Security News

DARPA Is Developing an Open-Source Voting System
2019-03-14 18:20

This sounds like a good development: ...a new $10 million contract the Defense Department's Defense Advanced Research Projects Agency (DARPA) has launched to design and build a secure voting...

Open-source 64-ish-bit serial number gen snafu sparks TLS security cert revoke runaround
2019-03-13 18:12

64 bits of cert ID on the wall, 64 bits of ID. Take the top bit down, don't pass it around, 63 bits of cert ID on the wall... A bunfight over a controversial UAE mobile security company led to the...

Open-source keygen snafu sparks 63-bit TLS cert revoke runaround
2019-03-13 18:12

What a difference a bit makes. 64 little flowers... brought the revokes and the scowls A mailing list bunfight over a controversial UAE mobile security company led to the discovery that millions...

Do bug bounties help open source security?
2019-03-09 15:45

The biggest problem of targeting open source software to find security issues relates to IT.

Windows Calculator is going open source
2019-03-08 11:46

Can the combined power of the world’s developers possibly improve the iconic Windows Calculator app? Microsoft seems to think so.

Fortanix Releases Open Source SDK for Intel SGX Enclaves
2019-03-06 19:01

Runtime encryption company Fortanix has launched a free and open source software development kit (SDK) for building Intel Software Guard Extensions (SGX) applications. read more

OSSPatcher: Automated mobile application patching for bugs in open source libraries
2019-02-26 11:09

Researchers from the Georgia Tech and Peking University are working on OSSPatcher, a system for automatic patching of vulnerable open source libraries included in mobile applications. Fulfilling a...

Google Open Sources Fuzzing Platform
2019-02-08 15:04

Google announced this week that it has open sourced ClusterFuzz, the fuzzing infrastructure it built to help finding memory corruption bugs in Chrome. read more

World's favourite open-source PDF interpreter needs patching (again)
2019-01-24 13:32

Still afraid of no ghost? You didn't read the script Google Project Zero bug-hunter Tavis Ormandy took a "random look at the new release" of Ghostscript, and turned up a vulnerability that works...

EU Offering Bug Bounties on Critical Open-Source Software
2019-01-09 13:05

The EU is offering "bug bounties on Free Software projects that the EU institutions rely on." Slashdot thread....