GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Matt "msw" Wilson (msw@mstdn.social)

  1. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Thursday, 11-Sep-2025 14:10:09 JST Matt "msw" Wilson Matt "msw" Wilson
    in reply to
    • daniel:// stenberg://
    • Greg K-H
    • Jacques Chester

    @jacques @bagder @gregkh btw… how is it going, making the Universal Asset Graph on purpose?

    In conversation about 3 months ago from mstdn.social permalink
  2. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Thursday, 11-Sep-2025 14:10:06 JST Matt "msw" Wilson Matt "msw" Wilson
    in reply to
    • daniel:// stenberg://
    • Greg K-H
    • Jacques Chester

    @jacques @bagder @gregkh I'd really love to have some public database that would help us all collectively make more efficient resource allocation decisions.

    Let's take CVE-2025-38352 for example. CISA added it to the KEV because Google said that there is evidence of exploitation in the context of Android.

    If you use CONFIG_POSIX_CPU_TIMERS_TASK_WORK=y the fix is not needed.

    Linux distros aren't affected but release "fixes" anyway. https://forums.rockylinux.org/t/rocky-8-10-cve-2025-38352/19590/3

    #PatchAllTheThings! #InfoSec

    In conversation about 3 months ago from mstdn.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: us1.discourse-cdn.com
      Rocky 8.10 - CVE-2025-38352
      OK, I’m busy waiting. Regarding Rocky 9: We also use a machine with kernel 5.14.0-570.37.1.el9. On this machine, the kernel parameter CONFIG_POSIX_CPU_TIMERS_TASK_WORK=y is effective. If I understand correctly, this means that the problem does not occur. Regards
  3. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Thursday, 12-Jun-2025 04:10:15 JST Matt "msw" Wilson Matt "msw" Wilson
    in reply to

    I feel so old.

    https://lists.gnome.org/archives/gnome-list/1998-July/msg00163.html

    In conversation about 7 months ago from mstdn.social permalink
  4. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Thursday, 12-Jun-2025 04:04:27 JST Matt "msw" Wilson Matt "msw" Wilson

    Oh the _feels_ when reading this announcement!

    I was one of the GNOME project’s first sysadmins, back in the days of a single CVS server running on a machine hosted at Red Hat’s office.

    It’s amazing to see their journey to the cloud!

    #Linux #GNOME #OpenSource #FreeSoftware #FOSS #OSS #Cloud #AWS
    https://foundation.gnome.org/2025/06/10/gnome-has-a-new-infrastructure-partner-welcome-aws/

    In conversation about 7 months ago from mstdn.social permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      http://office.It/
    2. No result found on File_thumbnail lookup.
      GNOME Has a New Infrastructure Partner: Welcome AWS! – The GNOME Foundation
  5. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Tuesday, 13-May-2025 17:07:30 JST Matt "msw" Wilson Matt "msw" Wilson

    setuid root screen is a gift that just keeps on giving…

    #CVE #CVE_2025_23395 #InfoSec #Linux #OpenSource
    https://security.opensuse.org/2025/05/12/screen-security-issues.html

    In conversation about 8 months ago from mstdn.social permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Multiple Security Issues in Screen
      from Matthias Gerstner
      Screen is the traditional terminal multiplexer software used on Linux and Unix systems. We found a local root exploit in Screen 5.0.0 affecting Arch Linux and NetBSD, as well as a couple of other issues that partly also affect older Screen versions, which are still found in the majority of distributions.
  6. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Saturday, 03-May-2025 05:13:18 JST Matt "msw" Wilson Matt "msw" Wilson
    in reply to
    • Jan Wildeboer 😷:krulorange:
    • Stefano Zacchiroli

    @zacchiro @jwildeboer I came here to say this. You don’t have to agree to the other licenses as a contributor. You just have to license your contribution in a way that Redis has the rights needed to use them as sub-licenses.

    Contributors that license their contributions under MIT or BSD should not find this objectionable. Contributors that mindfully choose AGPLv3 to advance software freedom likely object.

    But sadly few contributors make that mindful choice.

    In conversation about 8 months ago from mstdn.social permalink
  7. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Saturday, 03-May-2025 05:13:16 JST Matt "msw" Wilson Matt "msw" Wilson
    in reply to
    • Jan Wildeboer 😷:krulorange:
    • Stefano Zacchiroli

    @jwildeboer @zacchiro indeed, it has not been BSD for some time, which is why Valkey exists.

    My only point is that too often I see outrage from contributors who submitted code under MIT or BSD terms, perhaps following inbound=outbound licensing practices for a project, when their contributions are “taken” and made proprietary through a new restrictive license.

    They don’t realize they gave _all_ permission to do that with their choice of license.

    In conversation about 8 months ago from mstdn.social permalink

    Attachments


  8. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Friday, 18-Apr-2025 03:38:05 JST Matt "msw" Wilson Matt "msw" Wilson
    • Kevin Beaumont

    @GossiTheDog but do they need to be?

    How many of them need to be actively managed in a globally coordinated way?

    Should every organization attempt to interpret the information present in CVEs, and the CVE information ecosystem _directly_?

    In conversation about 8 months ago from mstdn.social permalink
  9. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Friday, 18-Apr-2025 00:54:05 JST Matt "msw" Wilson Matt "msw" Wilson
    in reply to

    I frequently grump about what the #CVE system has become in practice. Folks may think that I’m not a proponent of the program. That’s not true at all. I’m an advocate for it, and for all those who pour their time and talent into it (often voluntarily).

    But, IMO it is an overstatement to say that a CVE is a critical element in coordinating response to emerging vulnerabilities like heartbleed or log4shell. Embargoed critical vulns are rarely identified with CVEs among defenders.

    #InfoSec #CVD

    In conversation about 8 months ago from mstdn.social permalink
  10. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Wednesday, 16-Apr-2025 14:24:27 JST Matt "msw" Wilson Matt "msw" Wilson

    Reflecting tonight on the #CVE program, all it has given us, and how frustrated I’ve been because of what does, and what it fails to do.

    Unfortunately there is no point in claiming that the purpose of a system is to do what it constantly fails to do…

    #InfoSec #SBOM #OpenSource

    In conversation about 8 months ago from mstdn.social permalink
  11. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Wednesday, 16-Apr-2025 14:24:26 JST Matt "msw" Wilson Matt "msw" Wilson
    in reply to

    I’m actually quite OK with this.

    The broader community is very good at detecting situations like these as damage, and routing around.

    Just like the Internet. Right?

    We had public disclosure and known vulnerability databases before CVE. And nothing is stopping those who have a shared need from coming together to fill a vacuum…
    #cve

    In conversation about 8 months ago from mstdn.social permalink
  12. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Wednesday, 16-Apr-2025 14:24:25 JST Matt "msw" Wilson Matt "msw" Wilson
    in reply to

    This is what the #CVE and CPE system does.

    We can chose to make the system different.

    https://github.com/madler/zlib/issues/868#issuecomment-2807804350

    In conversation about 8 months ago from mstdn.social permalink
  13. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Friday, 14-Feb-2025 18:32:27 JST Matt "msw" Wilson Matt "msw" Wilson

    When you choose to use a #FOSS license like BSD-3, you are choosing asymmetrical benefit relationship.

    Others can “take without giving back” and there is nothing fundamentally wrong with that.

    For example see the CRC64 performance improvements in #Redis copied from #Valkey.

    #FreeSoftware #OpenSource #OSS

    https://github.com/redis/redis/pull/13638

    In conversation about 10 months ago from mstdn.social permalink
  14. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Friday, 14-Feb-2025 18:32:25 JST Matt "msw" Wilson Matt "msw" Wilson
    in reply to
    • Howard Chu @ Symas

    @hyc Speaking (only for myself) as someone who refused to use the "open source" term for a very long time, "giving back" isn't part of the bargain from my point of view.

    To me, Free Software means that you can privately use the software however you'd like with no obligations "back" to the original author. Non-private use has limited obligations.

    If you want to *protect* and *propagate* those freedoms for *others* (farther downstream), use a copyleft license.

    In conversation about 10 months ago from mstdn.social permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      New Page 1
  15. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Friday, 24-Jan-2025 00:13:04 JST Matt "msw" Wilson Matt "msw" Wilson

    So I deactivated my account on that other social media site with a one letter name.

    In conversation about a year ago from mstdn.social permalink
  16. Embed this notice
    Esther Payne :bisexual_flag: (onepict@chaos.social)'s status on Sunday, 01-Dec-2024 20:19:54 JST Esther Payne :bisexual_flag: Esther Payne :bisexual_flag:
    • Anna e só

    This article by @anna speaks to me.

    "I speak the language of technology—and if you're reading this, there's a high chance you do too. We're living bridges of domains mysterious and unknown to many, domains that make and will continue to make a difference in the scale of oppression and horrors being spread and perpetuated into the world. What you do with that capacity and that knowledge can mean the difference between life and death. Use it to empower others."

    https://notapplicable.dev/freeze-but-fight.

    In conversation about a year ago from chaos.social permalink Repeated by msw

    Attachments

    1. No result found on File_thumbnail lookup.
      Freeze-but-fight · Anna e só
      Anna e só (/ˈɐ̃.nɐ e ˈsɔ/) is a Brazilian information systems architect building accessible, diverse, and resilient open projects.
  17. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Saturday, 13-Apr-2024 15:13:52 JST Matt "msw" Wilson Matt "msw" Wilson
    • jbz

    @jbzfn no, they aren’t “abusing” anything.

    And, naturally, FreeBSD uses a BSD license, not MIT as the post claims…

    #FreeSoftware #OpenSource #FOSS #OSS

    https://docs.freebsd.org/en/articles/bsdl-gpl/

    In conversation Saturday, 13-Apr-2024 15:13:52 JST from mstdn.social permalink
  18. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Tuesday, 09-Apr-2024 11:27:25 JST Matt "msw" Wilson Matt "msw" Wilson

    "A community of scholars should not have to build walls as high as the sky to protect a reasonable expectation of privacy [msw: or 'security'], particularly when such walls will equally impede the free flow of information.

    There is a reasonable trust between scholars in the pursuit of knowledge, a trust upon which the users of the Internet have relied for many years.

    #FreeSoftware #OpenSource #FOSS #OSS #InfoSec #XZ

    In conversation Tuesday, 09-Apr-2024 11:27:25 JST from mstdn.social permalink
  19. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Tuesday, 09-Apr-2024 11:27:24 JST Matt "msw" Wilson Matt "msw" Wilson
    in reply to

    This policy of trust has yielded significant benefits to the computer science community and, through the contributions of that community, to the world at large.

    Violations of such a trust cannot be condoned. Even if there are unintended side benefits, which is arguable, there is a greater loss to the community as a whole."

    - The Cornell Commission: On Morris and the Worm

    https://dl.acm.org/doi/10.1145/63526.63530

    #FreeSoftware #OpenSource #FOSS #OSS #InfoSec #XZ

    In conversation Tuesday, 09-Apr-2024 11:27:24 JST from mstdn.social permalink
  20. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Tuesday, 09-Apr-2024 11:27:23 JST Matt "msw" Wilson Matt "msw" Wilson
    in reply to

    Given the latest attack on the Internet through persistent threat actors via xz-utils, what demands will be placed on the community of scholars (including Free and Open Source software developers) that build the software we all use and enjoy as digital public goods?

    Will they be "walls as high as the skies?"

    #FreeSoftware #OpenSource #FOSS #OSS #InfoSec #XZ

    In conversation Tuesday, 09-Apr-2024 11:27:23 JST from mstdn.social permalink
  • Before

User actions

    Matt "msw" Wilson

    Matt "msw" Wilson

    Socio-technical Systems Engineer at #Amazon | Free and Open Source (#FOSS) Advocate | he/him/they/them | Opinions: my own

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          25406
          Member since
          13 Nov 2022
          Notices
          91
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.