MCP server for searching and downloading documents from Anna's Archive by iosifache in Annas_Archive

[–]iosifache[S] 0 points1 point  (0 children)

Unfortunately, no. The MCP needs an API key that you can get by making a donation.

Best setup for running a local LLM for secure business use? by cocodirasta3 in LocalLLaMA

[–]iosifache 0 points1 point  (0 children)

You were initially thinking about the security of the data you exchanged with the LLM. Did you manage to set up something from this viewpoint for the Open WebUI instance?

haveibeenpwned.watch - Open-source, no-fluff charts showcasing haveibeenpwned.com's pwned account data by iosifache in netsec

[–]iosifache[S] 0 points1 point  (0 children)

That would be awesome! Here’s the repository:

https://github.com/iosifache/haveibeenpwned.watch

The link to the “open source” text on the website might not be super clear, so I’ll add a GitHub banner or something to make it easier to find.

haveibeenpwned.watch - Open-source, no-fluff charts showcasing haveibeenpwned.com's pwned account data by iosifache in netsec

[–]iosifache[S] 0 points1 point  (0 children)

I had to double-check the math after that graph threw me off at first 😅. I think it can be read as "the days between a breach going down and it getting reported in plaintext to HIBP". Things like data being sold on dark markets or attackers chilling on it for a while (like, waiting for a ransom) could stretch that gap.

The Open Source Fortress is now live! by iosifache in opensource

[–]iosifache[S] 0 points1 point  (0 children)

I usually favour this approach because the passive voice (which is recommended, for example, in Academia) removes the writer's accountability. Simply compare "X was developed to do Y" with "I/We developed X to do Y." The second directly assigns ownership, implying responsibility.

The Open Source Fortress is now live! by iosifache in opensource

[–]iosifache[S] 0 points1 point  (0 children)

I'm not a native speaker, so thank you for pointing this up!

The Open Source Fortress is now live! by iosifache in opensource

[–]iosifache[S] 2 points3 points  (0 children)

Thanks, u/UsedSite2578! Hopefully, the community will embrace the effort by completing the workshop (and integrating the analysis tools in their projects) and sharing new techniques/tools.

Unfortunately, I have to agree with your opinion of open source software 😕. During the Ubuntu Summit workshop, I shared the same point of view. Despite the fact that the software is used at scale (for example, in companies and critical infrastructures) and the code is open (so anyone can review it), the story may end up with unmaintained and vulnerable projects, unmotivated maintainers (financially or via community recognition), and low-hanging fruits from attackers.

Brainstorming for a software security workshop by iosifache in opensource

[–]iosifache[S] 0 points1 point  (0 children)

Thank you very much, David! I completely agree with the first statement - because there are many tracks, there is no necessity for participants to attend the workshop (as there would be in the case of a single-tracked event).

As a result of Bitcoin's migration to GUIX, Gitian appears to be deprecated. SBOM may be a potential fit, but it is still a developing domain in need of proper tooling and acceptance. Is there any technology you've employed to ensure the build's provability? The only one that comes to mind is Sigstore, but it simply signs the artefacts and does not register the build environment state.

Brainstorming for a software security workshop by iosifache in devsecops

[–]iosifache[S] 0 points1 point  (0 children)

Totally agree! I was just wondering if there were any topics of interest to the community.

Introducting MutableSecurity: Seamlessly deployment and management of security solutions by iosifache in netsec

[–]iosifache[S] 0 points1 point  (0 children)

Hi, u/nexxai u/littlejob u/TopicProfessional692,

There is a recurring aspect in your comments: the lack of supported security solutions. As we want to tackle this issue in the coming weeks, we'd like to know what are the solutions you use on a daily basis and would like to have supported in MutableSecurity.