|
Proposal: Stop requiring X-XSS-Protection, require CSP with explanation, for criterion hardened_sites 4 messages
I propose that for the "hardened_sites" criterion we stop requiring the HTTP header X-XSS-Protection, and that we require CSP & explain why. Here's the background. The Linux kernel is failing to meet
I propose that for the "hardened_sites" criterion we stop requiring the HTTP header X-XSS-Protection, and that we require CSP & explain why. Here's the background. The Linux kernel is failing to meet
|
By David A. Wheeler
·
|
|
[EXT] [CII-badges] Proposal: Stop requiring X-XSS-Protection, require CSP with explanation, for criterion hardened_sites
This change makes perfect since. Best, Jason N. Dossett, Ph.D. Research Staff Member Institute for Defense Analyses 4850 Mark Center Drive, Alexandria, VA 22311 Phone: 703-578-2773 Email: jdossett@...
This change makes perfect since. Best, Jason N. Dossett, Ph.D. Research Staff Member Institute for Defense Analyses 4850 Mark Center Drive, Alexandria, VA 22311 Phone: 703-578-2773 Email: jdossett@...
|
By Jason Dossett
·
|
|
Projects that received badges (monthly summary)
This is an automated monthly status report of the best practices badge application covering the month 2020-04. Here are some selected statistics for most recent completed month, preceded by the same s
This is an automated monthly status report of the best practices badge application covering the month 2020-04. Here are some selected statistics for most recent completed month, preceded by the same s
|
By badgeapp@...
·
|
|
Projects that received badges (monthly summary)
This is an automated monthly status report of the best practices badge application covering the month 2020-03. Here are some selected statistics for most recent completed month, preceded by the same s
This is an automated monthly status report of the best practices badge application covering the month 2020-03. Here are some selected statistics for most recent completed month, preceded by the same s
|
By badgeapp@...
·
|
|
I now work at the Linux Foundation!
All: As of today, I am a full-time employee of the Linux Foundation. My official title is "Director, Open Source Supply Chain Security". Basically, I'm going to working full-time on various efforts to
All: As of today, I am a full-time employee of the Linux Foundation. My official title is "Director, Open Source Supply Chain Security". Basically, I'm going to working full-time on various efforts to
|
By David A. Wheeler
·
|
|
Projects that received badges (monthly summary)
This is an automated monthly status report of the best practices badge application covering the month 2020-02. Here are some selected statistics for most recent completed month, preceded by the same s
This is an automated monthly status report of the best practices badge application covering the month 2020-02. Here are some selected statistics for most recent completed month, preceded by the same s
|
By badgeapp@...
·
|
|
More on spam countering efforts
FYI, we have implemented some simple spam countering mechanisms on the best practices badge application. Most trivially, whenever someone tries to create a project badge entry, they now see this: We'v
FYI, we have implemented some simple spam countering mechanisms on the best practices badge application. Most trivially, whenever someone tries to create a project badge entry, they now see this: We'v
|
By David A. Wheeler
·
|
|
Projects that received badges (monthly summary)
This is an automated monthly status report of the best practices badge application covering the month 2020-01. Here are some selected statistics for most recent completed month, preceded by the same s
This is an automated monthly status report of the best practices badge application covering the month 2020-01. Here are some selected statistics for most recent completed month, preceded by the same s
|
By badgeapp@...
·
|
|
Need some advice addressing "unfixable" publicly known vulnerabilities 3 messages
CII Badging community, I just updated the ESAPI project on the CII Badges site to account for a newly discovered CVE. Specifically, I added this verbiage: Most Software Compositional Analysis tools /
CII Badging community, I just updated the ESAPI project on the CII Badges site to account for a newly discovered CVE. Specifically, I added this verbiage: Most Software Compositional Analysis tools /
|
By Kevin W. Wall
·
|
|
Did logins change because of the CII-Badges new spam defenses? 2 messages
David, et al, Does the username / password for https://bestpractices.coreinfrastructure.org/ now require it to be done via GitHub? I just tried to login using my Gmail account (which was how I registe
David, et al, Does the username / password for https://bestpractices.coreinfrastructure.org/ now require it to be done via GitHub? I just tried to login using my Gmail account (which was how I registe
|
By Kevin W. Wall
·
|
|
Projects totals for last month impacted by spam countering efforts
Some of you may have noticed that the “Total Projects” went down last month (2855 to 2852), but the number of projects at 25%+ went up (1089 to 1114). The explanation is that we’ve been working to del
Some of you may have noticed that the “Total Projects” went down last month (2855 to 2852), but the number of projects at 25%+ went up (1089 to 1114). The explanation is that we’ve been working to del
|
By David A. Wheeler
·
|
|
Projects that received badges (monthly summary)
This is an automated monthly status report of the best practices badge application covering the month 2019-12. Here are some selected statistics for most recent completed month, preceded by the same s
This is an automated monthly status report of the best practices badge application covering the month 2019-12. Here are some selected statistics for most recent completed month, preceded by the same s
|
By badgeapp@...
·
|
|
Suggestions on countering spammers? 6 messages
Sadly, spammers have started to add nonsense "projects" to the CII Best Practices site at a higher rate than before. It appears to be all SEO-related fraud. I suppose that was inevitable, and I guess
Sadly, spammers have started to add nonsense "projects" to the CII Best Practices site at a higher rate than before. It appears to be all SEO-related fraud. I suppose that was inevitable, and I guess
|
By David A. Wheeler
·
|
|
Projects that received badges (monthly summary)
This is an automated monthly status report of the best practices badge application covering the month 2019-11. Here are some selected statistics for most recent completed month, preceded by the same s
This is an automated monthly status report of the best practices badge application covering the month 2019-11. Here are some selected statistics for most recent completed month, preceded by the same s
|
By badgeapp@...
·
|
|
Projects that received badges (monthly summary)
This is an automated monthly status report of the best practices badge application covering the month 2019-10. Here are some selected statistics for most recent completed month, preceded by the same s
This is an automated monthly status report of the best practices badge application covering the month 2019-10. Here are some selected statistics for most recent completed month, preceded by the same s
|
By badgeapp@...
·
|
|
Proposal: Use CVSS version 3, not version 2, in CII Best Practices measures 4 messages
A very few of our criteria mention CVSS (a method for estimating the risk from a vulnerability). For example, [dynamic_analysis_fixed] says this: CRITERION: "All medium and high severity exploitable v
A very few of our criteria mention CVSS (a method for estimating the risk from a vulnerability). For example, [dynamic_analysis_fixed] says this: CRITERION: "All medium and high severity exploitable v
|
By David A. Wheeler
·
|
|
Projects that received badges (monthly summary)
This is an automated monthly status report of the best practices badge application covering the month 2019-09. Here are some selected statistics for most recent completed month, preceded by the same s
This is an automated monthly status report of the best practices badge application covering the month 2019-09. Here are some selected statistics for most recent completed month, preceded by the same s
|
By badgeapp@...
·
|
|
FYI: CII Best Practices badge site continues to get updates
FYI: We continue the work keep the CII Best Practices badge site working smoothly. In particular, we've done a number of updates to keep things going over the last several months. You generally should
FYI: We continue the work keep the CII Best Practices badge site working smoothly. In particular, we've done a number of updates to keep things going over the last several months. You generally should
|
By David A. Wheeler
·
|
|
Projects that received badges (monthly summary)
This is an automated monthly status report of the best practices badge application covering the month 2019-08. Here are some selected statistics for most recent completed month, preceded by the same s
This is an automated monthly status report of the best practices badge application covering the month 2019-08. Here are some selected statistics for most recent completed month, preceded by the same s
|
By badgeapp@...
·
|
|
CII Best Practices badge application not affected by EU GDPR "like" button issues
The Court of Justice of the European Union (ECJ) has ruled that online websites that embed a Facebook "Like" button are responsible for the data they send to Facebook and are liable for the same penal
The Court of Justice of the European Union (ECJ) has ruled that online websites that embed a Facebook "Like" button are responsible for the data they send to Facebook and are liable for the same penal
|
By David A. Wheeler
·
|