Aristotelis Tzafalias

@aristot73@infosec.exchange
78 Followers
249 Following
372 Posts
If AI is so great finding bugs, will vendors come forward with a "all bugs found" guarantee with high penalties enforced if bugs found in the same code base? With real skin in the game is how we will see if they walk the talk :-]

If you are a #FreeSoftware manufacturer, project, or a potential steward under the Cyber Resilience Act #CRA , please contribute by filling out those surveys (best already by end of July):

Potential Free Software stewards (EN)
https://dialog-cybersicherheit.limesurvey.net/146965?lang=en

Free Software projects (EN)
https://dialog-cybersicherheit.limesurvey.net/241948?lang=en

Manufacturer (EN)
https://dialog-cybersicherheit.limesurvey.net/582853?lang=en

Questionnaire for potential OSS Stewards in terms of CRA

Currently hearing from @davidawheeler of the @openssf about the recently-published "Cyber Resilience Act (CRA) Brief Guide for Open Source Software (OSS) Developers" https://best.openssf.org/CRA-Brief-Guide-for-OSS-Developers On the OpenSSF's "CRA Tech Bi-Weekly" call. I'm so glad my contribution ("Don't Panic!") made it in.

Anyone can join these calls, by the way if you want to learn more about the CRA and how it might apply to your work. Visit https://github.com/ossf/wg-globalcyberpolicy#meeting-times to find out more about how to get involved.

Cyber Resilience Act (CRA) Brief Guide for Open Source Software (OSS) Developers

The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.

OpenSSF Best Practices Working Group

Want to influence the rules for vulnerability handling for every internet-connected product sold in the EU? Of course you do!

You are invited to the vulnerability handling deep dive session for the Cyber Resilience Act. July 22, online, free registration:

https://www.stan4cra.eu/event-details/deep-dive-session-vulnerability-handling

More info: https://www.stan4cra.eu/resources

#CRA #InfoSec

Deep dive session: Vulnerability Handling | Stan4cr

Stan4cr
The G in AGI stands for group think.
Spanish ‘development aid to the #Sahel countries has tripled, and the budget of the Spanish Agency for International Development Cooperation has doubled from €360 to €700 million.’ 👏 https://www.lamoncloa.gob.es/lang/en/presidente/news/Paginas/2024/20241009-appearance-lower-house.aspx
Pedro Sánchez: "Welcoming the outsider is not only a duty, but a step towards guaranteeing the welfare state"

Lower House of Parliament, Madrid, 09 October 2024. The President of the Government of Spain has vindicated the executive"s "humanitarian and responsible" migration policy, announcing measures to improve migrant integration and to promote their contribution to the demographic challenge.

It has officially begun. The CRA info request counter is no longer at zero.

Some professional news:

1. I’m now a Special Rapporteur for the Cyber Resilience Act.

2. My company is hiring EU subcontractors with network and security expertise!

Bow Shock Systems won a contract with ETSI to lead development of "vertical" cybersecurity standards for specific products. I'm leading the one for operating systems.

We're looking for people with technical expertise and leadership ability to lead three other verticals.

1/n

#fediHire

👋 Hey infosec.exchange! We’re the CHERI Alliance — excited to join the community!

🔐 We’re all about CHERI (Capability Hardware Enhanced RISC Instructions) — a powerful hardware-based approach to making memory safety and software security actually enforceable, by design.

💡 CHERI helps stop things like buffer overflows and use-after-free bugs before they cause trouble — with hardware-enforced protections built right into the architecture.

We’re here to:
- Share news about the CHERI community in general
- Talk about what our members are building with CHERI
- Connect with folks who care about deep, meaningful security improvements
Check us out 👉 cherialliance.org

Give us a follow if this sounds like your kind of thing!

#CHERI #MemorySafety #SecureByDesign #InfoSec #CyberSecurity #HardwareSecurity

Heavy AI use at work has a surprising relationship to burnout, new study finds https://www.zdnet.com/article/heavy-ai-use-at-work-has-a-surprising-relationship-to-burnout-new-study-finds/
Heavy AI use at work has a surprising relationship to burnout, new study finds

AI may make you more productive, but it comes with a psychological cost.

ZDNET
×

‘An Airplane has been defined as a collection of parts having an inherent tendency to fall to earth, and requiring constant effort and supervision to stave off that outcome. The System called "airplane" may have been designed to fly, but the parts don't share that tendency. In fact, they share the opposite tendency. And the System will fly—if at all—only as a System.’

— John Gall, The Systems Bible

‘The word "Solution" is only a fancy term for the Response of System "A" (ourselves) to System "B" (the Problem). And it's a misleading word, because it implies something that can be done once and for all. But System "B" is sure to Kick Back in response to our Response, and then we must respond once again.’

— John Gall, Systems Bible

@RuthMalan it's a fantastic book.
@RuthMalan that book is one of the greatest ever written for understanding the world.

@RuthMalan “Reality is more complex than it seems.”

https://go.gale.com/ps/i.do?id=GALE%7CA3333871

Gale - Institution Finder

@RuthMalan "The purpose of a system is what it does" has been one of the most important ways in which I try to make sense of the world. This book is a must-read.

@RuthMalan tangentially related video re airplanes, and how we don't _really_ understand how they work.

https://youtu.be/PjS3gs4HzQE

We still don't understand how airplanes fly

YouTube