At least it was recognized that the way forward requires decentralization and interoperable protocols. 👏

"The Service Mesh: What Every Software Engineer Needs to Know about the World's Most Over-Hyped Technology"

"The case of the $20000 cookie"

> The outsider ... had been communicating late last month with one of the company’s security analysts. In one message, the HackerOne analyst sent the community member parts of a cURL command that mistakenly included a valid session cookie that gave anyone with possession of it the ability to read and partially modify data the analyst had access to.

"Authentication vulnerabilities in OpenBSD"

(A patch that fixes the issue has already been released)

Malicious Python libraries stealing OpenPGP and SSH keys:

– Look for python3-dateutil, and jeIlyfish.
– Both modules try to exfiltrate SSH/OpenPGP keys and send them to an IP address.
– This is the third time the PyPI team intervenes to remove typo-squatted malicious Python libraries from the official repository.

#python #malware #pypi #infosec #security #cybersecurity

Mozilla ranks products from "not creepy" to "super creepy" in terms of privacy, explaining the reasons behind every score.

hmmm, might be useful to have a very quick look on how a given tool or programming language works.

"Help stop the sale of Public Interest Registry to a Private Equity Firm"

"Internet world despairs as non-profit .org sold for $$$$ to private equity firm, price caps axed"


