GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Matt "msw" Wilson (msw@mstdn.social)

  1. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Tuesday, 13-May-2025 17:07:30 JST Matt "msw" Wilson Matt "msw" Wilson

    setuid root screen is a gift that just keeps on giving…

    #CVE #CVE_2025_23395 #InfoSec #Linux #OpenSource
    https://security.opensuse.org/2025/05/12/screen-security-issues.html

    In conversation about 10 days ago from mstdn.social permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Multiple Security Issues in Screen
      from Matthias Gerstner
      Screen is the traditional terminal multiplexer software used on Linux and Unix systems. We found a local root exploit in Screen 5.0.0 affecting Arch Linux and NetBSD, as well as a couple of other issues that partly also affect older Screen versions, which are still found in the majority of distributions.
  2. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Saturday, 03-May-2025 05:13:18 JST Matt "msw" Wilson Matt "msw" Wilson
    in reply to
    • Jan Wildeboer 😷:krulorange:
    • Stefano Zacchiroli

    @zacchiro @jwildeboer I came here to say this. You don’t have to agree to the other licenses as a contributor. You just have to license your contribution in a way that Redis has the rights needed to use them as sub-licenses.

    Contributors that license their contributions under MIT or BSD should not find this objectionable. Contributors that mindfully choose AGPLv3 to advance software freedom likely object.

    But sadly few contributors make that mindful choice.

    In conversation about 21 days ago from mstdn.social permalink
  3. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Saturday, 03-May-2025 05:13:16 JST Matt "msw" Wilson Matt "msw" Wilson
    in reply to
    • Jan Wildeboer 😷:krulorange:
    • Stefano Zacchiroli

    @jwildeboer @zacchiro indeed, it has not been BSD for some time, which is why Valkey exists.

    My only point is that too often I see outrage from contributors who submitted code under MIT or BSD terms, perhaps following inbound=outbound licensing practices for a project, when their contributions are “taken” and made proprietary through a new restrictive license.

    They don’t realize they gave _all_ permission to do that with their choice of license.

    In conversation about 21 days ago from mstdn.social permalink

    Attachments


  4. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Friday, 18-Apr-2025 03:38:05 JST Matt "msw" Wilson Matt "msw" Wilson
    • Kevin Beaumont

    @GossiTheDog but do they need to be?

    How many of them need to be actively managed in a globally coordinated way?

    Should every organization attempt to interpret the information present in CVEs, and the CVE information ecosystem _directly_?

    In conversation about a month ago from mstdn.social permalink
  5. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Friday, 18-Apr-2025 00:54:05 JST Matt "msw" Wilson Matt "msw" Wilson
    in reply to

    I frequently grump about what the #CVE system has become in practice. Folks may think that I’m not a proponent of the program. That’s not true at all. I’m an advocate for it, and for all those who pour their time and talent into it (often voluntarily).

    But, IMO it is an overstatement to say that a CVE is a critical element in coordinating response to emerging vulnerabilities like heartbleed or log4shell. Embargoed critical vulns are rarely identified with CVEs among defenders.

    #InfoSec #CVD

    In conversation about a month ago from mstdn.social permalink
  6. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Wednesday, 16-Apr-2025 14:24:27 JST Matt "msw" Wilson Matt "msw" Wilson

    Reflecting tonight on the #CVE program, all it has given us, and how frustrated I’ve been because of what does, and what it fails to do.

    Unfortunately there is no point in claiming that the purpose of a system is to do what it constantly fails to do…

    #InfoSec #SBOM #OpenSource

    In conversation about a month ago from mstdn.social permalink
  7. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Wednesday, 16-Apr-2025 14:24:26 JST Matt "msw" Wilson Matt "msw" Wilson
    in reply to

    I’m actually quite OK with this.

    The broader community is very good at detecting situations like these as damage, and routing around.

    Just like the Internet. Right?

    We had public disclosure and known vulnerability databases before CVE. And nothing is stopping those who have a shared need from coming together to fill a vacuum…
    #cve

    In conversation about a month ago from mstdn.social permalink
  8. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Wednesday, 16-Apr-2025 14:24:25 JST Matt "msw" Wilson Matt "msw" Wilson
    in reply to

    This is what the #CVE and CPE system does.

    We can chose to make the system different.

    https://github.com/madler/zlib/issues/868#issuecomment-2807804350

    In conversation about a month ago from mstdn.social permalink
  9. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Friday, 14-Feb-2025 18:32:27 JST Matt "msw" Wilson Matt "msw" Wilson

    When you choose to use a #FOSS license like BSD-3, you are choosing asymmetrical benefit relationship.

    Others can “take without giving back” and there is nothing fundamentally wrong with that.

    For example see the CRC64 performance improvements in #Redis copied from #Valkey.

    #FreeSoftware #OpenSource #OSS

    https://github.com/redis/redis/pull/13638

    In conversation about 3 months ago from mstdn.social permalink
  10. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Friday, 14-Feb-2025 18:32:25 JST Matt "msw" Wilson Matt "msw" Wilson
    in reply to
    • Howard Chu @ Symas

    @hyc Speaking (only for myself) as someone who refused to use the "open source" term for a very long time, "giving back" isn't part of the bargain from my point of view.

    To me, Free Software means that you can privately use the software however you'd like with no obligations "back" to the original author. Non-private use has limited obligations.

    If you want to *protect* and *propagate* those freedoms for *others* (farther downstream), use a copyleft license.

    In conversation about 3 months ago from mstdn.social permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      New Page 1
  11. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Friday, 24-Jan-2025 00:13:04 JST Matt "msw" Wilson Matt "msw" Wilson

    So I deactivated my account on that other social media site with a one letter name.

    In conversation about 4 months ago from mstdn.social permalink
  12. Embed this notice
    Esther Payne :bisexual_flag: (onepict@chaos.social)'s status on Sunday, 01-Dec-2024 20:19:54 JST Esther Payne :bisexual_flag: Esther Payne :bisexual_flag:
    • Anna e só

    This article by @anna speaks to me.

    "I speak the language of technology—and if you're reading this, there's a high chance you do too. We're living bridges of domains mysterious and unknown to many, domains that make and will continue to make a difference in the scale of oppression and horrors being spread and perpetuated into the world. What you do with that capacity and that knowledge can mean the difference between life and death. Use it to empower others."

    https://notapplicable.dev/freeze-but-fight.

    In conversation about 6 months ago from chaos.social permalink Repeated by msw

    Attachments

    1. No result found on File_thumbnail lookup.
      Freeze-but-fight · Anna e só
      Anna e só (/ˈɐ̃.nɐ e ˈsɔ/) is a Brazilian information systems architect building accessible, diverse, and resilient open projects.
  13. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Saturday, 13-Apr-2024 15:13:52 JST Matt "msw" Wilson Matt "msw" Wilson
    • jbz

    @jbzfn no, they aren’t “abusing” anything.

    And, naturally, FreeBSD uses a BSD license, not MIT as the post claims…

    #FreeSoftware #OpenSource #FOSS #OSS

    https://docs.freebsd.org/en/articles/bsdl-gpl/

    In conversation about a year ago from mstdn.social permalink
  14. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Tuesday, 09-Apr-2024 11:27:25 JST Matt "msw" Wilson Matt "msw" Wilson

    "A community of scholars should not have to build walls as high as the sky to protect a reasonable expectation of privacy [msw: or 'security'], particularly when such walls will equally impede the free flow of information.

    There is a reasonable trust between scholars in the pursuit of knowledge, a trust upon which the users of the Internet have relied for many years.

    #FreeSoftware #OpenSource #FOSS #OSS #InfoSec #XZ

    In conversation about a year ago from mstdn.social permalink
  15. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Tuesday, 09-Apr-2024 11:27:24 JST Matt "msw" Wilson Matt "msw" Wilson
    in reply to

    This policy of trust has yielded significant benefits to the computer science community and, through the contributions of that community, to the world at large.

    Violations of such a trust cannot be condoned. Even if there are unintended side benefits, which is arguable, there is a greater loss to the community as a whole."

    - The Cornell Commission: On Morris and the Worm

    https://dl.acm.org/doi/10.1145/63526.63530

    #FreeSoftware #OpenSource #FOSS #OSS #InfoSec #XZ

    In conversation about a year ago from mstdn.social permalink
  16. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Tuesday, 09-Apr-2024 11:27:23 JST Matt "msw" Wilson Matt "msw" Wilson
    in reply to

    Given the latest attack on the Internet through persistent threat actors via xz-utils, what demands will be placed on the community of scholars (including Free and Open Source software developers) that build the software we all use and enjoy as digital public goods?

    Will they be "walls as high as the skies?"

    #FreeSoftware #OpenSource #FOSS #OSS #InfoSec #XZ

    In conversation about a year ago from mstdn.social permalink
  17. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Tuesday, 26-Mar-2024 14:46:08 JST Matt "msw" Wilson Matt "msw" Wilson
    in reply to

    I don't speak for either community effort, though I've been freely sharing my personal opinions with both efforts. 😅

    I wouldn't advise going with the CNCF unless you're happy with the policies that are already established (including the IP policy and project incubation / graduation process).

    I can't see how those policies and practices are a good fit for either community.

    In conversation about a year ago from mstdn.social permalink
  18. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Tuesday, 26-Mar-2024 14:46:00 JST Matt "msw" Wilson Matt "msw" Wilson
    • Matt "msw" Wilson
    • Michael Kinder

    @michael @msw I will place my bet on the project that attracts the most previously active contributors. Personally speaking I don’t think Drew’s fork will be it.

    In conversation about a year ago from mstdn.social permalink
  19. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Sunday, 24-Mar-2024 16:40:00 JST Matt "msw" Wilson Matt "msw" Wilson
    in reply to

    Wow, what an overwhelming community response in this PR. It is not a surprise when something like #Redis has become so loved by its community. There’s a clear sentiment that with this change it has been taken away.

    I encourage folks to support #OpenSource maintainers who were doing the hard work as individuals. They didn’t ask for any of this disruption in their lives. They exist and their efforts matter.
    #FOSS #OSS #FreeSoftware
    https://github.com/redis/redis/pull/13157#issuecomment-2014355620

    In conversation about a year ago from mstdn.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      Change license from BSD-3 to dual RSALv2+SSPLv1 by K-Jo · Pull Request #13157 · redis/redis
      Read more about the license change here: Redis Adopts Dual Source-Available Licensing Live long and prosper 🖖
  20. Embed this notice
    Matt "msw" Wilson (msw@mstdn.social)'s status on Friday, 22-Mar-2024 15:35:19 JST Matt "msw" Wilson Matt "msw" Wilson
    • Trolli Schmittlauch 🦥
    • ocdtrekkie
    • Matt "msw" Wilson
    • Theuni
    • scott
    • Atemu

    @ariadne @ocdtrekkie @theuni @schmittlauch @wwahammy @scott @msw @Atemu for the avoidance of doubt: Amazon is very clearly not an “open source company” and its branding has never claimed to be.

    In conversation about a year ago from mstdn.social permalink
  • Before

User actions

    Matt "msw" Wilson

    Matt "msw" Wilson

    Socio-technical Systems Engineer at #Amazon | Free and Open Source (#FOSS) Advocate | he/him/they/them | Opinions: my own

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          25406
          Member since
          13 Nov 2022
          Notices
          87
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.