would require a significant investment of time to verify the absence of bugs or malicious code. 🐞 ☠️

That said, even those who can understand code may not always have the time or energy to investigate every piece of software they install. So what are their criteria for endorsing a particular piece of software that they haven't analysed its code? 🧭

And what tips do you have for people who aren't developers, to help them make the best choices when they can't understand the code? Who can they trust?

Google to buy cybersecurity firm Wiz for $32B US in company's biggest ever deal
Google's parent company, Alphabet, has struck a deal to buy cybersecurity firm Wiz for $32 billion US in what would be the tech giant's biggest-ever acquisition, a move which comes at the same time it's facing a potential breakup of its internet empire.
#business #technology #cybersecurity #acquisition #News
cbc.ca/news/business/google-ac

Google to buy cybersecurity firm Wiz for $32B US in company's biggest ever deal
Google's parent company, Alphabet, has struck a deal to buy cybersecurity firm Wiz for $32 billion US in what would be the tech giant's biggest-ever acquisition, a move which comes at the same time it's facing a potential breakup of its internet empire.
#business #technology #cybersecurity #acquisition #News
cbc.ca/news/business/google-ac

Wenn ich am gleichen Tag gleich zwei billige Test-Phishing-Emails bekomme (Organisation nutzt Webex gar nicht) - halten die mich dann für blöd oder wollen die sicherstellen, dass wirklich niemand darauf reinfällt, damit sie ihre Statistik verbessern können? ("Sehen Sie, unser Training wirkt Wunder, die Menschen erkennen Phishing jetzt schon viel besser.") 🤔
#cybersecurity