Announcement

Collapse
No announcement yet.

Lawmakers press Linux on security of open-source software

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Lawmakers press Linux on security of open-source software

    From http://thehill.com/policy/cybersecur...ource-software
    “Companies like Microsoft, Adobe, or Apple have the processes and procedures in place to quickly address these vulnerabilities, and—more importantly—the time and funding to do so,” the lawmakers wrote Monday. “This is not always the case for OSS vulnerabilities, as OSS creators or maintainers may be globally-located volunteers, who often have unrelated full-time employment and may be uncompensated for their OSS work.”
    And, from the letter sent to The Linux Foundation: Click image for larger version

Name:	GS20180403191547.png
Views:	1
Size:	136.3 KB
ID:	649308
    Last edited by chimak111; Apr 03, 2018, 07:48 AM.
    Kubuntu 20.04

    #2
    Lawmakers press Linux on security of open-source software

    Originally posted by chimak111 View Post
    The real question is “how much of a campaign donation did these two political hacks get that prompted them to disparage OpenSSL for a four year old bug that was immediately patched?”

    IF they were smart enough to do a search for “vulnerabilities that affect all versions of Windows” they’d discover Windows bugs that were active for 15 years, and bugs that M$ refused to patch. There are dozens, right up to and including their vaunted Win10, which M$ claims is the “most secure Windows they’ve ever made”, but considering their past that’s not saying much
    "A nation that is afraid to let its people judge the truth and falsehood in an open market is a nation that is afraid of its people.”
    – John F. Kennedy, February 26, 1962.

    Comment


      #3
      Originally posted by chimak111 View Post
      ...have the processes and procedures in place to quickly address these vulnerabilities, and—more importantly—the time and funding to do so
      I find this quite laughable. Such companies rarely seem do address such issues in a timely manner unless forced to do so.

      Comment


        #4
        These morons clearly have no idea what the actual state of the web is. The web runs on open source. The servers are mostly open source, the languages are mostly open source, the frameworks are mostly open source, the framework plugins are mostly open source. People who know nothing about technology have no business writing laws to regulate it.

        Comment


          #5
          Unfortunately the "old saw" that "all politics is local" and ..."all politicians are great at pressing the flesh but also are "just people persons"...has met a "nexus" in the last few years...

          they "assume" that this or that is correct if it fits their political agenda...

          their "agenda" is not now "local" it is ...world wide ...for all to see...

          And...for all those with opposing agendas to SCREW THEM UP...

          a) from malice
          b) from stupidity

          but...

          c) for political gain...
          woodDETESTSitsmoke

          Comment


            #6
            Originally posted by whatthefunk View Post
            These morons clearly have no idea what the actual state of the web is. .
            LOL...LOL...LOL...

            I am a developer at an "online chat thing..." ...

            the problem is... THE AMAZING PERMUTATIONS AND COMBINATIONS OF...

            a) physical platforms... two...Iphone and Android
            b) the variations of the platforms...Android now...9...Iphone...don't know...
            c) the MANUFACTURER wanting to put " apps " onto the phone kind of like Microsith did decades ago to force UNKNOWING...INNOCENT...but UNKNOWING ...people to use "this tweaked to make money" thing...

            My college is STRUGGLING...with

            "how to upload a picture" into a teacher generated thread on the Leanring Management System...

            because of all the stuff above...

            not only does the college have to have an orientation session to...

            the LMS

            BUT...

            FOR EACH VARIANT OF HARDWARE/SOFTWARE/phone system...

            A HUGE...NIGHTMARE...

            the saviour(s) are...

            an OPEN SOURCE... REALLY...AN OPEN SOURCE LMS

            and...

            wait for it...

            HTML 5.

            WTF hit the nail on the head...

            and it is only going to get worse...

            UNTIL everybody gets on board with HTML 5

            woodjustsayinWTFhitthenailontheheadsmoke

            Comment


              #7
              Is your colleges learning management system an app or a web app? If they are struggling to upload pictures, there is clearly a problem somewhere. You can upload pictures with a couple lines of PHP (or really any other server-side language) and under 10 lines of html:
              Code:
              <?php
              $uploadDir = __DIR__ . '/uploads/';
              
              if (isset($_FILES['picture'])) {
                move_uploaded_file($_FILES['picture']['tmp_name'], $uploadDir . $_FILES['picture']['name']);
              }
              ?>
              <html>
                <body>
                    <form method="post" action="practice.php" enctype="multipart/form-data">
                        <input type="file" name="picture" id="pictuer">
                        <input type="submit" value="Upload" name="submit">
                    </form>
                </body>
              </html>
              There's no error handling or validation there, but thats how easy it is to do simple file uploading on a webpage. If they can't figure that out, somebody should be out of a job...

              Comment


                #8
                Originally posted by whatthefunk View Post
                Is your colleges learning management system an app or a web app? If they are struggling to upload pictures, there is clearly a problem somewhere. You can upload pictures with a couple lines of PHP (or really any other server-side language) and under 10 lines of html:
                Code:
                <?php
                $uploadDir = __DIR__ . '/uploads/';
                
                if (isset($_FILES['picture'])) {
                  move_uploaded_file($_FILES['picture']['tmp_name'], $uploadDir . $_FILES['picture']['name']);
                }
                ?>
                <html>
                  <body>
                      <form method="post" action="practice.php" enctype="multipart/form-data">
                          <input type="file" name="picture" id="pictuer">
                          <input type="submit" value="Upload" name="submit">
                      </form>
                  </body>
                </html>
                There's no error handling or validation there, but thats how easy it is to do simple file uploading on a webpage. If they can't figure that out, somebody should be out of a job...
                That’s because you know what you are doing. Having been in academia I sympathize with woody. People who are very smart in their degreed profession often think that degree makes them experts in everything else and if there are problems it’s always someone else’s fault.


                Sent from my iPhone using Tapatalk
                "A nation that is afraid to let its people judge the truth and falsehood in an open market is a nation that is afraid of its people.”
                – John F. Kennedy, February 26, 1962.

                Comment

                Working...
                X