News: 0000838965

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

GitHub's report on open-source security

([Security] Dec 4, 2020 15:40 UTC (Fri) (corbet))


GitHub has released its [1]"2020 State of the Octoverse" report ; one piece of that is [2]a report on security [PDF] . There are a number of interesting conclusions there, including that a surprising number of security vulnerabilities are planted deliberately. " Analysis on a random sample of 521 advisories from across our six ecosystems finds that 17% of the advisories are related to explicitly malicious behavior such as backdoor attempts. Of those 17%, the vast majority come from the npm ecosystem. While 17% of malicious attacks will steal the spotlight in security circles, vulnerabilities introduced by mistake can be just as disruptive and are much more likely to impact popular projects. Out of all the alerts GitHub sent developers notifying them of vulnerabilities in their dependencies, only 0.2% were related to explicitly malicious activity. That is, most vulnerabilities were simply those caused by mistakes. "



[1] https://octoverse.github.com/

[2] https://octoverse.github.com/static/2020-security-report.pdf

Microsoft Mandatory Survey (#13)

Customers who want to upgrade to Windows 98 Second Edition must now fill
out a Microsoft survey online before they can order the bugfix/upgrade.

Question 13: Which of the following new Microsoft products do you plan on
buying within the next 6 months?

A. Windows For Babies(tm) - Using an enhanced "click-n-drool" interface,
babies will be able to learn how to use a Wintel computer, giving them
a head start in living in a Microsoft-led world.

B. Where In Redmond Is Carmen Sandiego?(tm) - The archvillian Sandiego has
stolen the Windows source code and must be stopped before she can
publish it on the Net.

C. ActiveKeyboard 2000(tm) - An ergonomic keyboard that replaces useless
keys like SysRq and Scroll Lock with handy keys like "Play Solitaire"
and "Visit Microsoft.com".

D. Visual BatchFile(tm) - An IDE and compiler for the MS-DOS batch file
language. MSNBC calls it "better than Perl".