julia ferraioli :cc_by: · @juliaferraioli
3371 followers · 788 posts · Server floss.social

BEYOND proud to present "Beyond the Repository: Best practices for open source ecosystems researchers", a collaboration between myself, @amcasari, and @jlovato that was just published in the the @ACM Queue.

Please share with anyone who is doing research into open source!

queue.acm.org/detail.cfm?id=35

#OpenSource #oss #FOSS #sociotechnicalsystems #research #bestPractices

Last updated 1 year ago

Emory L. · @emory
161 followers · 1394 posts · Server soc.kvet.ch

users of browser that are worried about -2023-2033 (and you should be) it's easy to get version strings mixed up so in Edge (and presumably Brave and Vivalidi and any other Chrome-engine browser), make sure in `about://` that the chromium version is not older than 112.0.5615.121!

#microsoft #edge #CVE #infosec #bestPractices

Last updated 1 year ago

Emory L. · @emory
160 followers · 1338 posts · Server soc.kvet.ch

every time i read a post or guide and it walks someone through creating an without a password on the private key i want to reach through my display and whack them upside the head and tell them to read the g-ddamned manpage for `ssh-agent` and `ssh-keygen` again.

i log this as a critical finding in my threat model workshops. using strong authentication in automation is a solved problem and has been before the first commit to openssh as far as i can remember.

#openssh #keypair #bestPractices

Last updated 1 year ago

Emory L. · @emory
127 followers · 635 posts · Server soc.kvet.ch

I have staged my for tomorrow and I'm super excited to see this team in particular again! The best part about my job is meeting all the people that build marvelous things.

there's a woman in that team that was a contractor and i _loved_ her as to create separate accounts at Github.com/GitLab for each client which sure makes user access review easier and limits the blast radius.

i haven't investigated if my using in multiple IDs though.

#threatmodel #sop #bestPractices #yubikey #webauthn

Last updated 2 years ago

Jeff Winchester · @jeff
7 followers · 23 posts · Server wpbuilds.social

@nathan
It's hard to get people on board when it cost them time or money. I mean look, world leaders can't even get it together on the . I think the best thing we can do is spread the word to our fellow developers and clients. And also use ourselves.

#climate #bestPractices

Last updated 2 years ago

Emory · @emory
47 followers · 230 posts · Server soc.kvet.ch

huh my can use my type-C yubikey now. it didn't used to work but i got challenged at Github and said what the hell lets try and boom authenticated. (github lets you have a security key _AND_ a totp otp MFA option active at the same time \o/

#iPadPro #mfa #yubikey #bestPractices #infosec #github

Last updated 2 years ago

Emory · @emory
47 followers · 230 posts · Server soc.kvet.ch

i swapped out a 5.1 rig in my family room with a new to match a new Samsung Q-series TV. i have a real monster of a subwoofer that i can’t use with the ‘bar. the wireless subwoofer just doesn’t cut it even dialed up to +6.

: go into the soundbar menus, drop levels of all channels _not_ your sub i.e. center, front, to -4, leave sub at +6.

still no BIG BOOMS but at least it feels more theatrical as intended.

#Atmos #soundbar #tip #homeTheater #householdAV #bestPractices

Last updated 3 years ago