<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[&quot;Assume OSS is compromised&quot; - that is a very very deep hole indeed]]></title><description><![CDATA[<p>"Assume OSS is compromised" - that is a very very deep hole indeed </p><p><a href="https://www.paloaltonetworks.com/apps/pan/public/downloadResource?pagePath=/content/pan/en_US/resources/datasheets/defenders-guide-to-frontier-ai-checklist-for-cisos" rel="nofollow noopener"><span>https://www.</span><span>paloaltonetworks.com/apps/pan/</span><span>public/downloadResource?pagePath=/content/pan/en_US/resources/datasheets/defenders-guide-to-frontier-ai-checklist-for-cisos</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/b4627e0b-0dfe-48b7-8aec-f9522d9aa010/assume-oss-is-compromised-that-is-a-very-very-deep-hole-indeed</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 03:42:59 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/b4627e0b-0dfe-48b7-8aec-f9522d9aa010.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 24 Apr 2026 19:03:42 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to &quot;Assume OSS is compromised&quot; - that is a very very deep hole indeed on Fri, 24 Apr 2026 20:45:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/darkuncle%40infosec.exchange">@<span>darkuncle</span></a></span> <span><a href="/user/paul_ipv6%40infosec.exchange">@<span>paul_ipv6</span></a></span> <span><a href="/user/jerry%40infosec.exchange">@<span>jerry</span></a></span> I'm pretty sure that's what the rocketbois have in mind.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/Sempf/statuses/116461634793923510</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/Sempf/statuses/116461634793923510</guid><dc:creator><![CDATA[sempf@infosec.exchange]]></dc:creator><pubDate>Fri, 24 Apr 2026 20:45:19 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Assume OSS is compromised&quot; - that is a very very deep hole indeed on Fri, 24 Apr 2026 20:03:42 GMT]]></title><description><![CDATA[<p><span><a href="/user/paul_ipv6%40infosec.exchange">@<span>paul_ipv6</span></a></span> <span><a href="/user/jerry%40infosec.exchange">@<span>jerry</span></a></span> <span><a href="/user/sempf%40infosec.exchange">@<span>Sempf</span></a></span> precisely</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/darkuncle/statuses/116461471149651793</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/darkuncle/statuses/116461471149651793</guid><dc:creator><![CDATA[darkuncle@infosec.exchange]]></dc:creator><pubDate>Fri, 24 Apr 2026 20:03:42 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Assume OSS is compromised&quot; - that is a very very deep hole indeed on Fri, 24 Apr 2026 20:00:48 GMT]]></title><description><![CDATA[<p><span><a href="/user/darkuncle%40infosec.exchange">@<span>darkuncle</span></a></span> <span><a href="/user/jerry%40infosec.exchange">@<span>jerry</span></a></span> <span><a href="/user/sempf%40infosec.exchange">@<span>Sempf</span></a></span> </p><p>"I say we take off and nuke the entire site from orbit. It's the only way to be sure."</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/paul_ipv6/statuses/116461459765254731</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/paul_ipv6/statuses/116461459765254731</guid><dc:creator><![CDATA[paul_ipv6@infosec.exchange]]></dc:creator><pubDate>Fri, 24 Apr 2026 20:00:48 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Assume OSS is compromised&quot; - that is a very very deep hole indeed on Fri, 24 Apr 2026 20:00:36 GMT]]></title><description><![CDATA[<p><span><a href="/user/jerry%40infosec.exchange">@<span>jerry</span></a></span> I should be in marketing. "In this new world of frontier AI, &lt;copy and paste the same generic security advice that's been given for decades like zero-trust and inventory your assets&gt;"</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/Lee_Holmes/statuses/116461458950582403</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/Lee_Holmes/statuses/116461458950582403</guid><dc:creator><![CDATA[lee_holmes@infosec.exchange]]></dc:creator><pubDate>Fri, 24 Apr 2026 20:00:36 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Assume OSS is compromised&quot; - that is a very very deep hole indeed on Fri, 24 Apr 2026 19:58:33 GMT]]></title><description><![CDATA[<p><span><a href="/user/jerry%40infosec.exchange">@<span>jerry</span></a></span> <span><a href="/user/sempf%40infosec.exchange">@<span>Sempf</span></a></span> given how much commercial software (from Palo Alto and Microsoft, among others) depends on OSS somewhere in the dev toolchain, assume *all software* is compromised</p><p>it's the only way to be sure.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/darkuncle/statuses/116461450905175923</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/darkuncle/statuses/116461450905175923</guid><dc:creator><![CDATA[darkuncle@infosec.exchange]]></dc:creator><pubDate>Fri, 24 Apr 2026 19:58:33 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Assume OSS is compromised&quot; - that is a very very deep hole indeed on Fri, 24 Apr 2026 19:57:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/jerry%40infosec.exchange">@<span>jerry</span></a></span> "See, if you can read the source code, you should just assume it's compromised, but if you _can't_ read the source code, that's how you know it's good." 🤪<img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f921.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--clown_face" style="height:23px;width:auto;vertical-align:middle" title="🤡" alt="🤡" /></p>]]></description><link>https://board.circlewithadot.net/post/https://beige.party/users/sundew/statuses/116461446046920071</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://beige.party/users/sundew/statuses/116461446046920071</guid><dc:creator><![CDATA[sundew@beige.party]]></dc:creator><pubDate>Fri, 24 Apr 2026 19:57:19 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Assume OSS is compromised&quot; - that is a very very deep hole indeed on Fri, 24 Apr 2026 19:35:36 GMT]]></title><description><![CDATA[<p><span><a href="/user/jerry%40infosec.exchange">@<span>jerry</span></a></span> Let’s see how long anything lasts after ripping out curl, ffmpeg, etc b/c it _might_ be an attack surface.</p>]]></description><link>https://board.circlewithadot.net/post/https://ioc.exchange/users/hamishthepiper/statuses/116461360648935601</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://ioc.exchange/users/hamishthepiper/statuses/116461360648935601</guid><dc:creator><![CDATA[hamishthepiper@ioc.exchange]]></dc:creator><pubDate>Fri, 24 Apr 2026 19:35:36 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Assume OSS is compromised&quot; - that is a very very deep hole indeed on Fri, 24 Apr 2026 19:34:54 GMT]]></title><description><![CDATA[<p><span><a href="/user/jerry%40infosec.exchange" rel="nofollow noopener">@<span>jerry</span></a></span> <span><a href="/user/sempf%40infosec.exchange" rel="nofollow noopener">@<span>Sempf</span></a></span> </p><p>I'm going to be moving forward with my very own bespoke vibecoded OS. No way the hackers can plant anything in it if even I have no clue what's in there!</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.space/users/fennix/statuses/116461357940291022</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.space/users/fennix/statuses/116461357940291022</guid><dc:creator><![CDATA[fennix@infosec.space]]></dc:creator><pubDate>Fri, 24 Apr 2026 19:34:54 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Assume OSS is compromised&quot; - that is a very very deep hole indeed on Fri, 24 Apr 2026 19:28:53 GMT]]></title><description><![CDATA[<p><span><a href="/user/sempf%40infosec.exchange">@<span>Sempf</span></a></span> it's the only choice</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/jerry/statuses/116461334250518278</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/jerry/statuses/116461334250518278</guid><dc:creator><![CDATA[jerry@infosec.exchange]]></dc:creator><pubDate>Fri, 24 Apr 2026 19:28:53 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Assume OSS is compromised&quot; - that is a very very deep hole indeed on Fri, 24 Apr 2026 19:28:21 GMT]]></title><description><![CDATA[<p><span><a href="/user/jerry%40infosec.exchange">@<span>jerry</span></a></span> Whelp. Everyone convert those Linux AWS containers to Windows.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/Sempf/statuses/116461332164464962</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/Sempf/statuses/116461332164464962</guid><dc:creator><![CDATA[sempf@infosec.exchange]]></dc:creator><pubDate>Fri, 24 Apr 2026 19:28:21 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Assume OSS is compromised&quot; - that is a very very deep hole indeed on Fri, 24 Apr 2026 19:11:55 GMT]]></title><description><![CDATA[<p><span><a href="/user/exception%40mastodon.savvy.ch">@<span>exception</span></a></span> <span><a href="/user/jerry%40infosec.exchange">@<span>jerry</span></a></span> only way to be secure is to code it yourself using punch cards. Make sure to punch the holes yourself using a lot of force. Don't want a hanging chad to introduce a hidden vulnerability!</p>]]></description><link>https://board.circlewithadot.net/post/https://defcon.social/users/varx/statuses/116461267579928470</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://defcon.social/users/varx/statuses/116461267579928470</guid><dc:creator><![CDATA[varx@defcon.social]]></dc:creator><pubDate>Fri, 24 Apr 2026 19:11:55 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Assume OSS is compromised&quot; - that is a very very deep hole indeed on Fri, 24 Apr 2026 19:11:02 GMT]]></title><description><![CDATA[<p><span><a href="/user/jerry%40infosec.exchange">@<span>jerry</span></a></span> it's not entirely out of line to simply "assume compromise" for any software (or the hardware it controls, Palo Alto) but it is indeed a deep hole. AI tools may actually make problems in open source "shallow" in ways not visible or verifiable in closed systems - and while the open source projects may not be able to buy expensive tooling people looking for things to brag about may spend their own money on those tools anyway.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/fencepost/statuses/116461264047860612</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/fencepost/statuses/116461264047860612</guid><dc:creator><![CDATA[fencepost@infosec.exchange]]></dc:creator><pubDate>Fri, 24 Apr 2026 19:11:02 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Assume OSS is compromised&quot; - that is a very very deep hole indeed on Fri, 24 Apr 2026 19:10:06 GMT]]></title><description><![CDATA[<p><span><a href="/user/jerry%40infosec.exchange">@<span>jerry</span></a></span> OSS can be audited. I think that scares these companies most of all.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/Epic_Null/statuses/116461260411709868</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/Epic_Null/statuses/116461260411709868</guid><dc:creator><![CDATA[epic_null@infosec.exchange]]></dc:creator><pubDate>Fri, 24 Apr 2026 19:10:06 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Assume OSS is compromised&quot; - that is a very very deep hole indeed on Fri, 24 Apr 2026 19:07:10 GMT]]></title><description><![CDATA[<p><span><a href="/user/jerry%40infosec.exchange">@<span>jerry</span></a></span> Assume you will never now just how deeply all closed source software is compromised.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.savvy.ch/users/exception/statuses/116461248854449521</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.savvy.ch/users/exception/statuses/116461248854449521</guid><dc:creator><![CDATA[exception@mastodon.savvy.ch]]></dc:creator><pubDate>Fri, 24 Apr 2026 19:07:10 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Assume OSS is compromised&quot; - that is a very very deep hole indeed on Fri, 24 Apr 2026 19:04:51 GMT]]></title><description><![CDATA[<p><span><a href="/user/krypt3ia%40infosec.exchange">@<span>krypt3ia</span></a></span> I guess we knew about them already</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/jerry/statuses/116461239771175164</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/jerry/statuses/116461239771175164</guid><dc:creator><![CDATA[jerry@infosec.exchange]]></dc:creator><pubDate>Fri, 24 Apr 2026 19:04:51 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Assume OSS is compromised&quot; - that is a very very deep hole indeed on Fri, 24 Apr 2026 19:04:23 GMT]]></title><description><![CDATA[<p><span><a href="/user/jerry%40infosec.exchange">@<span>jerry</span></a></span> NOT THE OFFICE OF STRATEGIC SERVICES!</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/krypt3ia/statuses/116461237939334442</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/krypt3ia/statuses/116461237939334442</guid><dc:creator><![CDATA[krypt3ia@infosec.exchange]]></dc:creator><pubDate>Fri, 24 Apr 2026 19:04:23 GMT</pubDate></item></channel></rss>