"Assume OSS is compromised" - that is a very very deep hole indeed
-
"Assume OSS is compromised" - that is a very very deep hole indeed
@jerry Whelp. Everyone convert those Linux AWS containers to Windows.
-
@jerry Whelp. Everyone convert those Linux AWS containers to Windows.
@Sempf it's the only choice
-
@Sempf it's the only choice
-
"Assume OSS is compromised" - that is a very very deep hole indeed
@jerry Let’s see how long anything lasts after ripping out curl, ffmpeg, etc b/c it _might_ be an attack surface.
-
"Assume OSS is compromised" - that is a very very deep hole indeed
@jerry "See, if you can read the source code, you should just assume it's compromised, but if you _can't_ read the source code, that's how you know it's good." 🤪

-
@Sempf it's the only choice
-
"Assume OSS is compromised" - that is a very very deep hole indeed
@jerry I should be in marketing. "In this new world of frontier AI, <copy and paste the same generic security advice that's been given for decades like zero-trust and inventory your assets>"
-
"I say we take off and nuke the entire site from orbit. It's the only way to be sure."
-
"I say we take off and nuke the entire site from orbit. It's the only way to be sure."
@paul_ipv6 @jerry @Sempf precisely
-
@paul_ipv6 @jerry @Sempf precisely
@darkuncle @paul_ipv6 @jerry I'm pretty sure that's what the rocketbois have in mind.
-
R relay@relay.infosec.exchange shared this topic