mikemcsharry Posted July 25, 2017 Posted July 25, 2017 fascinating article - I know that Black Duck are pushing stuff that lets you track whats going on with Open Source in your network .. but this article might make you think about a thing or two .. https://www.out-law.com/en/articles/2017/june/oversight-of-use-of-open-source-code-crucial-as-gdpr-approaches-says-industry-expert I'm on a webinar this afternoon where these folks are partially presenting - I'll feed in anything i find
GrumbleDook Posted July 25, 2017 Posted July 25, 2017 fascinating article - I know that Black Duck are pushing stuff that lets you track whats going on with Open Source in your network .. but this article might make you think about a thing or two .. https://www.out-law.com/en/articles/2017/june/oversight-of-use-of-open-source-code-crucial-as-gdpr-approaches-says-industry-expert I'm on a webinar this afternoon where these folks are partially presenting - I'll feed in anything i find The reference to PCI regs is very pertinent. For many of us, ISO27001 and the risk-based approach to information management is the best and most relevant area to look at. It will be interesting to see what is covered on the webinar. Thanks for highlighting this, Mike, and looking forward to the feedback.
mavhc Posted July 25, 2017 Posted July 25, 2017 Mainstream open source articles are all really weird. "omg, your software might be out of date", that applies to everything. "Pittinger said this is because there is no system within the open source community to alert businesses when vulnerabilities are identified in the versions of software they are running" Not heard of git pull, or apt update then? Or https://cve.mitre.org/ Sounds like a scare story. 1
Geoff Posted July 25, 2017 Posted July 25, 2017 I just vulnerability scan internally. That usually does a better job of picking up out of date open source stuff than it does with propriety stuff. For an extra kick in the crotch to this scaremongering article, the vulnerability scanner I use is open source. OpenVAS. OpenVAS - OpenVAS - Open Vulnerability Assessment System 1
mikemcsharry Posted July 25, 2017 Author Posted July 25, 2017 errmm ... I don't know how to admit his but .. well, I've had afew very early starts and the chair was too comfortable and, anyway, 2/3 of my cup of tea is cold .. Maybe bods of a certain age should be banned from webinars, but I di wake up agian before it finished, . All that aside, the one thing that struck me is the vast amount of open source tucked away in commercial applications. I recently installed the software that comes with Clever Boards - have you looked at the implications for data security of ShareX?? (That didn't go on!!).
jthompson Posted July 25, 2017 Posted July 25, 2017 I just vulnerability scan internally. That usually does a better job of picking up out of date open source stuff than it does with propriety stuff. For an extra kick in the crotch to this scaremongering article, the vulnerability scanner I use is open source. OpenVAS. OpenVAS - OpenVAS - Open Vulnerability Assessment System Ooh, that looks like something fun to play with!
mavhc Posted July 25, 2017 Posted July 25, 2017 errmm ... I don't know how to admit his but .. well, I've had afew very early starts and the chair was too comfortable and, anyway, 2/3 of my cup of tea is cold .. Maybe bods of a certain age should be banned from webinars, but I di wake up agian before it finished, . All that aside, the one thing that struck me is the vast amount of open source tucked away in commercial applications. I recently installed the software that comes with Clever Boards - have you looked at the implications for data security of ShareX?? (That didn't go on!!). Remove all the print screen buttons from your keyboards now!
Geoff Posted July 25, 2017 Posted July 25, 2017 Ooh, that looks like something fun to play with! Took about 2 hours to setup on a CentOS VM.
mikemcsharry Posted July 25, 2017 Author Posted July 25, 2017 I also noticed on one PC that I turned off all sharex options. Next update of sharex put them all on again. Bin time.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now