Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
daniel:// stenberg://
@bagder@mastodon.social  路  activity timestamp 4 days ago

Ahead of tomorrow's release of four new #curl CVEs I want you to know: we do our very best to secure curl every step of the way. Security is hard.

Code style
Banned functions
Complexity checks
Human reviews
Review bots
No binary blobs
No confusables
Document everything
Many tests
Cl like crazy
All the picky compiler options and -Werror
Valgrind and sanitizers
Static code analyzers
Fuzzing (in Cl and non-stop)
Cl jobs never 鈥渨rite back"
Reproducible releases
Signed releases, commits, tags
code audits
2fa for all committers
Code style Banned functions Complexity checks Human reviews Review bots No binary blobs No confusables Document everything Many tests Cl like crazy All the picky compiler options and -Werror Valgrind and sanitizers Static code analyzers Fuzzing (in Cl and non-stop) Cl jobs never 鈥渨rite back" Reproducible releases Signed releases, commits, tags code audits 2fa for all committers
Code style Banned functions Complexity checks Human reviews Review bots No binary blobs No confusables Document everything Many tests Cl like crazy All the picky compiler options and -Werror Valgrind and sanitizers Static code analyzers Fuzzing (in Cl and non-stop) Cl jobs never 鈥渨rite back" Reproducible releases Signed releases, commits, tags code audits 2fa for all committers
3
  • Copy link
  • Flag this post
  • Block
Pianosaurus 馃暣
@pianosaurus@c.im replied  路  activity timestamp 4 days ago

@bagder Ken Thompson would have pointed out "No binary blobs except the compiler; you may be compromised."

1
  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
@bagder@mastodon.social replied  路  activity timestamp 4 days ago

@pianosaurus also one of the critical lessons from the xz attack!

  • Copy link
  • Flag this comment
  • Block
Graham Sutherland / Polynomial
@gsuberland@chaos.social replied  路  activity timestamp 4 days ago

@bagder red green colour blindness test [HARD MODE]

  • Copy link
  • Flag this comment
  • Block
advokatt
@km@mastodon.babb.no replied  路  activity timestamp 4 days ago

@bagder i feel something is missing there

1
  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
@bagder@mastodon.social replied  路  activity timestamp 4 days ago

@km I should probably distribute them a little different unless I can think of more boxes to mention...

1
  • Copy link
  • Flag this comment
  • Block
advokatt
@km@mastodon.babb.no replied  路  activity timestamp 4 days ago

@bagder slop protection? i mean, you have it!

  • Copy link
  • Flag this comment
  • Block
Log in

Gnar 馃敟 social

This is a Bonfire Federated social instance for those that enjoy gnarly adventures. Whether it's shredding mountains or slaying guitars, from action sports to art.

Gnar 馃敟 social: About 路 Code of conduct 路 Privacy 路 Users 路 Instances
Gnar;馃敟 social 路 1.0.0-rc.3.6 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login