Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Josh Bressers

@joshbressers@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Podcaster (http://opensourcesecuritypodcast.com http://hackerhistory.com) - Blogger (http://opensourcesecurity.io) - He/Him

2749 Followers
912 Following
50 Posts
Joined April 20, 2017
Podcast:
https://opensourcesecurity.io/
Web:
https://bress.net
Cookies?:
Yes please
TTY:
1
Signal:
joshbressers.01
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2w ago
I had the joy to chat with @bagder@mastodon.social and @icing@chaos.social about #curl security things We discussed the Summer of Bliss, the influx of LLM vulnerability reports. The stress of dealing with these things, and how much effort all this security work has become They are both amazing people who have a ton of knowledge and experience to share https://opensourcesecurity.io/2026/2026-09-curl-bliss-stefan-daniel/ #OpenSourceSecurity #security #vulnerability
The curl summer of Bliss with Daniel and Stefan
Open Source Security

The curl summer of Bliss with Daniel and Stefan

Josh chats with Daniel and Stefan from curl about their summer of bliss. Curl stopped taking vulnerability reports for a month and nothing much happened really. Daniel and Stefan have a really pragmatic view of all the new LLM powered vulnerability detection tools. The cost of finding a vulnerability has dropped dramatically, but the cost of fixing those bugs hasn’t changed. Taking some time off is important for anyone in the middle of these reports. Daniel and Stefan have some great experience

19
0
16
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2mo ago
I wrote a blog post You don't have a supply chain, you have a supply soup This is something I want to spend some time investigating in the future, it's all vastly more complicated and weird than we think it is https://opensourcesecurity.io/2026/07-supply-soup/
Blog - You don't have a supply chain, you have supply soup
Open Source Security

Blog - You don't have a supply chain, you have supply soup

2026 has been a wild year. There are more vulnerabilities than anyone can count. We seem to keep talking about the number itself instead of things like how we got here or what we’re going to do about it, which is neat. The number of attacks against open source is basically an uncountable mess. Also very neat. And the cherry on top of this poop sundae is number of companies that have promised us they are going to “fix” open source, and when they use the word fix they really mean sell you a soluti

37
7
16
2
Open post
Josh Bressers @joshbressers@infosec.exchange
· 3mo ago
Replying to
@grumpygamer@mastodon.gamedev.place @Viss@mastodon.social I don’t understand how this isn’t just the status quo If you tried to claim something was the fault of autocorrect everyone would call you an idiot And they would be right
19
0
3
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 5mo ago
Replying to
@gregkh @wdormann @Viss This post got into my head. I think you're right, the days of coordination are over So I wrote it down https://opensourcesecurity.io/2026/05-vulnerability-economics/
The lopsided economics of vulnerabilities
Open Source Security

The lopsided economics of vulnerabilities

There was recently a really good thread about the Copy Fail vulnerability between Will Dormann and Greg K-H. The TL;DR is that vulnerability reporting and disclosure is in a weird state of flux. This discussion got me wondering what’s going on, and I think we’re seeing the extremes emerging of how vulnerabilities have always worked. The middle of the bell curve has been removed. There are three groups in this story. The Security Researchers, the Companies, and Open Source developers. In the abov

37
53
24
3
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2mo ago
Replying to
@andrewnez@mastodon.social How nice of them to let you know
5
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 3mo ago
I had a chat with Lori Lorusso and Niko Matsakis about the Rust Foundation Maintainers Fund Funding open source is a huge topic right now, the Rust Foundation has some great ideas. It will be exciting to watch this one grow and evolve https://opensourcesecurity.io/2026/2026-07-rfmf-lori-niko/ #OpenSourceSecurity #rust #RustFoundation
Rust Foundation Maintainers Fund with Lori and Niko
Open Source Security

Rust Foundation Maintainers Fund with Lori and Niko

Josh chats with Lori Lorusso and Niko Matsakis about the Rust Foundation Maintainers Fund. This is a new project the Rust Foundation has create to help fund Rust maintainers. It’s a great discussion where Lori and Niko cover all the ways they expect to fund the maintainers which is never as easy as one initially expects. Funding open source is a huge topic right now, it sounds like the Rust Foundation has some great ideas.

9
0
5
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 3mo ago
I had the pleasure to chat with @allanfriedman@infosec.exchange about Bill of Materials things on #OpenSourceSecurity We touched on SBOMs, HBOMs, AIBOMs, and even some other BOM types I can't remember now Allan is always fun to chat with, and he has encyclopedic knowledge about the BOM universe https://opensourcesecurity.io/2026/2026-06-allan-omnibom/
AIBOM, CBOM, and HBOM with Allan Friedman
Open Source Security

AIBOM, CBOM, and HBOM with Allan Friedman

Josh chats with Allan Friedman about all things Bill of Materials. Allan did a ton of work to help turn SBOM into what it is today. He has many thoughts and ideas around the new types of BOMs, a concept he’s calling the OmniBOM. Allan is always fun to chat with and he brings a ton of knowledge and advice. Episode Links Allan’s Linkedin Dirk Gently’s Holistic SBOM Agency Allan’s AIBOM paper HBOM Cryptography Bill of Materials (CBOM) This episode is also available as a podcast, search for “Open So

7
4
9
1
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2mo ago
Replying to
@andrewnez@mastodon.social this is a work of art Well done
4
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2mo ago
Replying to
@mttaggart@infosec.exchange 5.6 million crimony
3
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 5mo ago
Replying to
@andrewnez@mastodon.social The number of people who understand this is an extremely small number My poster child for this is https://github.com/ossf/tac/issues/101 It's filled with opinions that don't change even when shown the data. Those are the same people that then built scorecard
github.com
12
3
4
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 3mo ago
On this episode of @CypherCon@infosec.exchange #HackerHistory I talk to Michael Lenz It's a great story about starting out with what we now call retro computers, building a SOC and SIEM before those were really things, and eventually putting focus into Burbsec community meetups https://hackerhistory.com/podcast/the-history-of-michael-lenz/
hackerhistory.com
6
0
3
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2mo ago
I miss the days when my spellchecker just worked
4
1
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2mo ago
Replying to
@andrewnez@mastodon.social We can hope you've ruined the day for some well funded security company totally not illegally scraping your data :)
3
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2mo ago
Replying to
@andrewnez@mastodon.social @Di4na@hachyderm.io @Rairii@labyrinth.zone did someone finally rewrite curl in a weekend?
2
0
1
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 4mo ago
Replying to
@mattblaze@federate.social @robpike@hachyderm.io hey now. It’s TWO resistors!
8
1
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2mo ago
Replying to
@andrewnez@mastodon.social That's all your satire posts :)
2
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2mo ago
Replying to
@wdormann@infosec.exchange I wonder if it will get actual 0days or just be a slopfest
1
3
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2mo ago
Replying to
@wdormann@infosec.exchange Deer are assholes So are squirrels
1
1
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 5mo ago
Replying to
@gregkh @deftpunk @wdormann @Viss I do think signaling intent to publish a website and make noise falls under a proper disclosure plan
5
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2mo ago
Replying to
@jacques@mastodon.chester.id.au indeed
1
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2mo ago
Replying to
@icing@chaos.social Sadly this is probably correct
1
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 5mo ago
Replying to
@ancoghlan@mastodon.social I'm not opposed to a company employing people at a given project to get some advanced notice The devil is in the details, but I think in many cases it could work
3
2
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 5mo ago
Replying to
@gregkh @deftpunk @wdormann @Viss You said this wasn't reported to the kernel security team From where I sit (and I'm not in the middle of this) it seems like if you plan to make a website and give something a name, tell the securiy team If you're OK with the current process though I shall trust you on this, you're the expert, I'm just the peanut gallery
3
2
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 3mo ago
Replying to
@simplenomad@rigor-mortis.nmrc.org I’ve done several things like this and requested passing the EFF. The taxes weren’t going to be worth it
1
1
1
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 3mo ago
Replying to
@ryan@m29.us When I chatted with @cadey@pony.social about Anubis, they called it a "waifuectomy", which is the best name for anything ever https://opensourcesecurity.io/2026/2026-01-anubis-xe/
opensourcesecurity.io
1
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 3mo ago
Replying to
@andrewnez@mastodon.social @Viss@mastodon.social Poe's Law FTW!!!
1
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 5mo ago
Replying to
@Le_suisse@social.gerbet.me @ariadne@social.treehouse.systems @gregkh@social.kernel.org @wdormann@infosec.exchange @Viss@mastodon.social @andrewnez@mastodon.social @Di4na@hachyderm.io Yes! The #GCVE folks are really on the ball about all this I would be willing to bet a milkshake they will be one of the more authoritative sources in the future
2
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 5mo ago
Replying to
@ra6bit@infosec.exchange @ariadne@social.treehouse.systems @gregkh@social.kernel.org @wdormann@infosec.exchange @Viss@mastodon.social @andrewnez@mastodon.social @Di4na@hachyderm.io Every single time an open source database has been tried it has failed spectacularly. For whatever reason the consumers of that data take and give nothing back then the project dies
2
2
1
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 5mo ago
Replying to
@andrewnez@mastodon.social @mainec@fromm.social you know it’s all of them :)
1
1
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 5mo ago
Replying to
@ra6bit@infosec.exchange @ariadne@social.treehouse.systems @gregkh@social.kernel.org @wdormann@infosec.exchange @Viss@mastodon.social @andrewnez@mastodon.social @Di4na@hachyderm.io It's a very valid question that gets asked quite a bit It *seems* like it's something should work. But sadly it doesn't
1
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 5mo ago
Replying to
@siddhesh_p@mastodon.social @gregkh@social.kernel.org @wdormann@infosec.exchange @Viss@mastodon.social Every project is really its own ecosystem I think glibc does a really good job with CVEs But I suspect if you go from 12 a year to 12 a month your process will have to change It's possible you would adopt the "give it a CVE and move on" approach, or because there is so much attention from the distros you could get some extra help to deal with the volume
1
3
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 5mo ago
Replying to
@Di4na@hachyderm.io @gregkh@social.kernel.org @wdormann@infosec.exchange @corsac@mastodon.social @Viss@mastodon.social Yeah, this Which then goes back to your comments about our tooling being horrid and makes updates slow and painful
1
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 5mo ago
Replying to
@wdormann @gregkh @deftpunk @Viss Ugh, I misread your 14 as a 4 it seems 14 is still pretty good for most things, I won't argue about that
1
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2mo ago
Replying to
@ariadne@social.treehouse.systems Ahhh, I didn't know it could already do PURLs, very nice! Adding CPE certainly wouldn't hurt. and there are things CPE can identify PURL can't I still hate them though :)
0
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2mo ago
I had a chat with @joshcorman@infosec.exchange about securing critical infrastructure on #OSSPodcast Josh is one of the best in the industry on this topic. He has a ton of interesting (and sometimes scary) things to say about it all https://opensourcesecurity.io/2026/2026-07-critical-infrastructure-josh-corman/
opensourcesecurity.io
0
1
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2mo ago
I might be missing something here I'm seeing what I think is a pattern with all these vulnerability clearing houses coming out of the woodwork The common theme seems to be "give us money and we will make sure you know about embargoed vulnerabilities" It's hard to see the logical end to this is anything other than researchers just dropping 0days
0
2
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2mo ago
Replying to
@sethmlarson@mastodon.social @yossarian@infosec.exchange if AI says it’s true then it is Embrace your destiny
0
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 3mo ago
Replying to
@christianmlong@wandering.shop Awesome, thanks!
0
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2mo ago
Replying to
@ariadne@social.treehouse.systems CPE sucks rocks. I would allow other identifiers like PURL also
0
1
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2mo ago
Replying to
@wdormann@infosec.exchange I suggest you buy a feral wolf, that seems like the most practical solution
0
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 1mo ago
Replying to
@bagder@mastodon.social the reply would probably be “what are YOU willing to pay for windows support” ;)
0
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2mo ago
Replying to
@ariadne@social.treehouse.systems For sure, that's a obvious hand waive to start the show Until a bunch of 0days start to show up :)
0
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 3mo ago
Replying to
@petrillic@hachyderm.io I assume that's just an empty file :)
0
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2mo ago
Replying to
@ariadne@social.treehouse.systems this all reeks of Thatcher’s “there is no alternative” which is code for “shut up and let me destroy society “
0
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 3mo ago
Replying to
@andrewnez@mastodon.social I dig this and I'm glad it's a big topic Something I was thinking about during my morning bike ride after reading this, is it's sort of sideways comparison Roads and bridges were built on purpose by the people who have to take care of them Open source is more like I build a road through my back yard, and it suddenly becomes critical infrastructure because it's the only road to the new restaurant I don't think that makes it less important, but it also is a weird problem to understand and solve
0
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2mo ago
Replying to
@notting@mas.to This is a great idea 1) Find vulnerability 2) Bet on market for the next vulnerability to be found 3) Probably go to jail for fraud 4) Hahahahaha just kidding everything is fine
0
0
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 5mo ago
Replying to
@Di4na@hachyderm.io @gregkh@social.kernel.org @deftpunk@fosstodon.org @wdormann@infosec.exchange @Viss@mastodon.social That's also a good point It's extra frustrating when there's nothing us unwashed masses can do except wait
0
2
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 5mo ago
Replying to
@gregkh@social.kernel.org @deftpunk@fosstodon.org @wdormann@infosec.exchange @Viss@mastodon.social I do wonder sometimes how many of those CVEs you file could be a privilege escalation with a proper reproducer I'm sure it's not zero
0
1
0
0
Open post
Josh Bressers @joshbressers@infosec.exchange
· 2mo ago
Replying to
@adamshostack@infosec.exchange that’s just the sort of thing the AI would say!
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:19:47 UTC