• 0 Posts
  • 7 Comments
Joined 2 years ago
cake
Cake day: June 9th, 2023

help-circle

  • No. The internet and the later WWW have been so instrumental in my life there is no way I’d have not had been influenced differently.

    I’ve worked through so many arguments and unsafe questions in online spaces that simply wouldn’t have been possible in the very conservative areas I grew up. I’d likely have had to seek answers with out groups and ended up elsewhere adding to my changed influences. I’d have likely had a very different career path too.

    I’m faithful that I’d have ended up in the same religion but it’d have taken a much darker journey to get there.






  • Hopefully more projects take advantage of vulnerability scanning and monitoring tools like those in this OWASP list https://owasp.org/www-community/Free_for_Open_Source_Application_Security_Tools, have good code quality standards to make their projects easier to understand and evaluate, contribute and respond to CVE reports, and get third party security auditing.

    All of that is hard to motivated those throwing their code out to the world only to share how they scratched their itch to perform. I think we need a combination of governments and non-profits providing incentives / grants to projects doing good practices, document and provide trusted a forum to validate vulnerabilities, give some backing to “trusted” frameworks, and provide some vulnerability and auditing themselves.

    The recent EU push into more government open source usage will help as they will be more incentivized to secure the pipelines and everyone will benefit the fruits of that firehose of funding.