OSP
前往频道在 Telegram
1 393
订阅者
无数据24 小时
-37 天
-1830 天
帖子存档
1 393
Ente
..."Ente is a service that provides a fully open source, end-to-end encrypted platform for you to store your data in the cloud without needing to trust the service provider.
On top of this platform, we have built two apps so far:
Ente Photos (an alternative to Apple and Google Photos) and
Ente Auth (a 2FA alternative to the deprecated Authy)."
GitHub
1 393
FreeDOS Founder Jim Hall: After 30 Years, What I've Learned About Open Source Community
By | the old-OS dept |
[...] "the larger lesson is that "Open Source projects must be grounded in community." Without open doors for new ideas and ongoing development, even the most well-intentioned project becomes a stagnant echo chamber...Maintain open lines of communication... This can take many forms, including an email list, discussion board, or some other discussion forum.
Other forums where people can ask more general "Help me" questions are okay but try to keep all discussions about project development on your official discussion channel.
The last of its seven points stresses that "An Open Source project isn't really Open Source without source code that everyone can download, study, use, modify and share" (urging careful selection for your project's licensing).
But the first point emphasizes that "It's more than just code,"
" [...]
#FreeDOS_Founder #Jim_Hall #After_30_Years What_I've #Learned_About #Open_Source_Community
1 393
Cisco helps Simprints take face biometrics open-source
By | Masha Borak |
[...] "Simprints’ solutions have been used in cash and aid distribution programs in Nigeria, Somalia and Kenya.
The company is also working with health authorities in Ethiopia, Uganda, Ghana, Bangladesh and India’s state of Rajasthan.
Among its projects are an electronic community health information system (eCHIS) in Ethiopia and vaccination drives in Uganda." [...]
[...] "The technology conglomerate has been working with Simprints since 2018 as part of a corporate social responsibility program called One Billion Lives.
At the time, Simprints was testing mobile phone camera-based facial biometrics as an alternative to their existing fingerprint biometric solution." [...]
#Cisco #Simprints #Face_Biometrics #Open_Source
1 393
Majority of Critical Open Source Projects Contain Memory Unsafe Code
By | James Coker |
[...] "More than half (52%) of critical open source projects contain code written in a memory-unsafe language, according to a new analysis by the Cybersecurity and Infrastructure Security Agency (CISA) in collaboration with government agency partners from Australia and Canada.
The Exploring Memory Safety in Critical Open Source Projects joint report investigated the scale of memory safety risk in open source software.
It analyzed a list of 172 projects derived from the Open Source Security Foundation (OpenSSF) Securing Critical Projects Working Group’s List of Critical Projects.
The report concluded that most critical open source projects potentially contain memory safety vulnerabilities.
This is a result of direct use of memory unsafe languages or external dependency on projects that use memory-unsafe languages.
The agencies observed that 55% of the total lines of code (LoC) for all projects were written in a memory-unsafe language.
These projects include operating system kernels and drivers, cryptography and networking." [...]
[...] "Security Risks from Memory Unsafe Languages
The new analysis follows a White House report published in February 2024, which called on the tech industry to adopt memory safe programming languages.
The Office of the National Cyber Director (ONCD) report cited research showing that up to 70% of Common Vulnerabilities and Exposures (CVE) relate to memory safety issues, such as buffer overflows, which could be eliminated by adopting memory safe programming languages, such as Rust.
Currently, the majority of code is written in memory unsafe languages, like C and C++. This means such code is generating substantial patching and incident response costs for software manufacturers and consumers." [...]
#Critical #New_Analysis #Open_Source_Projects #Contain_Code #Memory_Unsafe_Language
1 393
SAP New Open Source Manifesto
By | Michael Ameling |
"SAP is proud to announce the publication of its open source manifesto, reinforcing our commitment to open source principles and community engagement.
The manifesto aligns with SAP’s established presence as a key contributor to open source: SAP currently ranks as one of the top ten commercial contributors globally on GitHub in the OSCI.
Expanding open source innovation Read our open source manifesto
Open Innovation and Collaboration
“Our open source manifesto is more than a declaration of our current contributions; it’s a promise to continue driving open innovation and collaboration at a significant scale,” said Juergen Mueller, chief technology officer and member of the Executive Board of SAP SE.
“By embracing open source, we not only accelerate our own innovation but also empower our customers and partners to build on a foundation of transparency, security, and shared success.” "[...]
#SAP #Open_Source
#New #Manifesto #Principles #Community_Engagement
1 393
In Depth: China Debates Pros and Cons of Open-Source AI Models
By | Liu Peilin | and | Ding Yi |
"When discussing the development of large language models (LLMs)
Zhou Hongyi, CEO of Chinese cybersecurity firm 360 Security Technology Inc.,
dismissed claims that open-source LLMs are inferior to closed-source ones, calling such assertions “nonsense.”
Zhou’s comments, which were delivered during the 27th Harvard College China Forum in April,
were widely seen as a response to Baidu Inc.’s CEO Robin Li,
who had previously said that it did not make sense for LLMs to be open-source and that closed-source LLMs would gain an expanding edge in capabilities as technology advances." [...]
#LLMs #Large_Language_Models
#Open_Source #Closed_Source #Development #Capabilities
1 393
Daytona secures $5M for open-source SaaS customisation
By | Lucy Adams |
[...] "The company has recently created an open source version geared toward individual developers that has seen strong demand, garnering 5,000 GitHub stars in two months.
Daytona initially emerged as a solution tailored for large enterprises, enabling their developers to automate tasks, collaborate effortlessly, and enhance productivity albeit while adherent to enterprise security needs.
Recognizing the importance of extending these benefits beyond large organizations, it has open sourced key components of its enterprise platform to empower the individual developers with the same streamlined development experience.
One persistent challenge in the developer community is that inconsistent development environments lead to significant productivity losses.
According to IEEE Journal, developers lose 56% of their productive time due to inefficient environments.
Daytona addresses this issue head-on by allowing any developer to create a fully working environment with a single command, “daytona create.” "[...]
#Daytona #Open_Source #SaaS_Customisation
1 393
Haiqu Releases Open-source Quantum Computing Toolkit
By | Matt Swayne |
"Insider Brief
• Haiqu announces the release of its new open-source toolkit called Rivet.
• Rivet empowers developers with flexibility and performance in their quantum computing workflows by significantly reducing transpilation bottlenecks.
• The software provides the necessary tools to streamline workflows and run effective algorithms on quantum computers." [...]
[...]" “Richard Givhan, CEO and Founder of Haiqu, commented:
“In our QML research, we found that existing libraries do not allow for fast, controlled, and noise-aware transpilation of parametrized circuits.
We developed Rivet internally to minimize the time/money spent on high-volume, high-quality transpilation. We are open-sourcing it to make others’ research a little more efficient.”
Haiqu’s Rivet allows users to select the transpiling stack of their choice, for their entire circuit or just a section.
It currently supports Qiskit, BQSKit and Pytket, and will continue to expand its supported stacks.
For more details on Rivet, you can find it on GitHub here.
[...]
#Haiqu #Rivet #Open_Sourcing #Quantum_Computing #Transpilation_Bottlenecks
1 393
Not all ‘open source’ AI models are actually open: here’s a ranking
By | Elizabeth Gibney |
"Many of the large language models that power chatbots claim to be open, but restrict access to code and training data.
Truly open-source models should allow researchers to replicate and interrogate them.
Technology giants such as Meta and Microsoft are describing their artificial intelligence (AI) models as ‘open source’ while failing to disclose important information about the underlying technology, say researchers who analysed a host of popular chatbot models.
The definition of open source when it comes to AI models is not yet agreed, but advocates say that ’full’ openness boosts science, and is crucial for efforts to make AI accountable.
What counts as open source is likely to take on increased importance when the European Union’s Artificial Intelligence Act comes into force.
The legislation will apply less strict regulations to models that are classed as open.
Some big firms are reaping the benefits of claiming to have open-source models, while trying “to get away with disclosing as little as possible”, says Mark Dingemanse, a language scientist at Radboud University in Nijmegen, the Netherlands. This practice is known as open-washing." [...]
#AI_Models #LLMs #Open_Source #Open_Washing
1 393
THE POWER OF FOSS
By | US ARMY |
[...] "Imagine FOSS as a massive warehouse with digital building blocks such as code, libraries and complete frameworks.
These building blocks can be assembled into custom solutions tailored to unique operational needs.
A scenario could include a unit operating in a region with limited connectivity where commercial communication systems might falter, causing isolation. In such cases, FOSS enables tech-savvy Soldiers to use open-source technologies to build and deploy a code solution, re-establishing communications systems and moving away from antiquated pen and paper solutions, which are often not scalable.
In an isolated operational environment, using Jenkins would enable the unit to continuously integrate and deploy software once it has been updated for security vulnerabilities or enhanced with new features. The source code for these updates could be managed and version-controlled in a Git repository, hosted on a local server within the unit’s network.
This setup ensures that even in disconnected or bandwidth-limited situations, the unit can maintain up-to-date software, enhancing operational effectiveness and cybersecurity resilience. Then the solution can be better codified by a software factory or used as a prototype for a contractable solution.
The power of FOSS extends far beyond rapid prototyping, unlocking Soldier-driven innovation. A Soldier working in logistics may have an idea for streamlining supply chain management. Instead of filing a suggestion report for the currently used software and hoping for the best, they can use FOSS frameworks such as Angular and Django to create a proof of concept.
Angular’s robust front-end development capabilities can facilitate the creation of an intuitive user interface for tracking and managing supplies in real time.
Concurrently, Django, with its efficient back-end structure, can be used for complex data processing and integration with existing military databases. The application may perform some lightweight tasks, which could be containerized with Docker or Kaniko. These tools allow the application to be standardized and isolated from its environment, making it portable and consistent across any computing platform.
The application can then be deployed and shared with other units, giving them the ability to deploy the application in a Kubernetes cluster or other container orchestration services.
Kubernetes, a popular orchestration system, manages the deployment, scaling and operations of these containers across a cluster of virtual machines.
Putting this power in the hands of Soldiers in the battlefield leverages the power of innovation and FOSS.
This approach fosters an environment where the best ideas are given space and tooling to be developed and deployed by Soldiers who will use them on the front lines." [...]
[...] "CONCLUSION
Integrating FOSS in military operations is not just about technological advancement. It signifies a fundamental shift toward a more agile, innovative and technologically proficient military force.
The Army’s new software policy and the growing recognition of FOSS’s value herald a future where military innovation is continuous, collaborative and deeply integrated into defense strategies. As our adversaries also navigate the digital terrain, leading the race to harness the full spectrum of technological innovation will be critical in defining the future of military supremacy.
For more information on open-source software, go to https://dodcio.defense.gov/Open-Source-Software-FAQ/#q-isnt-using-open-source-software-oss-forbidden-by-dod-information-assurance-ia-policy." [...]
#FOSS #Open_Source #Angular #Django #Docker #Kaniko #Prototype_Technologies
1 393
Repost from cRyPtHoN™ INFOSEC (EN)
Tor Browser 13.5 brings Android enhancements, better bridge management
The Tor Project has released Tor Browser 13.5, bringing several improvements and enhancements for Android and desktop versions.
The Tor Browser is a specialized open-source web browser designed for anonymous browsing by routing the user's traffic through thousands of volunteer-run servers called nodes/relays, which constitute the Tor network.
https://www.bleepingcomputer.com/news/security/tor-browser-135-brings-android-enhancements-better-bridge-management/
https://blog.torproject.org/new-release-tor-browser-135/
📡@cRyPtHoN_INFOSEC_IT
📡@cRyPtHoN_INFOSEC_FR
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_DE
📡@BlackBox_Archiv
1 393
Cilium: Open-source eBPF-based networking, security, observability
By | HELPNET SECURITY |
"Cilium is an open-source, cloud-native solution that leverages eBPF technology in the Linux kernel to provide, secure, and monitor network connectivity between workloads.
What is eBPF?
eBPF is a technology originating from the Linux kernel that allows sandboxed programs to run in a privileged context, such as the operating system kernel.
It extends the kernel’s capabilities safely and efficiently without modifying the kernel source code or loading kernel modules.
Cilium features
Cilium offers a flat Layer 3 network extending across multiple clusters, supporting native routing and overlay modes.
It knows Layer 7 protocols and can enforce network policies from Layer 3 to Layer 7 using an identity-based security model decoupled of network addressing.
Cilium provides distributed load balancing for traffic between pods and to external services, capable of replacing kube-proxy by using eBPF hash tables for nearly unlimited scalability.
It also supports advanced features such as integrated ingress and egress gateways, bandwidth management, and service mesh, and offers comprehensive network and security visibility and monitoring.
Cilium is available for free on GitHub." [...]
#Cilium #eBPF_Based #Networking #Security #Observability #For_Free #Github #Open_Source
1 393
Repost from TermuxIL Crypto World
Crypto Security Firm Ironblocks Builds 'Firewall' for DeFi Protocols
By | Danny Nelson |
"
Blockchain security platform Ironblocks' new tool is a free service for developers who want to add security to their smart contracts,
CEO Or Dadosh told CoinDesk. Called Firewall, it allows them to plug-and-play various security "policies" to monitor transactions on their decentralized finance protocols for suspicious attempts.
The open-source toolkit could offer at least some salve to the ever-present threat of hacks in DeFi.
Dadosh estimated any given week brings with it as many as 10 different hacks of protocols offering lending, trading, staking or other financial services to crypto holders.
Those heists add up: PeckShield estimated $60 million in losses in April.
Firewall sits inside the smart contracts processing protocols' transactions, Dadosh said.
Developers get their pick of a handful of policies that scour the flow for sketchy patterns and other tells that a hack is in progress.
"It doesn't stop or pause the application, it just stops the specific transaction that may attack the application, just like in web2 firewalls," Dadosh said." [...]
#Ironblocks #Firewall #DeFi_Protocols #Crypto_Security1 393
Sniffnet: Free, open-source network monitoring
By | Mirko Zorz | Director of Content, Help Net Security
"Sniffnet is a free, open-source network monitoring tool to help you easily track your Internet traffic. What sets it apart is its strong focus on user experience.
Unlike most network analyzers, Sniffnet is built to be easily usable by everyone, regardless of technical expertise.
“There are different features that make Sniffnet stand out.
First, it’s very rare to see a GUI application entirely developed in Rust. From a usability standpoint, the tool is unique in its ease of use.
Network analyzers are typically complex and intended for network administrators, but my app aims to be easily usable by beginners,” Giuliano Bellini, the creator of Sniffnet, told Help Net Security.
Sniffnet features
• Choose a network adapter on your PC to inspect.
• Select filters to apply to the observed traffic.
• View statistics about your Internet traffic.
• See real-time charts of traffic intensity.
• Monitor your network even when the application is minimized.
• Export comprehensive capture reports as PCAP files.
Identify over 6000 upper layer services, protocols, Trojans, and worms.
• Discover the domain name and ASN of the hosts you’re exchanging traffic with.
• Identify connections within your local network.
• Find the geographical location of remote hosts.
• Save your favorite network hosts.
• Inspect each of your network connections in real-time.
• Set custom notifications for defined network events.
• Choose the style that suits you best, including custom themes support.
Sniffnet
natively includes MMDB databases that provide insights about observed IP addresses. Specifically, the app includes the following databases:
IP to country MMDB, and IP to ASN MMDB. The embedded databases are the free version of MaxMind GeoLite2 databases.
However, you can also use your own MMDB files as well. This feature can be useful in various scenarios:
• You own the commercial version of these databases, which offers greater accuracy.
• You want to update the databases frequently without waiting for a new version of Sniffnet.
• You prefer to use a different database provider for your analysis.
Future plans and download
Some of the features coming in upcoming versions include malicious traffic detection, PCAP file import, firewall capabilities, an agent for remote host monitoring, and a web interface.
Sniffnet is available for free on GitHub. It’s available for Linux, Windows, and macOS." [...]
@OSPopensourceplanet
#Sniffnet #Open_Source #Network_Monitoring #Internet_Traffic1 393
Scientists find security risk in RISC-V open-source chip architecture that China hopes can help sidestep US sanctions
By | Zhang Tong | in Beijing
"• Northwestern Polytechnical University, a major defence research institute in China, confirmed flaw which allows attackers to bypass security protections
• US lawmakers reportedly consider sanctions to restrict RISC-V access because of concerns of rapid technology transfer and Chinese adoption of architecture
A Chinese research team says it has uncovered a significant security flaw in processor design that could have a wide impact on China’s booming domestic chip industry.
China was relying on the structure of the world’s largest open-source CPU architecture to build their own CPUs and bypass the US chip ban, and was paying attention to any weaknesses, they said." [...]
1 393
#Podcast
Be prepared for open source software risks | TechTarget
https://www.podbean.com/ep/pb-8ek9c-1608bd0
By Nicole Laskowski | Beth Pariseau |
Published: 03 Jun 2024
"Companies need to prepare for the risks and responsibilities of using open source software, according to Chainguard's Dan Lorenc. Nothing is ever completely free.
Dan Lorenc, co-founder and CEO of Chainguard, doesn't believe "tragedy of the commons" is an accurate label for what's happening today with open source software.
"It's an easy analogy to make because you see open source as something everyone depends on but no one is incentivized to maintain," he tells TechTarget Editorial's Beth Pariseau in Episode 7 of IT Ops Query: Tech's Tragedy of the Commons.
But unlike a commons such as public park, where overuse can diminish the resource, open source software doesn't deteriorate the more it's downloaded.
That said, Lorenc, who is also a member of the OpenSSF Technical Advisory Committee, doesn't overlook the inherent risks that come with using open source software, especially in terms of sustainability and liability.
Although the source code might be free, there is no such thing as a free lunch, he said.
He thinks companies should consider and plan for maintenance given that a vulnerability could have crippling effects on business operations and national security.
"Make sure you know what you're adopting. Make sure you know that it's sustainably developed or not.
And have a plan for what to do in case maintenance does slow down or isn't up to the standard you have," he said. "And that plan can't be just file angry GitHub issues and yell at the maintainers."
Governments, too, are focused on open source software maintenance.
But the work on this front is tricky, given the lack of a software warranty for open source and the constraints around free speech." [...]
1 393
Chronon: Open-source data platform for AI/ML applications - Help Net Security
By | Mirko Zorz | Director of Content, Help Net Security
"Chronon is an open-source, end-to-end feature platform designed for machine learning (ML) teams to build, deploy, manage, and monitor data pipelines for machine learning.
Chronon enables you to harness all the data within your organization, including batch tables, event streams, and services, to drive your AI/ML projects without the need to manage the typically required orchestration.
Key features:
Consume data from various sources, including event streams, DB table snapshots, change data streams, service endpoints, and warehouse tables modeled as slowly changing dimensions, fact, or dimension tables.
Produce results in both online and offline contexts. Online, as scalable low-latency endpoints for feature serving, or offline as hive tables for generating training data.
Real-time or batch accuracy: configure results to be either Temporal or Snapshot accurate.
Temporal accuracy updates feature values in real-time in online contexts and produces point-in-time correct features offline. Snapshot accuracy updates features once daily at midnight.
Backfill training sets from raw data without waiting months to accumulate feature logs for model training.
Utilize a powerful Python API: data source types, freshness, and contexts are API-level abstractions composed of intuitive SQL primitives like group-by, join, and select, with powerful enhancements.
Automate feature monitoring: auto-generate monitoring pipelines to understand training data quality, measure training-serving skew, and monitor feature drift.
Chronon is available for free on GitHub."
[...]
