Explore top 10 tips to secure your open-source projects now. Read More
×Data scientists, who often choose open source packages without considering security, increasingly face concerns over the unvetted use of those components, new study shows. . Vulnerabilities in open source components — such as the widespread flaws revealed 10 months ago in Log4j 2.0 — have forced data scientists to reevaluate the open source code frequently used in analysis and the creation of machine learning models. According to a report by Anaconda, a data-science platform firm, in the past year, 40% of surveyed data scientists, business analysts, and students have scaled back their use of open source components, while a third remained steady, and only 7% incorporated more open source code into their projects. The majority of those surveyed do not report to the information technology department (18%), but work within their own data science or research and development group (47%), according to Anaconda's " 2022 State of Data Science" report, released last week. . Data engineers are reducing their reliance on community-driven code libraries due to vulnerabilities associated with unchecked elements.. Open Source Vulnerabilities,Data Scientist Concerns,Machine Learning Security. . Brittany Day
Security advisor Luca Bongiorni spun up an Ubuntu Linux instance on Azure and was extremely annoyed to receive a sales message from a Canonical representative three hours later. Say what?? Bongiorni openly voiced his frustration, "WHY [did] MICROSOFT FORWARDED TO UBUNTU THAT I SPUN A NEW VM!?!" Customer privacy, what's that?" . It was just another day for Luca Bongiorni, a security advisor for Bentley Systems. He'd just spun up an Ubuntu Linux 18.04 instance on the Microsoft Azure cloud using a corporate sandbox for testing purposes. Three hours later, on Bongiorni's LinkedIn account he received a message from a Canonical sales representative saying, " I saw that you spun up an Ubuntu image in Azure ," and telling him he'd be his "point of contact for anything Ubuntu -related in the enterprise." Say what?? Actually, Bongiorni was a little more "frank" about his annoyance and surprise that a Canonical salesperson had tracked him down on an entirely different service and knew that he had just used Ubuntu on Microsoft Azure. " What the f*** is happening here? WHY [did] MICROSOFT FORWARDED TO UBUNTU THAT I SPUN A NEW VM!?!" Customer privacy, what's that? . Luca Bongiorni shares his concerns regarding data privacy following an unanticipated notification regarding the configuration of his Azure Ubuntu setup.. Azure Cloud, User Privacy, Ubuntu Security. . LinuxSecurity.com Team
With the coronavirus outbreak rapidly spreading worldwide, governments are or exploring or implementing privacy-intrusive solutions for tracking the disease's spread. What are your thoughts on these solutions? . As the global coronavirus (COVID-19) outbreak is leaving its mark across the world, at least four governments are deploying or at looking at implementing privacy-intrusive surveillance systems to track citizens and the disease's spread. Countries like China and South Korea have already deployed extensive citizen tracking systems, while Israel and the US are preparing similar surveillance measures. The link for this article located at ZDNet is no longer available. . Governments are implementing privacy-intrusive tracking solutions to combat COVID-19's spread. Explore the privacy implications.. COVID-19 Tracking, Privacy Concerns, Government Surveillance, Data Collection, Intrusive Solutions. . LinuxSecurity.com Team
Experts agree that paper ballots are needed, but eight American states will use completely paperless machines in the 2020 elections regardless. What are your thoughts on this? Comment below. . Despite the obvious risk and years of warnings, at least eight American states and 16 million American voters will use completely paperless machines in the 2020 US elections, a new report by New York University’s Brennan Center for Justice found. Paperless voting machines persist despite a strong consensus among US cybersecurity and national security experts that paper ballots and vote audits are necessary to ensure the security of the next election. The Brennan Center report points to the Senate Intelligence Committee investigation of Russian interference in the 2016 section, which also recommends paper ballots for security and verification. The link for this article located at MIT Technology Review is no longer available. . In light of the danger, 16 million citizens are set to rely on electronic voting systems for their ballots, prompting worries.. Voting Security, Paperless Voting, Election Technology. . Brittany Day
Many people fear that AI-powered hacking would aid criminals in carrying out dangerous and costly cyberattacks. However, threat actors appear to be doing just fine without it. What is your opinion on this? Is AI-powered hacking a legitimate concern or are these fears misplaced? Comment below. . Artificial intelligence is captivating tech news audiences. Unfortunately, growing expectations for AI’s impact on legitimate business have spawned a distracting narrative about potential AI-powered cyberattacks. Is this really a threat that needs to be on our radar? Based on my work examining dark web markets and the techniques cybercriminals use to collect, resell or commit fraud with stolen data, I question the usefulness of AI to run-of-the-mill cybercrime. The link for this article located at The Next Web is no longer available. . Artificial intelligence is captivating tech news audiences. Unfortunately, growing expectations for . people, ai-powered, hacking, would, criminals, carrying, dangerous, costly. . Brittany Day
In what may be a case of "if we ignore it, it will go away," South Africa's largest electricity company has become the subject of the public exposure of customer data after ignoring researcher pleas to resolve the problem. . The link for this article located at ZDNet is no longer available. . The link for this article located at ZDNet is no longer available.. ignore, south, africa's, largest, electricity. . LinuxSecurity.com Team
One of the world. The link for this article located at Sydney Morning Herald is no longer available. . The link for this article located at Sydney Morning Herald is no longer available.. world, article, located, sydney, morning, herald, longer. . LinuxSecurity.com Team
Today in Open Source: Does Linux Mint have a security problem? Or has the media made a mountain out of a molehill? . There have been disturbing reports in the media about Linux Mint having security problems. Is this something to worry about or has it been wildly overblown by the press? Muktware takes a look at this issue and refutes the claims made by a Canonical developer. The link for this article located at IT World is no longer available. . There have been disturbing reports in the media about Linux Mint having security problems. Is this s. today, source, linux, security, problem, media, mountain. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.