73
Insecure software makers are the real cyber villains – CISA
(www.theregister.com)
c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.
THE RULES
Instance Rules
Community Rules
If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.
Learn about hacking
Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !cybersecurity@lemmy.capebreton.social !securitynews@infosec.pub !netsec@links.hackliberty.org !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub
Notable mention to !cybersecuritymemes@lemmy.world
I'm not sure I fully agree with you, partly because she's not talking about OSS alone. Let's look at a recent but important example.
Yubikeys manufactured before firmware version 5.7 (before May 2024), are vulnerable to a specific type of attack that is not novel, due to a faulty IC via its code. It's something that should have been caught during QA. Who is to blame?
Yubikey didn't make the faulty IC, so obviously the IC maker should bear at least a good chunk of it, but I think it's Yubikey's responsibility to verify their work, especially since they're the ones making the ultimate promise of cryptographic suitability that businesses and governments rely upon.
I don't know if it's right to call companies like this "villains," but I think "lazy or lax" might be appropriate. Additionally, I like the idea of calling cybercrime groups funny names.