I wrote a blog post
You don't have a supply chain, you have a supply soup
This is something I want to spend some time investigating in the future, it's all vastly more complicated and weird than we think it is
https://opensourcesecurity.io/2026/07-supply-soup/
Remote
Josh Bressers
@joshbressers@infosec.exchange
Podcaster (http://opensourcesecuritypodcast.com http://hackerhistory.com) - Blogger (http://opensourcesecurity.io) - He/Him
0 Followers
0 Following
50 Posts
Joined April 20, 2017
Podcast:
Web:
Cookies?:
Yes please
TTY:
1
Signal:
joshbressers.01
Open post
Replying to @grumpygamer@mastodon.gamedev.place
@grumpygamer@mastodon.gamedev.place @Viss@mastodon.social I don’t understand how this isn’t just the status quo
If you tried to claim something was the fault of autocorrect everyone would call you an idiot
And they would be right
19
0
3
0
Open post
Replying to @gregkh@social.kernel.org
@gregkh @wdormann @Viss
This post got into my head. I think you're right, the days of coordination are over
So I wrote it down
https://opensourcesecurity.io/2026/05-vulnerability-economics/
37
53
24
3
Open post
I had a chat with Lori Lorusso and Niko Matsakis about the Rust Foundation Maintainers Fund
Funding open source is a huge topic right now, the Rust Foundation has some great ideas. It will be exciting to watch this one grow and evolve
https://opensourcesecurity.io/2026/2026-07-rfmf-lori-niko/
#OpenSourceSecurity #rust #RustFoundation
9
0
5
0
Open post
Open post
Replying to @andrewnez@mastodon.social
@andrewnez@mastodon.social this is a work of art
Well done
4
0
0
0
Open post
I had the pleasure to chat with @allanfriedman@infosec.exchange about Bill of Materials things on #OpenSourceSecurity
We touched on SBOMs, HBOMs, AIBOMs, and even some other BOM types I can't remember now
Allan is always fun to chat with, and he has encyclopedic knowledge about the BOM universe
https://opensourcesecurity.io/2026/2026-06-allan-omnibom/
7
0
9
0
Open post
I miss the days when my spellchecker just worked
4
1
0
0
Open post
Replying to @andrewnez@mastodon.social
@andrewnez@mastodon.social @Di4na@hachyderm.io @Rairii@labyrinth.zone did someone finally rewrite curl in a weekend?
2
0
0
0
Open post
On this episode of @CypherCon@infosec.exchange #HackerHistory I talk to Michael Lenz
It's a great story about starting out with what we now call retro computers, building a SOC and SIEM before those were really things, and eventually putting focus into Burbsec community meetups
https://hackerhistory.com/podcast/the-history-of-michael-lenz/
6
0
3
0
Open post
Replying to @andrewnez@mastodon.social
@andrewnez@mastodon.social The number of people who understand this is an extremely small number
My poster child for this is
https://github.com/ossf/tac/issues/101
It's filled with opinions that don't change even when shown the data. Those are the same people that then built scorecard
12
3
4
0
Open post
Replying to @mattblaze@federate.social
@mattblaze@federate.social @robpike@hachyderm.io hey now. It’s TWO resistors!
8
1
0
0
Open post
Replying to @wdormann@infosec.exchange
@wdormann@infosec.exchange I wonder if it will get actual 0days or just be a slopfest
1
1
0
0
Open post
Replying to @wdormann@infosec.exchange
@wdormann@infosec.exchange Deer are assholes
So are squirrels
1
1
0
0
Open post
Replying to @jacques@mastodon.chester.id.au
1
0
0
0
Open post
Open post
Replying to @gregkh@social.kernel.org
5
0
0
0
Open post
Replying to @ancoghlan@mastodon.social
@ancoghlan@mastodon.social
I'm not opposed to a company employing people at a given project to get some advanced notice
The devil is in the details, but I think in many cases it could work
3
2
0
0
Open post
Replying to @gregkh@social.kernel.org
@gregkh @deftpunk @wdormann @Viss
You said this wasn't reported to the kernel security team
From where I sit (and I'm not in the middle of this) it seems like if you plan to make a website and give something a name, tell the securiy team
If you're OK with the current process though I shall trust you on this, you're the expert, I'm just the peanut gallery
3
2
0
0
Open post
Replying to @ryan@m29.us
@ryan@m29.us
When I chatted with @cadey@pony.social about Anubis, they called it a "waifuectomy", which is the best name for anything ever
https://opensourcesecurity.io/2026/2026-01-anubis-xe/
1
0
0
0
Open post
Replying to @Le_suisse@social.gerbet.me
@Le_suisse@social.gerbet.me @ariadne@social.treehouse.systems @gregkh@social.kernel.org @wdormann@infosec.exchange @Viss@mastodon.social @andrewnez@mastodon.social @Di4na@hachyderm.io
Yes! The #GCVE folks are really on the ball about all this
I would be willing to bet a milkshake they will be one of the more authoritative sources in the future
2
0
0
0
Open post
Replying to @ra6bit@infosec.exchange
@ra6bit@infosec.exchange @ariadne@social.treehouse.systems @gregkh@social.kernel.org @wdormann@infosec.exchange @Viss@mastodon.social @andrewnez@mastodon.social @Di4na@hachyderm.io
Every single time an open source database has been tried it has failed spectacularly. For whatever reason the consumers of that data take and give nothing back then the project dies
2
2
1
0
Open post
Replying to @andrewnez@mastodon.social
@andrewnez@mastodon.social @mainec@fromm.social you know it’s all of them :)
1
1
0
0
Open post
Replying to @siddhesh_p@mastodon.social
@siddhesh_p@mastodon.social @gregkh@social.kernel.org @wdormann@infosec.exchange @Viss@mastodon.social
Every project is really its own ecosystem
I think glibc does a really good job with CVEs
But I suspect if you go from 12 a year to 12 a month your process will have to change
It's possible you would adopt the "give it a CVE and move on" approach, or because there is so much attention from the distros you could get some extra help to deal with the volume
1
3
0
0
Open post
Replying to @ra6bit@infosec.exchange
@ra6bit@infosec.exchange @ariadne@social.treehouse.systems @gregkh@social.kernel.org @wdormann@infosec.exchange @Viss@mastodon.social @andrewnez@mastodon.social @Di4na@hachyderm.io
It's a very valid question that gets asked quite a bit
It *seems* like it's something should work. But sadly it doesn't
1
0
0
0
Open post
Replying to @Di4na@hachyderm.io
@Di4na@hachyderm.io @gregkh@social.kernel.org @wdormann@infosec.exchange @corsac@mastodon.social @Viss@mastodon.social
Yeah, this
Which then goes back to your comments about our tooling being horrid and makes updates slow and painful
1
0
0
0
Open post
Replying to @wdormann@infosec.exchange
1
15
0
0
Open post
Replying to @joshbressers@infosec.exchange
1
0
0
0
Open post
I might be missing something here
I'm seeing what I think is a pattern with all these vulnerability clearing houses coming out of the woodwork
The common theme seems to be "give us money and we will make sure you know about embargoed vulnerabilities"
It's hard to see the logical end to this is anything other than researchers just dropping 0days
0
2
0
0
Open post
Replying to @andrewnez@mastodon.social
@andrewnez@mastodon.social I dig this and I'm glad it's a big topic
Something I was thinking about during my morning bike ride after reading this, is it's sort of sideways comparison
Roads and bridges were built on purpose by the people who have to take care of them
Open source is more like I build a road through my back yard, and it suddenly becomes critical infrastructure because it's the only road to the new restaurant
I don't think that makes it less important, but it also is a weird problem to understand and solve
0
0
0
0
Open post
Replying to @gregkh@social.kernel.org
@gregkh@social.kernel.org @deftpunk@fosstodon.org @wdormann@infosec.exchange @Viss@mastodon.social
I do wonder sometimes how many of those CVEs you file could be a privilege escalation with a proper reproducer
I'm sure it's not zero
0
1
0
0
Open post
I had a chat with @joshcorman@infosec.exchange about securing critical infrastructure on #OSSPodcast
Josh is one of the best in the industry on this topic. He has a ton of interesting (and sometimes scary) things to say about it all
https://opensourcesecurity.io/2026/2026-07-critical-infrastructure-josh-corman/
0
1
0
0
Open post
Replying to @ariadne@social.treehouse.systems
@ariadne@social.treehouse.systems Ahhh, I didn't know it could already do PURLs, very nice!
Adding CPE certainly wouldn't hurt. and there are things CPE can identify PURL can't
I still hate them though :)
0
0
0
0
Open post
Replying to @andrewnez@mastodon.social
@andrewnez@mastodon.social
How nice of them to let you know
0
0
0
0
Open post
Replying to @sethmlarson@mastodon.social
@sethmlarson@mastodon.social @yossarian@infosec.exchange if AI says it’s true then it is
Embrace your destiny
0
0
0
0
Open post
Replying to @adamshostack@infosec.exchange
@adamshostack@infosec.exchange that’s just the sort of thing the AI would say!
0
0
0
0
Open post
Replying to @simplenomad@rigor-mortis.nmrc.org
@simplenomad@rigor-mortis.nmrc.org I’ve done several things like this and requested passing the EFF. The taxes weren’t going to be worth it
0
0
0
0
Open post
Replying to @ariadne@social.treehouse.systems
@ariadne@social.treehouse.systems this all reeks of Thatcher’s “there is no alternative” which is code for “shut up and let me destroy society “
0
0
0
0
Open post
Replying to @ariadne@social.treehouse.systems
@ariadne@social.treehouse.systems CPE sucks rocks. I would allow other identifiers like PURL also
0
1
0
0
Open post
Replying to @andrewnez@mastodon.social
@andrewnez@mastodon.social We can hope you've ruined the day for some well funded security company totally not illegally scraping your data :)
0
0
0
0
Open post
Open post
Replying to @bagder@mastodon.social
@bagder@mastodon.social the reply would probably be “what are YOU willing to pay for windows support” ;)
0
0
0
0
Open post
Replying to @ariadne@social.treehouse.systems
@ariadne@social.treehouse.systems For sure, that's a obvious hand waive to start the show
Until a bunch of 0days start to show up :)
0
0
0
0
Open post
Replying to @petrillic@hachyderm.io
@petrillic@hachyderm.io I assume that's just an empty file :)
0
0
0
0
Open post
Replying to @Di4na@hachyderm.io
@Di4na@hachyderm.io @gregkh@social.kernel.org @deftpunk@fosstodon.org @wdormann@infosec.exchange @Viss@mastodon.social
That's also a good point
It's extra frustrating when there's nothing us unwashed masses can do except wait
0
2
0
0
Open post
Replying to @wdormann@infosec.exchange
@wdormann@infosec.exchange I suggest you buy a feral wolf, that seems like the most practical solution
0
0
0
0
Open post
Replying to @andrewnez@mastodon.social
@andrewnez@mastodon.social That's all your satire posts :)
0
0
0
0
Open post
Replying to @notting@mas.to
@notting@mas.to This is a great idea
1) Find vulnerability
2) Bet on market for the next vulnerability to be found
3) Probably go to jail for fraud
4) Hahahahaha just kidding everything is fine
0
0
0
0
Open post
Replying to @andrewnez@mastodon.social
@andrewnez@mastodon.social @Viss@mastodon.social
Poe's Law FTW!!!
0
0
0
0