Security Blog

The latest news and insights from Google on security and safety on the Internet

Contributing To Open Source Software Security

5 maggio 2008
Share on Twitter Share on Facebook
Google

11 commenti :

Grove Group ha detto...
Questo commento è stato eliminato da un amministratore del blog.
11 maggio 2008 alle ore 10:20
Unknown ha detto...

The "request a review" option is gone from my webmaster page for metrotimes.com, and I need to remove the "This site may harm your computer" message now that the hack has been fixed. What should I do?

12 maggio 2008 alle ore 12:20
yaminiseotips.com ha detto...

Hi this is danyy sorry to use this i came across your blog its very interesting your content also very nice if you like any design for your site like animated header at top of the blog i will provide you for free of cost in return i need link from your blog if interested please let me know.

Regards
Danyy
dn.danyy@gmail.com

26 giugno 2008 alle ore 06:50
Nima ha detto...
Questo commento è stato eliminato da un amministratore del blog.
18 luglio 2008 alle ore 12:20
Grove Group ha detto...
Questo commento è stato eliminato da un amministratore del blog.
21 luglio 2008 alle ore 09:20
Unknown ha detto...

Olha eu adoro o orkut, mas eu vou dar uma opinião importante que eu sei que os outros usuários vão gostar.Seria bom que a gente tivesse a opÇão de escolher a cor do orkut,pois é muito chato se ter uma cor padrão para uma coisa que é da gente, sabe? Espero que gostem da idéia e ponha ela em ação.Obrigado desde já...

2 agosto 2008 alle ore 14:04
Anonimo ha detto...
Questo commento è stato eliminato da un amministratore del blog.
30 agosto 2008 alle ore 06:54
Anonimo ha detto...
Questo commento è stato eliminato da un amministratore del blog.
9 settembre 2008 alle ore 07:55
Anonimo ha detto...

I' sorry to say oCERT was not helpful. In fact I'm really considering they are doing social engineering. In reviewing my open source project, Andrea Barisani was arrogant and dogmatic. oCERT claimed to have discovered a flaw, then they did such noise that every single virus witter would be aware of this flaw, then oCERT provided a patch that breaks functionality and proceeded to distribute this patch saying it was generated by project maintainer. Finally they announced an embargo and then they broken the embargo saying the info was leaked. Please, oCERT stay away of open source projects.

29 marzo 2009 alle ore 09:55
Unknown ha detto...

ememe: I don't know who are you nor what you are talking about. Provide more details if you want to make an informative post instead of just trolling.

oCERT never breaks embargo, if someone else involved in the process (oCERT is not the only party) leaks and breaks an embargo then it's oCERT duty to release an advisory as the information is public anyway.

oCERT doesn't do "social engineering" but this statement comments itself to be honest. Our reputation is well established, just look at our advisories and our members to get an idea.

If by chance you are referring to our last lcms advisory then you should probably read some comments from here:

http://www.valdyas.org/fading/index.cgi/software/beware_of_friends_bearing_patches.comments

as well as the advisory itself.

Your mention of "virus witter" (I assume you mean virus writers) is similiar to lcms maintainer.....go figure.

Andrea Barisani
lcars@ocert.org

6 aprile 2009 alle ore 11:42
Marti Maria ha detto...

A friend pointed out this blog...

No, I was not who posted that crap. This is obviously a troll using some complains I did to create a flame war. My complains were about a patch, not about Andrea. I never got personal against Andrea. Also, I think this post is highly offensive.

I would have no problems signing my comments, even if those are strong words, as you probably already know.
Don't feed the troll.
Marti Maria
www.littlecms.com

13 aprile 2009 alle ore 10:24

Posta un commento

  

Etichette


  • #sharethemicincyber
  • #supplychain #security #opensource
  • android
  • android security
  • android tr
  • app security
  • big data
  • biometrics
  • blackhat
  • C++
  • chrome
  • chrome enterprise
  • chrome security
  • connected devices
  • CTF
  • diversity
  • encryption
  • federated learning
  • fuzzing
  • Gboard
  • google play
  • google play protect
  • hacking
  • interoperability
  • iot security
  • kubernetes
  • linux kernel
  • memory safety
  • Open Source
  • pha family highlights
  • pixel
  • privacy
  • private compute core
  • Rowhammer
  • rust
  • Security
  • security rewards program
  • sigstore
  • spyware
  • supply chain
  • targeted spyware
  • tensor
  • Titan M2
  • VDP
  • vulnerabilities
  • workshop


Archive


  •     2025
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2024
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2023
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2022
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2021
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2020
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2019
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2018
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2017
    • dic
    • nov
    • ott
    • set
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2016
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2015
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2014
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • apr
    • mar
    • feb
    • gen
  •     2013
    • dic
    • nov
    • ott
    • ago
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2012
    • dic
    • set
    • ago
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2011
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
  •     2010
    • nov
    • ott
    • set
    • ago
    • lug
    • mag
    • apr
    • mar
  •     2009
    • nov
    • ott
    • ago
    • lug
    • giu
    • mar
  •     2008
    • dic
    • nov
    • ott
    • ago
    • lug
    • mag
    • feb
  •     2007
    • nov
    • ott
    • set
    • lug
    • giu
    • mag

Feed

Follow
Give us feedback in our Product Forums.
  • Google
  • Privacy
  • Terms