GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Jonathan Yu (jawnsy@mastodon.social)'s status on Tuesday, 27-Aug-2024 03:49:54 JST Jonathan Yu Jonathan Yu
    in reply to
    • Maaret Pyhäjärvi

    @maaretp What's the goal of the security testing? It can be useful to get a baseline that you can then work to improve

    In conversation about 9 months ago from mastodon.social permalink
    • Embed this notice
      Paul Cantrell (inthehands@hachyderm.io)'s status on Tuesday, 27-Aug-2024 03:49:54 JST Paul Cantrell Paul Cantrell
      in reply to
      • Maaret Pyhäjärvi

      @jawnsy @maaretp
      One of the deep problems with security is that (unlike performance, say) it’s not really directly measurable, except in hindsight. You’re managing •unknown• problems and not just •known• ones.

      Thus the best chance of answering the question “How secure is this system?” is to look at systemic factors that create risk (e.g. maintenance process, delivery cadence, tool choices, internal incentives) and not just the specific flaws a security test would uncover.

      In conversation about 9 months ago permalink
    • Embed this notice
      Maaret Pyhäjärvi (maaretp@mas.to)'s status on Tuesday, 27-Aug-2024 03:49:55 JST Maaret Pyhäjärvi Maaret Pyhäjärvi

      The obsession to test for security feels misplaced when you see a system where dependencies are not updated, developers have little ideas about designs leading to vulnerabilities in the choice of language and deployments are driven by fast convenience over thoughtful trust perimeters. It’s peculiar how testing is the first thing after mild awareness.

      In conversation about 9 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.