Jason Stangroome

175 Followers
422 Following
1.5K Posts

He/him. Principal Infrastructure Engineer. CISSP. Futurama and Factorio enthusiast. Privacy advocate.

Australia.

#infosec #cybersecurity

githubhttps://jstangroome.github.io/jstangroome/
justmytootshttps://justmytoots.com/@jstangroome@infosec.exchange
I'm not interested in your Home Lab. Tell me about your Home Prod. How'd your last disaster recovery test go? Where's your continuity plan documented? Show me your risk register. 😋
Heading home after a whirlwind trip to SF. @evacide and I are working on a project. The results were… different than we expected. More soon.
a CVE dispute

A few years years ago the curl project signed up and became a CNA. This means that we are masters of and can allocate our own CVE identifiers. For any security problems within our territory, it is we who decides if the issue should get a CVE our not. No more bogus CVEs. 57 CVEs … Continue reading a CVE dispute →

daniel.haxx.se

Not a moment too soon! 😅 GitHub Actions checkout now blocks risky pull_request_target checkouts by default to help prevent pwn request supply chain attacks.

https://socket.dev/blog/github-actions-checkout-blocks-pull-request-target-checkouts

GitHub Actions Checkout Now Blocks Risky pull_request_target Checkouts

GitHub Actions checkout now blocks risky pull_request_target checkouts by default to help prevent pwn request supply chain attacks.

Socket

What many people misunderstand about hosting your own content (like this social media instance) is thinking we somehow NEED a big audience or Big Tech involvement.

I'm perfectly fine if the world faded away and it was just the thousand of us here. It's like the early days of the web when we had small forums, nobody missed Reddit back then. Federation is a big plus, not a requirement.

It's the same with websites or IRC for me. I know people use Discord, but I still stick to IRC even if there are only about a hundred of us left. I know people use AI now and website visitors are dropping, but who cares? I still keep doing it for those who like to read.

I don't need the whole world involved for this to feel worthwhile. It's mine, I own it, and I host it for as long as I breathe. After that, it won't matter to me anymore, but I hope other admins keep things running the way I did.

#SelfHosted #SelfHosting #OpenSource #Fediverse #Mastodon #OpenWeb #SocialWeb

We’re so easy to mislead when we don’t know what the words mean.

#average #earnings #AusPol

ATO tax data shows that when politicians talk about 'average Australians', they’re not talking about most Australians | The Point https://thepoint.com.au/off-the-charts/260619-ato-tax-data-shows-that-when-politicians-talk-about-average-australians-theyre-not-talking-about-most-australians

ATO tax data shows that when politicians talk about 'average Australians', they’re not talking about most Australians

It might surprise people to realise just how little a majority of Australians earn. We are often told about average earnings and even average full-time earnings. But averages are not “the middle”. They are merely the sum of all earnings by all people working in Australia divided by the number of those workers.

The Point

We have updated Flathub's LLM policy to explicitly disallow AI usage for both the submission process and applications being submitted.

https://github.com/flathub-infra/documentation/commit/992f57b30de98ddbd5e80959e9672998c83c8c97

I've had some reservations about it, so the wording before that commit was relatively milder. I know it's an unpopular opinion on the Fediverse, but I do think LLMs are inevitable, and the reality is that you can expect less organically grown code as time goes on. I believe it can be a useful tool in and outside FOSS; I hoped we will see a larger number of apps where authors made some effort beyond prompting an agent. Meanwhile, the number of unpleasant interactions I've had with entitled submitters acting as if they were bestowing their brilliant software upon us idiots who are rejecting it went through the roof in the last month. I'm tired.

As always, we are not applying this retroactively, so any vibecoded apps which were already published will remain available.

Reword LLM policy to make it clear it's not allowed · flathub-infra/documentation@992f57b

Documentation for flathub. Contribute to flathub-infra/documentation development by creating an account on GitHub.

GitHub

New by me: I analyzed the websites of America's top companies (aka Fortune 100) and found dozens of companies don't have any easy way to report security flaws to them.

Of the companies that _do_ have vulnerability disclosure policies, half don't actually pay for bug reports.

I break down the data in my new article: https://this.weekinsecurity.com/dozens-of-americas-largest-companies-have-no-simple-way-to-report-security-flaws/

My cyber newsletter also goes out weekly. Sign up/RSS: https://this.weekinsecurity.com

Dozens of America's largest companies have no simple way to report security flaws

New analysis shows that around one-third of America's Fortune 100 companies do not have a vulnerability disclosure policy, bug bounty, or a dedicated email address for reporting security flaws.

~this week in security~
Just found out there’s a .final TLD, which begs the question: when will there be a .final2?