• 0 Posts
  • 39 Comments
Joined 2 years ago
cake
Cake day: June 9th, 2023

help-circle




  • Hopefully more projects take advantage of vulnerability scanning and monitoring tools like those in this OWASP list https://owasp.org/www-community/Free_for_Open_Source_Application_Security_Tools, have good code quality standards to make their projects easier to understand and evaluate, contribute and respond to CVE reports, and get third party security auditing.

    All of that is hard to motivated those throwing their code out to the world only to share how they scratched their itch to perform. I think we need a combination of governments and non-profits providing incentives / grants to projects doing good practices, document and provide trusted a forum to validate vulnerabilities, give some backing to “trusted” frameworks, and provide some vulnerability and auditing themselves.

    The recent EU push into more government open source usage will help as they will be more incentivized to secure the pipelines and everyone will benefit the fruits of that firehose of funding.








  • I think masto and indie/fedi microblogging makes sense for seeing the empherial now that you are interested not topic based content. (Especially on small niche instances via the local feed) its a also great way to meet like minded people and build longer lasting connections as you see more of a person via their stream than only seeing them in niche spaces. Granted many people single topic their accounts, but masto is way more personal and less influencer type accounts than Twitter was, though those accounts exist too. You can still follow topics, but that’s a way of finding new people with shared interests not necessarily only deep diving in a topic.

    Lemmy and topic forums in general are great at deep diving in a topic, but since you stay in the niche while you might see people frequent in that niche you really don’t have those longer interactions. Some forum communities try to mitigate this by having general chat posts or chat rooms on the side.

    Different kinds of social media have their strengths.







  • Edit: I tried writing out an explanation of how defederation works, but Lemmy has a few more gotchas with communities being owned on different instances. See https://lemmy.world/comment/276067 for some info about how the Beehaw defederation of LW worked.

    Meta can and already probably does have crawler bots capturing the data anyway. Anything public on the internet you should assume is consumable by these types of companies.

    Additionally, instances of ActivityPub platforms can further require releases of ownership if they have a TOS stating so in their registration (like any other website). IANAL but I would reach out to one to discuss your options on restricting the usage of your works if that is a concern. In general, I think the safest option is to host your own works and share only the links and what you don’t mind being scraped on sites like these. Some AP platforms like Mastodon Glitch Edition allow local-only (non-federated) posts, but as far as I know Lemmy don’t support that yet.