“Andy Brinkmeyer”?
Our names are too similar and we both like Rust. We must be destined to do battle
mastodon 4.7.3🦀 #rustlang / 🐦 #jj / 🍄 #atproto / 📦 #opensource
⚠️ CVE / ✅ Hipcheck / 🔎 OmniBOR
🔵 Principal Engineer at MITRE (opinions are mine)
Mostly posts on BlueSky.
“Andy Brinkmeyer”?
Our names are too similar and we both like Rust. We must be destined to do battle
New from me in the ACM Queue: "Memory Safety for Skeptics," where I argue in favor of pursuing memory safety amid competing priorities, and how to do it!
RE: @yossarian@infosec.exchange
Seems obviously right. At the very least, this will test vendors' claims that they can quickly detect bad packages pre-installation; if that's true, then a widespread cooldown policy wouldn't cause windows of opportunity to widen.
Checkout out Mastodon and once again being annoyed at the lack of quote posts, even just to quote yourself
Hipcheck 3.15.0 is out!
Includes prebuilt binaries for Arm64 Linux, improved affiliation analysis, better errors for bad policy files, better detection of SPDX SBOMs, and improved query registration in the Rust SDK!
We usually think of open source as being volunteer-based, but corporations are pervasively involved in open source software.
Their impact is enormous and under-recognized.
In this post I dive deep on the history, market forces, ecosystem effects, and options for action to make open source more resilient to corporate capture and expand options for support.
https://www.alilleybrinker.com/blog/open-source-software-and-corporate-influence/
@phooky@octodon.social There is an unstable feature for inferring the length. https://github.com/rust-lang/rust/issues/85077