GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    fugueish (fugueish@infosec.exchange)'s status on Thursday, 07-Dec-2023 05:57:57 JST fugueish fugueish

    Eliminating this vulnerability class should be seen as a business imperative likely requiring participation from many departments. The authoring agencies urge executives to lead from the top by publicly identifying senior staff who will drive publication of their roadmap and assist with realigning resources as needed.

    https://www.cisa.gov/resources-tools/resources/case-memory-safe-roadmaps

    In conversation Thursday, 07-Dec-2023 05:57:57 JST from infosec.exchange permalink
    • Embed this notice
      fugueish (fugueish@infosec.exchange)'s status on Thursday, 07-Dec-2023 05:57:55 JST fugueish fugueish
      in reply to

      In part, this is because they are planning for the post-memory-unsafety future. (See e.g. https://www.youtube.com/watch?v=mi6ZLmrXNP0)

      But vendors are still addicted to their ability to dump these externalities onto customers. It's 'expensive' to move away from C/C++ in exposed attack surface — but only because the existing costs are externalized.

      In conversation Thursday, 07-Dec-2023 05:57:55 JST permalink

      Attachments

      1. #HITB2021SIN KEYNOTE 1: Security Technology Arms Race 2021 - Medal Event - Mark Dowd
        The investment into both offensive and defensive technologies has grown dramatically in line with the Internet’s rise as the pivotal system for communication...
    • Embed this notice
      fugueish (fugueish@infosec.exchange)'s status on Thursday, 07-Dec-2023 05:57:57 JST fugueish fugueish
      in reply to

      Intelligence agencies begging vendors to fix the bugs they use for intelligence gathering might seem surprising. But they have complex equities to balance, among them the fact that it is their nations who most depend on reliable information infrastructure.

      In conversation Thursday, 07-Dec-2023 05:57:57 JST permalink
      Matthew Lyon repeated this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.