OSTIF Official

960 posts

OSTIF Official banner
OSTIF Official

OSTIF Official

@OSTIFofficial

Non-profit org that connects open-source projects with security resources. We are the Open Source Technology Improvement Fund.

Chicago, IL Katılım Mayıs 2015
800 Takip Edilen1.7K Takipçiler
Sabitlenmiş Tweet
OSTIF Official
OSTIF Official@OSTIFofficial·
Do you have an extra 5 minutes today you want to spend learning about open source security? OSTIF is proud to share our 2024 Annual Report today, covering the 60 open source security engagements we directed last year. See links 👇 to read about our efforts!
OSTIF Official tweet media
English
1
0
2
519
OSTIF Official
OSTIF Official@OSTIFofficial·
With that in mind, our Executive Director Derek Zimmer proposed a new program: a Bug of the Year trophy, given to the individual who finds the best bug published by OSTIF in a calendar year.
English
0
0
0
22
OSTIF Official
OSTIF Official@OSTIFofficial·
While reflecting on our past 10 years, we revisited vulnerabilities discovered during OSTIF audits. As a result of our work, several hundred bugs a year are discovered on average.
English
1
0
0
25
OSTIF Official
OSTIF Official@OSTIFofficial·
Miss our last OSTIF meetup? You can catch the recording here of Robin David, Software Security Researcher and Research Lead at Quarkslab, presenting "Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure". #OSTIF #OpenSource #bitcoin
OSTIF Official tweet media
English
1
0
1
104
OSTIF Official
OSTIF Official@OSTIFofficial·
With the help of @7aSecurity, this project received custom security testing, documentation, and tooling contributing to Stork’s ongoing security and development work.  Full post here: ostif.org/stork-audit-co…
English
0
0
0
12
OSTIF Official
OSTIF Official@OSTIFofficial·
@OSTIFofficial is proud to share the results of our security audit of Stork. Stork is an open source project developed by the Internet Systems Consortium (ISC) that acts as an administrative interface for monitoring, maintaining, and surveilling Kea servers. #OSTIF #7ASecurity
OSTIF Official tweet media
English
1
0
0
81
OSTIF Official
OSTIF Official@OSTIFofficial·
While there is a lot to address, an important point of this story sticks out to us at OSTIF- that it was best practices, the secondary review of code before a push, that caught this before disaster struck.
English
0
0
1
36
OSTIF Official
OSTIF Official@OSTIFofficial·
For the past 4 years, OSTIF has run a Managed Audit Program for the CNCF. We’ve audited 33 projects with maintainers all over the world, reinforcing the security of cloud native open source for billions of users. Read report here: ostif.org/cncfmanagedpro… #OSTIF #CNCF #Report
OSTIF Official tweet media
English
0
1
4
393
OSTIF Official
OSTIF Official@OSTIFofficial·
Make sure you attend the live events if you want to participate in the Q&A, as those aren't recorded! Also make sure you're subscribed to our Luma calendar for notifications of any new meetups! luma.com/ostif-meetups #OSTIF #meetup #audit
English
0
0
0
37
OSTIF Official
OSTIF Official@OSTIFofficial·
Join us next Wednesday at 11AM CST for an OSTIF meetup with Robin David, Software Security Researcher and Research Lead at Quarkslab, presenting "Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure". Link in 🧵👇 #OSTIF #bitcoin
OSTIF Official tweet media
English
1
2
3
174
OSTIF Official
OSTIF Official@OSTIFofficial·
RSVP for next week's meetup with @kaepora, Senior Applied Cryptography Auditor at Cure53 presenting "High Assurance Cryptography and the Ethics of Disclosure". RSVPing adds the event to your calendar and lets us know you're coming! luma.com/xc4yuezb #OSTIF #OpenSource
English
0
1
2
859
OSTIF Official
OSTIF Official@OSTIFofficial·
@OSTIFofficial is proud to share the results of our security audit of zlib. Zlib is an open source lossless data-compression library for use on virtually any computer hardware and operating system. See 🧵 below 👇 #OSTIF #7ASecurity #audit #zlib
OSTIF Official tweet media
English
1
1
0
167
OSTIF Official
OSTIF Official@OSTIFofficial·
Join us in 2 weeks on Wednesday, February 25th, for an OSTIF meetup with @kaepora, Senior Applied Cryptography Auditor at Cure53 presenting "High Assurance Cryptography and the Ethics of Disclosure". #OSTIF #OpenSource #disclosure
OSTIF Official tweet media
English
1
1
3
698