GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Josh Bressers (joshbressers@infosec.exchange)

  1. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Monday, 04-May-2026 02:54:55 JST Josh Bressers Josh Bressers
    in reply to
    • Viss
    • Will Dormann

    @Viss @wdormann every AI vulnerability company wants to find something juicy, and have no idea how to coordinate the findings

    In conversation about 20 days ago from infosec.exchange permalink
  2. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Monday, 04-May-2026 02:54:53 JST Josh Bressers Josh Bressers
    in reply to
    • Viss
    • Greg K-H
    • Will Dormann

    @gregkh @wdormann @Viss

    This post got into my head. I think you're right, the days of coordination are over

    So I wrote it down
    https://opensourcesecurity.io/2026/05-vulnerability-economics/

    In conversation about 20 days ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: opensourcesecurity.io
      The lopsided economics of vulnerabilities
      from Josh Bressers
      There was recently a really good thread about the Copy Fail vulnerability between Will Dormann and Greg K-H. The TL;DR is that vulnerability reporting and disclosure is in a weird state of flux. This discussion got me wondering what’s going on, and I think we’re seeing the extremes emerging of how vulnerabilities have always worked. The middle of the bell curve has been removed. There are three groups in this story. The Security Researchers, the Companies, and Open Source developers. In the above discussion Will is a security research (one of the best I’ve ever seen). Greg is part of open source. There isn’t a great company representative, but that’s OK.
  3. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Wednesday, 25-Mar-2026 18:21:02 JST Josh Bressers Josh Bressers

    I love the hot takes that this Trivy debacle will be the end of open source

    Heartbleed didn't kill open source
    Log4Shell couldn't get the job done
    xz tried and failed

    This won't kill it either

    Free is too good of a deal

    In conversation about 2 months ago from infosec.exchange permalink
  4. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Tuesday, 13-Jan-2026 02:59:06 JST Josh Bressers Josh Bressers

    This week on #OpenSourceSecurity I have a chat with @algernon about @iocaine

    Iocaine creates a maze of garbage to trap scraping bots. I love this idea, it has amazing chaotic good energy!

    I learn all about how Iocaine works, and even got to see some dashboards showing off the size of the problem and how Iocaine handles it all.

    https://opensourcesecurity.io/2026/2026-01-iocaine-algernon/

    In conversation about 4 months ago from infosec.exchange permalink
  5. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Thursday, 09-Oct-2025 11:21:41 JST Josh Bressers Josh Bressers

    OK open source security nerds, I need your help

    I have a podcast youtube show thing called Open Source Security

    https://opensourcesecurity.io/

    I'm always looking for guests. Back when I changed formats in January I had a pretty large list of people sent to me as suggestions. I've made it through the list (it took me 10 months)

    If you know someone (or are someone) doing open source security work I would love a suggestion. DMs are open and there are other contact things on the website

    I especially like guests who are unsung heroes

    In conversation about 8 months ago from infosec.exchange permalink
  6. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Monday, 15-Sep-2025 03:21:09 JST Josh Bressers Josh Bressers
    in reply to
    • Ryan Castellucci (they/them) :nonbinary_flag:
    • lemon

    @ryanc @lemonlolita the lower decks tuvix episode is solid gold. You should watch it after this

    In conversation about 8 months ago from infosec.exchange permalink
  7. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Thursday, 28-Aug-2025 14:42:53 JST Josh Bressers Josh Bressers

    The Register wrote a story about a single maintainer open source project, I think it's shameful and upsetting. So I wrote a blog post about it

    An absolutely ridiculous amount of open source is one person projects. I have the data to prove it

    https://opensourcesecurity.io/2025/08-oss-one-person/

    In conversation about 9 months ago from infosec.exchange permalink
  8. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Monday, 21-Jul-2025 23:16:56 JST Josh Bressers Josh Bressers
    in reply to
    • Adam Shostack :donor: :rebelverified:

    @adamshostack This post has been living for free in my head for a few days

    The part I'm most pondering is how not just anyone can build a bridge. We have a very defined field for who is allowed to design and build bridges

    And when it does fail, there are incredibly detailed investigations

    And those investigations end up changing the rules for future bridges (and might even result in existing bridges getting an upgrade)

    While in cybersecurity, I think we are basically at the "random person build bridge out of stuff they found in the woods" stage of bridge building

    It's also worth noting, it took hundred (probably thousands) of years to get to the place we are with bridge building

    In conversation about 10 months ago from infosec.exchange permalink
  9. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Wednesday, 16-Apr-2025 15:56:23 JST Josh Bressers Josh Bressers

    There's a discord server a bunch of vulnerability nerds hang out in I run. We'll be talking about what's happening with #CVE for the foreseeable future (good, bad, and ugly)

    Everyone is welcome to join, feel free to lurk, ask questions, or suggest ideas

    https://discord.gg/gSCrXxMuPx

    In conversation about a year ago from infosec.exchange permalink
  10. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Thursday, 03-Apr-2025 04:09:18 JST Josh Bressers Josh Bressers
    in reply to
    • sjvn
    • Greg K-H
    • The New Stack
    • badger

    @gregkh @TheNewStack @badger @sjvn

    Working to fix the CVE problems should be applauded

    But we need to keep in mind there are open source projects that are one person who spends two hours every other Saturday

    Expecting that person to become a CNA is 🍌

    They should be able to control their CVE data also, but today they can't

    In conversation about a year ago from infosec.exchange permalink
  11. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Thursday, 03-Apr-2025 04:08:58 JST Josh Bressers Josh Bressers
    in reply to
    • sjvn
    • The New Stack

    @sjvn @TheNewStack

    Ugh, please don't normalize "every open source projects needs to be a CNA"

    Most open source projects don't have the resources to be a CNA and shouldn't need to be a CNA

    Curl and the Kernel became CNAs because the CVE process is broken

    In conversation about a year ago from infosec.exchange permalink
  12. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Tuesday, 25-Feb-2025 23:09:00 JST Josh Bressers Josh Bressers

    This episode #OpenSourceSecurity talks to @sheogorath about forking open source projects

    It's a lot more complicated than you think it is, and Sheogorath has some first hand experience from one of the most complicated forks I've ever seen in HedgeDoc

    It's a fun chat filled with lessons

    https://opensourcesecurity.io/2025/2025-02-fork_open_source_sheogorath/

    In conversation about a year ago from infosec.exchange permalink
  13. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Tuesday, 21-Jan-2025 00:18:13 JST Josh Bressers Josh Bressers
    • Gary "grim" Kramlich

    I had a chat with @grimmy on #OpenSourceSecurity about maintaining an open source project for more than 20 years (Gary maintains Pidgin)

    It's a fun conversation that brought back many memories as well as some lessons for everyone involved in open source

    https://opensourcesecurity.io/2025/01-open_source_maintenance_with_gary_kramlich/

    In conversation Tuesday, 21-Jan-2025 00:18:13 JST from infosec.exchange permalink
  14. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Friday, 17-Jan-2025 00:46:35 JST Josh Bressers Josh Bressers

    Being on the "Top 10 CVE assigners of 2025" list probably isn't something fortinet is very excited about :)

    In conversation Friday, 17-Jan-2025 00:46:35 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/838/357/344/242/430/original/0ae3d1fb04d5d6c3.png
  15. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Wednesday, 01-Jan-2025 23:57:53 JST Josh Bressers Josh Bressers

    Now that 2025 is here, it's time to wind down the #osspodcast

    It was a fun run, but it was time to be done.

    I have a new project I'm calling "Open Source Security" (the domain is too good to not do something with it)

    I want to chat with people securing the use and creating of open source. I explain a lot more in the blog post (which also has audio)

    If you're one of these people, let me know! There are a lot of lessons for us all, and the people doing the best work aren't being listened to

    https://opensourcesecurity.io/posts/2025-01-the_future_of_open_source_security/

    In conversation Wednesday, 01-Jan-2025 23:57:53 JST from infosec.exchange permalink
  16. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Tuesday, 10-Dec-2024 22:05:05 JST Josh Bressers Josh Bressers
    in reply to
    • Cory Doctorow
    • daniel:// stenberg://

    @bagder @pluralistic the solution is obviously more AI

    It’s the one trick THEY don’t want you to know!!!

    In conversation Tuesday, 10-Dec-2024 22:05:05 JST from infosec.exchange permalink
  17. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Tuesday, 10-Dec-2024 12:26:10 JST Josh Bressers Josh Bressers
    in reply to
    • Seth Larson
    • Ecosyste.ms

    @sethmlarson Ooohhh, actually, I wonder if it's the fault of @ecosystems

    They had some data issues around that time I think

    In conversation Tuesday, 10-Dec-2024 12:26:10 JST from infosec.exchange permalink
  18. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Tuesday, 10-Dec-2024 10:47:23 JST Josh Bressers Josh Bressers
    • Seth Larson

    @sheogorath @sethmlarson

    Goodness no. This is pretty confusing stuff, the questions help me double check I'm not missing something

    I appreciate the questions

    In conversation Tuesday, 10-Dec-2024 10:47:23 JST from infosec.exchange permalink
  19. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Tuesday, 10-Dec-2024 10:42:40 JST Josh Bressers Josh Bressers
    • Seth Larson

    @sheogorath @sethmlarson

    I will accept that as the spike, but there are over 2 years of 1000 (give or take) removals per month, then it drops to 100

    In conversation Tuesday, 10-Dec-2024 10:42:40 JST from infosec.exchange permalink
  20. Embed this notice
    Josh Bressers (joshbressers@infosec.exchange)'s status on Tuesday, 10-Dec-2024 10:38:30 JST Josh Bressers Josh Bressers
    • Seth Larson

    Hey @sethmlarson

    I'm doing some investigation on how often the various ecosystems are removing packages. Do you know why PyPI had this decrease in the number of removed packages in the middle of May?

    In conversation Tuesday, 10-Dec-2024 10:38:30 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/625/963/913/324/005/original/0d0e97b521d94ab6.png
  • Before

User actions

    Josh Bressers

    Josh Bressers

    VP of Security at Anchore - Podcaster (http://opensourcesecuritypodcast.com http://hackerhistory.com) - Blogger (http://opensourcesecurity.io) - He/Him

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          138318
          Member since
          20 Jun 2023
          Notices
          91
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.