Skip to main content

标 题: UMN必然在历史上留下一笔, 我支持lu教授, 打破虚假安全幻想

 发信人: mitbbs2715 (好吃不懒做), 信区: Programming
标  题: UMN必然在历史上留下一笔, 我支持lu教授, 打破虚假安全幻想
发信站: BBS 未名空间站 (Fri Apr 23 05:08:41 2021, 美东)

其实我一直就说公司不能信任开源代码, 因为里面垃圾多, 甚至很多恶意添加的漏洞,
NAS, CIA, 黑客都干过. 不是一次两次的, BSD 审核那么严格, 都报出来NAS给钱给
reviewer让恶意代码通过审核的事情(9x, 200x, 爆过不止一次),不要说linux这么松散
的审核体系了.

OSS 最坏的是给人漏洞容易被发现的错觉, 让大家麻痹大意, 不去仔细审核, UMN这次
打破了OSS安全的幻境是好事. 实际上, Lu证明之前插入的漏洞就不会少, 只是很难发
现.

这告诉我们, OSS 必须要严格审核, 未自己审核过的代码能不用就不用. 公司必须使用
人工智能自动审核对所有OSS进行深度审查, 刻不容缓.

Lu教授是英雄

Comments

Popular posts from this blog

CKA Simulator Kubernetes 1.22

  https://killer.sh Pre Setup Once you've gained access to your terminal it might be wise to spend ~1 minute to setup your environment. You could set these: alias k = kubectl                         # will already be pre-configured export do = "--dry-run=client -o yaml"     # k get pod x $do export now = "--force --grace-period 0"   # k delete pod x $now Vim To make vim use 2 spaces for a tab edit ~/.vimrc to contain: set tabstop=2 set expandtab set shiftwidth=2 More setup suggestions are in the tips section .     Question 1 | Contexts Task weight: 1%   You have access to multiple clusters from your main terminal through kubectl contexts. Write all those context names into /opt/course/1/contexts . Next write a command to display the current context into /opt/course/1/context_default_kubectl.sh , the command should use kubectl . Finally write a second command doing the same thing into ...

OWASP Top 10 Threats and Mitigations Exam - Single Select

Last updated 4 Aug 11 Course Title: OWASP Top 10 Threats and Mitigation Exam Questions - Single Select 1) Which of the following consequences is most likely to occur due to an injection attack? Spoofing Cross-site request forgery Denial of service   Correct Insecure direct object references 2) Your application is created using a language that does not support a clear distinction between code and data. Which vulnerability is most likely to occur in your application? Injection   Correct Insecure direct object references Failure to restrict URL access Insufficient transport layer protection 3) Which of the following scenarios is most likely to cause an injection attack? Unvalidated input is embedded in an instruction stream.   Correct Unvalidated input can be distinguished from valid instructions. A Web application does not validate a client’s access to a resource. A Web action performs an operation on behalf of the user without checkin...