Elektrine lite

← Feed

Stefano Zacchiroli

zacchiro@mastodon.xyz

<p>Full professor of computer science at Polytechnic Institute of Paris. Co-founder &amp; CSO Software Heritage. Free Software activist. Previously: Debian leader, Open Source Initiative board.</p>

Posts

  • Post #3960792

    &quot;There is no Commons. You&#39;re just DoS-ing someone else&#39;s infrastructure.&quot;

  • Post #1408868

    Repeat after me: if #Firefox stops being maintained, #LibreWolf is not a viable long-term alternative (nor is any other Firefox-based web browser).

  • Post #1157752

    My colleagues at CEA in #Paris, France, are hiring a 2-year #postdoc to work on the joint research project #SECUBIC about #fuzzing binaries to identify #backdoors. (See this recently joint work at #ICSE2025 for previous results: https://upsilon.cc/~zack/research/publications/icse-2025-rosa-fuzzing.pdf ) If you&amp;#39;re interested, or know interested candidates, head to: https://secubic-ptcc.github.io/jobs/open/2025/04/02/postdoc-supply-chain-binary-fuzzing.html for details. #getfedihired

  • Post #1157750

    &amp;quot;If you have a buggy program, you can fix it or call it AI&amp;quot; - David Parnas, #ICSE2025

  • Post #1157749

    Congrats to my coauthors @plumtrie, E. Decoux, and M. Marcozzi for the best artifact #award at #ICSE2025. 99% of the merit for this goes to Dimitri (in the picture), who did all the heavy lifting, chapeau. The artifact itself is worth looking at as blueprint/example for students and colleagues working on replication packages in complex contexts (like ours here, having to replicate long running fuzzing experiments).

  • Post #1157747

    Advice to young colleagues when preparing rebuttals for papers submitted to major academic conferences or journals. When there is a soft limit (e.g., 1000 words) it is in your best interest to make your key rebuttal arguments fit that limit. And only later, if you really have to, add additional arguments/details after that limit, clearly marking the separation between the two. What you should not do, is just ignore the limit and submit a free-flow long text. It will not serve your cause.

  • Post #1157746

    I am recruiting a postdoctoral researcher to work at Polytechnic Institute of Paris for 30 months, in the fields of #SoftwareEngineering and #Cybersecurity The recruited person will work on leveraging @swheritage as a knowledge base to improve the state of the art of (binary) software composition analysis (SCA), to detect the presence and details of #OpenSource software shipped within IT products. See https://institutminestelecom.recruitee.com/l/en/o/post-doctorante-ou-post-doctorant-en-genie-...

  • Post #1055816

    Welcoming @benhermann at #SoftwareHeritage headquarters today, to talk about « What We Learned in 15 Years of #ArtifactEvaluation » #research #digitalpreservation #softwareEngineering

  • Post #1055815

    The « Software Source Code Exhbition », co-curated by Mathilde Fichen from @swheritage, is now on display at Cité des Sciences et de l&amp;#39;Industrie, the most prominent science museum in #Paris, France. https://www.cite-sciences.fr/fr/au-programme/lieux-ressources/carrefour-numerique2/evenements/source-code-exhibition It&amp;#39;s until March 25th, 2026 and in the free part of the museum, no ticket needed. If you are around and into software, I recommend visiting it, as it&amp;#39;s super...

  • Post #1055813

    In empirical software engineering research, we use &amp;quot;replication package&amp;quot; as term of art for artifacts shared to enable others to rerun a scientific experiment. Sadly, it is a semantically wrong expression. It should be called &amp;quot;reproducibility package&amp;quot; instead. The former (replication) is for a &amp;quot;Different team, [with a] different experimental setup&amp;quot; to rerun experiment, which is not the goal. The latter (reproducibility) is for a &amp;quot...

  • Post #600856

    WOW! Full #security devroom at #FOSDEM, for the presentation of &amp;quot;ROSA: finding #backdoors with #fuzzing&amp;quot; by my fellow co-authors @plumtrie and M. Marcozzi. More about this work in the full paper at https://arxiv.org/abs/2505.08544 (#openaccess, of course)

  • Post #600854

    Is there a good URL scheme to use as href link when publishing Matrix account info on the web? Ideally it should be something that automatically open a chat to you if you are already on Matrix somehow, or explains how to create an account (on whatever server one likes) if not.

  • Post #600851

    In « Promises, Perils, and (Timely) Heuristics for Mining Coding Agent Activity » (#openaccess preprint at: https://hal.science/hal-05487636) we review the potential and risks of mining agent-based coding activities in empirical #SoftwareEngineering #research. To be presented at the #MSR2026 conference this summer.

  • Post #600850

    Just noticed that the national recruitment platform for teachers/researchers civil servants in #France is now called &amp;quot;Odyssée&amp;quot;. 10/10 for not missing a good joke opportunity.

  • Post #196590

    At #FOSDEM, 40% of attendees at the opening talk (in a full room with 1200 seats) raised their hand to signal this is the first time they attend. This is super exciting for an old fart like me, who has been attending for 25 years. There is hope for the future! Welcome fellow hackers, and have a blast.