Security is becoming an increasingly key piece of the open source puzzle amid industry-wide pushes to shift left and integrate security during early stages of application development. The Linux Foundation’s Open Source Security Foundation (OpenSSF), which encompasses Google’s Supply chain Levels for Software Artifacts (SLSA), is one example of how the open source community is working to improve software security through an ecosystem approach, vying for proactive handling of security by default. . OpenSSF brings together players like Cisco, GitHub, Google, VMware, and others to develop better security tools and practices for open source application development without bias toward a specific ecosystem or vendor. “It’s been very much a volunteer-driven effort involving all sorts of companies and individual software experts,” OpenSSF GM Brian Behlendorf said during a KubeCon press conference. . The Open Source Security Foundation (OpenSSF) coordinates collaboration between enterprises such as Microsoft and IBM to strengthen security frameworks in software engineering.. OpenSSF, Software Security, Security Tools, Open Source Development, Community Collaboration. . LinuxSecurity.com Team
An encryption method widely expected to secure next-generation wireless phones and other devices succumbed to a brute-force collaborative effort to break it, a French research agency announced Thursday. An international team of researchers — led by crypto researcher Robert . . .. An encryption method widely expected to secure next-generation wireless phones and other devices succumbed to a brute-force collaborative effort to break it, a French research agency announced Thursday. An international team of researchers — led by crypto researcher Robert Hurley of the French National Institute for Research in Computer Science and Control, or INRIA — and other computer enthusiasts found the 108-bit key to a scrambled message after four months of number crunching by 9,500 computers worldwide.. A new security protocol for advanced mobile gadgets has been breached due to joint attempts of exhaustive key-searching.. Next-Gen Wireless Encryption, Brute Force Security Threats, Wireless Security Research. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.