es
Feedback
OSP

OSP

Ir al canal en Telegram

OSP (Open Source Planet) ערוץ שכולו קוד פתוח בשיתוף @termuxisrael2

Mostrar más
1 393
Suscriptores
Sin datos24 horas
-37 días
-1830 días
Archivo de publicaciones
OSP
1 393
SUSE CEO: "If you want secure software, it has to be open source By | ERIK VAN KLINKEN | "Dirk-Peter van Leeuwen has been CEO
SUSE CEO: "If you want secure software, it has to be open source By | ERIK VAN KLINKEN |
"Dirk-Peter van Leeuwen has been CEO at SUSE since May 2023. Since then, the IT world has been rocked by AI, open source struggles and sweeping cost savings campaigns. The SUSE CEO views the future with confidence, but, “Under competitive pressure, decisions are often made without enough care.”
[...] "In the infrastructure world of SUSE, the current, slightly less-derided bogeyman is Red Hat. Last year, it shut down the source code to the widely used Red Hat Enterprise Linux (RHEL) – much to the concern and annoyance of the open source community, which gratefully used free RHEL alternatives that built on Red Hat’s work. CentOS Linux, Red Hat’s free RHEL variant, was used 20 times more than the paid-for RHEL, but that distribution has since been discontinued. Alternatives like Alma Linux and Rocky Linux had to fork, while SUSE announced it would do the same backed by a $10 million investment. To top it off, Red Hat ended support for RHEL 7 as of June 30 of this year. However, SUSE has since offered a way out for all RHEL and CentOS users" [...] #SUSE #CEO #Secure_Software #Has_to_Be #Open_Source

OSP
1 393
OpenCTI: Open-source cyber threat intelligence platform By | Help Net Security | "OpenCTI is an open-source platform designed
OpenCTI: Open-source cyber threat intelligence platform By | Help Net Security | "OpenCTI is an open-source platform designed to help organizations manage their cyber threat intelligence (CTI) data and observables." "The platform, developed by Filigran, structures its data using a knowledge schema built on the STIX2 standards. It features a modern web application architecture with a GraphQL API and a user-friendly front end. OpenCTI integrates with other tools and applications, such as MISP and TheHive, among others, enhancing its capability to serve as a central hub for cyber threat intelligence management. The objective is to develop a comprehensive tool that enables users to effectively capitalize on technical and non-technical data while ensuring that every piece of information is traceable back to its source. Key features include interlinking data points, tracking first and last-seen dates, assessing confidence levels, and more. The tool is integrated with the MITRE ATT&CK framework via a dedicated connector to assist in structuring the data, though users can also incorporate their datasets. Once analysts within OpenCTI have processed and curated the data, the tool can infer new relationships from the existing ones, enhancing the understanding and visualization of the information. This empowers users to extract valuable insights and leverage meaningful knowledge from the raw data. Download OpenCTI is available for free on GitHub. All components are shipped as Docker images and manual installation packages. For a production deployment, the developers recommend deploying all components in containers, including dependencies, using native cloud services or orchestration systems such as Kubernetes." #OpenCTI #Open_Source #Cyber_Threat_Intelligence #Platform

OSP
1 393
Beyond the Walled Garden of Open Source By | Jonathan Marsh | [...] "A company might publish open source not for direct profi
Beyond the Walled Garden of Open Source By | Jonathan Marsh |
[...] "A company might publish open source not for direct profit but to build industry mind-share around their brand or point of view, to shake up a market by putting pressure on competitive technologies, or to incubate an ecosystem to improve innovation or keep development and maintenance costs down."
"An individual or organization might publish as open source simply to share something of interest or to contribute to the sphere of human knowledge — this could be a research project, tests, or a product that has ended its commercial life but is still in use by specific users. It would serve those who promote open source to consider openness in broader terms, beyond viewing open source as a walled garden in which everything inside is deemed “open” and everything outside is not. Instead, openness should be considered in a broader context and encouraged as much as possible outside the officially recognized open source licensing context.  To do so requires appreciating and accommodating the diversity of values and motives of the publisher. With that viewpoint, new possibilities can arise:" [...] #Beyond #Walled_Garden #Open_Source #Competitive_Technologies #Incubate_Ecosystem #Improve_Innovation

OSP
1 393
Record You (Privacy focused voice and screen recorder app build with MD3) https://f-droid.org/packages/com.bnyro.recorder/

OSP
1 393
Record You (Privacy focused voice and screen recorder app build with MD3) "Record You is a voice and screen recorder app buil
Record You (Privacy focused voice and screen recorder app build with MD3)
"Record You is a voice and screen recorder app built with Material Design 3 (You). It supports multiple audio formats and codecs, such as M4A, AAC and OPUS.
Record You uses SAF (Storage Access Framework), thus it doesn't require any storage permissons. It doesn't have any dependencies apart from the Android base and Material design libraries, therefore the app is very lightweight." #Record_You #Privacy_Focused #Voice_and_Screen #Recorder_app #Build_With #MD3 #Material_Design_3 #F_Droid

OSP
1 393
Sourcegraph makes core repository private, co-founder complains open source means "extra work and risk" By | Tim Anderson | "
Sourcegraph makes core repository private, co-founder complains open source means "extra work and risk" By | Tim Anderson |
"Sourcegraph has removed the formerly open source core repository for its popular code search product from public view – with CEO and co-founder Quinn Slack saying open source makes little sense for “full server-side end-user applications” and adds “extra work and risk”.
[...] "Slack now says that the code will no longer be public, though there is a public snapshot of the repository just before it became private. Slack gave reasons for the change including keeping “very differentiated” code secret, hiding code intended to prevent abuse, and that removing the open source license enabled new revenue streams with cloud providers and other resellers." [...] "Slack replied that the index still includes almost a million repositories but that many had been removed because “it was very complex to keep up with millions of repositories due to GitHub rate limits and scaling.” In particular, repositories with few GitHub stars have been removed." [...] #Sourcegraph #Makes #Core_Repository_Private #Co_Founder #Complains #Open_Source #Means #Eextra_work #Risk

OSP
1 393
Descent 3 open source project gets a first release | GamingOnLinux By | Liam Dawe | "After getting open sourced back in April
Descent 3 open source project gets a first release | GamingOnLinux By | Liam Dawe | "After getting open sourced back in April and now run as a community project, the Descent 3 open source engine has a first release available. You do need a copy of the game to run it which you can get from GOG and Steam." [...]
[...] "Also now available is a roadmap towards the next release which includes plans for a graphics renderer rewrite to use more modern OpenGL, support for higher screen resolutions, localization support"
#Descent3 #Open_Source_Project #First_Release #Game

OSP
1 393
Back to Basics: Licensing and Open Source By | David Sandy | [...] "We’ll Need to See Your License… Software licensing is reasonably complex, due to the fact that it ranges anywhere from completely open source to totally locked down. To make things simpler, let’s break down some of the more popular forms of licensing: Public Domain: This is the lowest rung on the protection ladder. If you don’t care what people do with your software and just want to get it out there for the world to see, use, and experience, this is the license for you. Lesser General Public License: LGPL is built more for libraries. Much like a Public Domain license, anyone is free to use your code and build it into their own; but, if a user modifies your code while it is under LGPL, their code will also fall under the terms of your LGPL license. Permissive: This is the halfway point on the protection tree. While it does allow for people to do some things with your software, you can lock down certain means of distribution or modification. Copyleft: LGPL is a weaker form of copyleft. Much like how LGPL works, you get to define how you want people to use your code, but once they incorporate it into their own code or modify it, they now are bound to your terms of use. Proprietary: Proprietary code is one of the most protected licenses you can get. If you don’t want people doing anything with your code without your permission, this is the license for you. Each of these licenses are built with a purpose in mind, and can be combined with other licenses to meet your needs. If you want to make money on your code, you can combine a commercial license with Copyleft to ensure that people don’t redistribute your code without you getting paid." [...] #Basics #Open_Source #Software_Licensing

OSP
1 393
Authentik: Open-source identity provider Authentik is an open-source identity provider designed for maximum flexibility and a
Authentik: Open-source identity provider Authentik is an open-source identity provider designed for maximum flexibility and adaptability. It easily integrates into existing environments and supports new protocols. It’s a comprehensive solution for implementing features like sign-up, account recovery, and more in your application, eliminating the need to manage these tasks manually. https://www.helpnetsecurity.com/2024/08/16/authentik-open-source-identity-provider/ 📡@cRyPtHoN_INFOSEC_IT 📡@cRyPtHoN_INFOSEC_FR 📡@cRyPtHoN_INFOSEC_EN 📡@cRyPtHoN_INFOSEC_DE 📡@BlackBox_Archiv

OSP
1 393
Repost from Hacker News
mpv a free, open-source, and cross-platform media player (🔥 Score: 151+ in 2 hours) Link: https://readhacker.news/s/6d4jy Comments: https://readhacker.news/c/6d4jy

OSP
1 393
TigerEye releases open-source DuckDB.dart to simplify data-intensive application development By | DUNCAN RILEY | ''TigerEye Labs Inc., an artificial intelligence-powered planning and revenue management platform company, today announced the open-source release of DuckDB.dart, a tool that helps developers build and run data-intensive applications more easily and efficiently. DuckDB.dart is a native Dart application programming interface for DuckDB that has been designed to simplify the creation of data-intensive applications for desktop and mobile platforms.  DuckDB is an in-process SQL database management system optimized for analytical queries on large datasets, designed to run efficiently within a single machine. DuckDB has grown increasingly popular over the last few years, particularly in data science and analytics communities, thanks to its high performance, ease of use and ability to handle large datasets efficiently in local environments, but it still requires certain skills to implement and extract data. The new DuckDB.dart is focused on making data analysis and simulation with DuckDB easier and more efficient. DuckDB.dart is built on DuckDB’s high-performance C APIs and introduces new Dart data types for quick and easy use. The service’s “columnar” format and vectorized query execution allow for faster downloads and more efficient data analysis and simulation while also reducing device memory usage.'' [...] #TigerEye #Open_Source #DuckDB #Dart #Simplify_Data_Intensive #Data_Analysis #SQL #Database_Management_System #Analytical_Queries  #Large_Datasets #Application_Development

OSP
1 393
Sparrow : An Innovative Open-Source Platform for Efficient Data Extraction and Processing from Various Documents and Images By | Niharika Singh | Sparrow enables the creation of independent LLM agents that can be called through an API to handle specific tasks. This flexibility makes it a valuable tool for organizations aiming to automate and optimize their data processing workflows. Sparrow demonstrates its effectiveness through several key metrics. For example, its use of advanced RAG (retrieval-augmented generation) pipelines significantly reduces the time required to extract and process data from both PDFs and images. The tool’s modular architecture ensures that it can handle various document types with consistent performance, regardless of the scale of data being processed. Sparrow’s ease of integration with existing workflows and its support for multiple formats further enhance its utility in diverse organizational settings. Furthermore, Sparrow’s support for both open-source and commercial use, along with its dual licensing options, ensures that it is available to a broad spectrum of users, from small companies to large corporations." #Sparrow #Open_Source_Platform #Data_Extraction #Documents_Images #Independent #LLM_Agent #API

OSP
1 393
Scout Suite: Open-source cloud security auditing tool By | Help Net Security | "Scout Suite is an open-source, multi-cloud security auditing tool designed to assess the security posture of cloud environments. By leveraging the APIs provided by cloud vendors, Scout Suite collects and organizes configuration data, making it easier to identify potential risks. Instead of manually sifting through numerous pages on cloud web consoles, Scout Suite automatically generates a comprehensive and clear overview of the attack surface, streamlining the security assessment process. Scout Suite was created by security consultants and auditors to deliver a security-focused, point-in-time snapshot of the cloud account in which it is executed. After the data is collected, all subsequent analysis and usage can be conducted offline. Currently, the following cloud providers are supported: • Amazon Web Services • Microsoft Azure • Google Cloud Platform • Alibaba Cloud (alpha) • Oracle Cloud Infrastructure (alpha) • Kubernetes clusters on a cloud provider (alpha) • DigitalOcean Cloud (alpha) Scout Suite is available for free on GitHub." [...] #Scout_Suite #Open_Source #Cloud_Security #Auditing_Tool #Automatically_Generates #Comprehensive #Clear_Overview #Attack_Surface

OSP
1 393
Open source tools to boost your productivity By | Paul Sawers, Ivan Mehta | #Open_Source_Tools #Boost_Your_Productivity #Escape_Proprietary_Clutches

OSP
1 393
cables .gl, free visual programming: now open source, offline By | Peter Kirn | cables.gl is a wonderful creative environment for everything the browser can do visually – interaction, motion, and 3D. And now it sports a full open source MIT license and a version you can download and use offline. cables.gl I’ve raved about for some time as an essential addition to the arsenal of anyone working with interaction design, digital media and digital art, and live visuals. I know it’s easy to get bogged down in the sheer number of tools that are out there now – an astounding number that is even free or has at least some basic community/free license. But the reality is, once you get comfortable with tools ranging from TouchDesigner to Three.js JavaScript coding, you can move fairly comfortably from tool to tool to hack what you need, especially when prototyping. So you might well try something quickly with a collaborator with cables.gl before diving into full-blown custom code or patching.'' [...] #cables_gl #Free_Visual_Programming #Now #Open_Source_Offline

OSP
1 393
SSHamble: Open-source security testing of SSH services By | Help Net Security | "runZero published new research on Secure Shell (SSH) exposures and unveiled a corresponding open-source tool, SSHamble. This tool helps security teams validate SSH implementations by testing for uncommon but dangerous misconfigurations and software bugs." [...] [...] "As one of the most common remote administration services, SSH is widespread; it is found in every major operating system, embedded in many applications, and enabled by default in cloud environments. Researchers uncovered new SSH authentication bypass issues, information leaks, and misconfigurations. SSH vulnerabilities were also identified in various products, including a significant regression in OpenSSH for Microsoft Windows. Additional SSH vulnerabilities were identified in Digi International ICS gateways, Panasonic ethernet switches, Realtek-based ADSL routers, Ruckus wireless access points, common Git-based development tools like Soft Serve and GOGS, and various consumer-focused networking equipment. In some cases, vendors have made patches available." [...] #SSHamble #Open_Source #Security_Testing #Validate_SSH_Implementations #SSH_Services

OSP
1 393
5 best open-source email clients for Linux (and why Geary is my go-to) By | Jack Wallen | "I've used every open-source email client available. These are the best of the best. I might be a dinosaur, but email is still my jam. I prefer communicating via email to any other means of interaction (other than face-to-face). Email is efficient, used globally, isn't OS-dependent, and allows me to catalog and organize my inbox as I see fit, even retaining years of searchable communications. In a nutshell, I depend on email." [...] #5_Best #Open_Source #Email_Clients #Linux #Geary

OSP
1 393
Can AI even be open source? It's complicated By | Steven Vaughan-Nichols | "AI can't exist without open source, but the top AI vendors are unwilling to commit to open-sourcing their programs and data sets. To complicate matters further, defining open-source AI is a messy issue that has yet to be settled. Without open source, there is no artificial intelligence (AI). Period. End of statement.  It's not just that AI's early roots spring from the 1960s' open language Lisp; the headline AI generative models, such as ChatGPT, Llama 2, and DALL-E, are built on solid, open-source foundations. However, those models and programs themselves are not open source." [...] #Can_AI_Even #Be_Open_Source #Its_Complicated

OSP
1 393
Repost from Hidden Links
TrueCrypt – Free Open-Source On-The-Fly Disk Encry http://jw545nmps6xzusfhhct5t64agtnsrujppbfvfwzwxtfmpjfzu645i5ad.onion Cate
TrueCrypt – Free Open-Source On-The-Fly Disk Encry http://jw545nmps6xzusfhhct5t64agtnsrujppbfvfwzwxtfmpjfzu645i5ad.onion Category: #Other /////////// For info purpose only, use VeraCrypt instead \\\\\\\\\\\

OSP
1 393
כך סין עוקבת אחר ספינות מלחמה אמריקאיות באמצעות תמונות לוויין גלויות https://i-hls.com/he/archives/124717 ''טכניקה חדשה לאיסוף מודיעין ימי בסין עושה גלים: באמצעות שימוש בתמונות לוויין ברזולוציה נמוכה ממקורות גלויים, צוות של חוקרים סינים טוען כי הצליח לזהות ספינות מלחמה אמריקאיות שאחרת אינן ניתנות לגילוי באמצעות כלים הנגישים לציבור הרחב. כפי שדווח ב-Interesting Engineering, הצוות, בראשות הונג ג'ון מהאקדמיה הימית של דליאן, הצליח לפתח אלגוריתם שהיה מסוגל לזהות נושאת מטוסים אמריקאית מסוג נימיץ וספינות מלחמה אחרות מתוך תמונות לווין בעלות רזולוציה נמוכה ביותר, של עשרות או מאות מטרים, כך שהספינה נראית בה כמעט בלתי-נראית. השיטה של הצוות מתבססת על בחינת דפוס האדוות שנוצר סביב כלי השיט שונים בהפלגתם, וכי דפוסים אלה ייחודיים לספינה שיוצרת אותם. מאחר שתבנית האדוות של כלי השיט יכולה להימתח לאורך עשרות קילומטרים, הצוות יכול להשתמש אפילו בתמונות ברזולוציה נמוכה כדי לזהות את הספינות הללו. המחקר שלהם, שפורסם באפריל בכתב העת Computer Simulation, מתאר את הפרמטרים הפיזיים הנחוצים לזיהוי מדויק של דגמי ספינות ספציפיים. אף על פי שאורך האדוות שהספינה יוצרת יכול להתפרש על פני עשרות קילומטרים, חילוץ נתונים שימושיים מתמונות לוויין אלה עלול להיות מאתגר בשל הפרעות בסביבה כמו עננים וגלים, אשר יכולים להסתיר סממנים מזהים בשובל הייחודי של הספינה. מדובר באתגר גדול שהקבוצה הייתה צריכה להתגבר עליו. על אף שמעקב-גלים הינה טכניקה שכוחות ימיים השתמשו בה במשך עשרות שנים, הגישה של סין היא חדשנית כי היא משתמשת בתמונות ברזולוציה נמוכה, מה שלא היה קיים לפני כן. עם זאת, מגבלות השיטה כוללות זמינות מוגבלת של תמונות בזמן אמת, והיא מתקשה עם כלים הנעים במהירות, והצוות שואף לשפר זאת. סין, שסביר להניח שיש לה יכולות איסוף מודיעין מתקדמות, כולל רשת נרחבת של לוויינים, כנראה לא צריכה לקבל מודיעין ימי מתמונות ברזולוציה נמוכה ממקורות גלויים. עם זאת, השיטה יכולה להיות בעלת ערך רב עבור מדינות עם פחות משאבי לוויין ממנה.''