BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] Is open source more secure at the current level of AI?
- Subject: [Discuss] Is open source more secure at the current level of AI?
- From: richard.pieri at gmail.com (Rich Pieri)
- Date: Thu, 9 Apr 2026 20:12:56 -0400
- In-reply-to: <da463e02632199b9580c097f66fdfa81.squirrel@mail.mohawksoft.com>
- References: <3ba75ddf-6d93-40c7-85ca-050531c8a4dd@app.fastmail.com> <thxkhw4eu7fd5evlxyxypilxlab4jkiuh76x6fqefp27gefjhv@74x7migauwzi> <4e616515-7aa4-4590-9740-2df77ba0def5@app.fastmail.com> <da463e02632199b9580c097f66fdfa81.squirrel@mail.mohawksoft.com>
On Thu, 9 Apr 2026 18:37:47 -0400 markw at mohawksoft.com wrote: > Trust me, I've been in the industry for over 4 decades. Any company > that puts the effort into scanning their source also will scan the > open source. This has been common practice for well over a decade. I > have personally managed CVE detection and mitigation in two companies. There's even a sub-industry specializing in this. We use three different vendors' (that I know of, there might be more that the release group uses that I'm not aware of) systems to scan EVERYTHING we pull in from outside, EVERYTHING we run, EVERYTHING we write internally, EVERYTHING we build, and EVERYTHING we ship to our customers. We sign everything we ship with a dedicated security appliance. Our customers can be confident that nothing has been tampered with after it leaves our network. And if developers forget to sign their test builds? Or they try to pull in things that aren't authorized? One of those security systems will kill it and quarantine it. If it isn't validated and signed then it does not run. -- \m/ (--) \m/
- Follow-Ups:
- [Discuss] Is open source more secure at the current level of AI?
- From: markw at mohawksoft.com (markw at mohawksoft.com)
- [Discuss] Is open source more secure at the current level of AI?
- References:
- [Discuss] Is open source more secure at the current level of AI?
- From: rrose at pobox.com (Randall Rose)
- [Discuss] Is open source more secure at the current level of AI?
- From: dsr at randomstring.org (Dan Ritter)
- [Discuss] Is open source more secure at the current level of AI?
- From: rrose at pobox.com (Randall Rose)
- [Discuss] Is open source more secure at the current level of AI?
- From: markw at mohawksoft.com (markw at mohawksoft.com)
- [Discuss] Is open source more secure at the current level of AI?
- Prev by Date: [Discuss] Is open source more secure at the current level of AI?
- Next by Date: [Discuss] Is open source more secure at the current level of AI?
- Previous by thread: [Discuss] Is open source more secure at the current level of AI?
- Next by thread: [Discuss] Is open source more secure at the current level of AI?
- Index(es):
