Jean-Baptiste Maillet

Hardcore embedded C/C++ caveman.
Supply chain cybersecurity, SBOM , vulnerability management.
#embedded #linux #oss #psirt

Jean-Baptiste Mailletjbm@infosec.exchange
2025-05-28

As for me, I consider CISA's work on SBOM and VEX as dead. Same for vulnrichment. *Maybe* KEV would survive. :thinkgoing:

This is pure personal speculation of course, I'm not an ex-insider like you @todb (not even familiar with the ins and outs of US gov agencies, from 🥖 here).

Jean-Baptiste Maillet boosted:
Alexandre Dulaunoyadulau@infosec.exchange
2025-05-28

Spotted yet another "NIS 2 certified" title on LinkedIn. Impressive, considering NIS 2 doesn't actually have a certification.

Are training agencies just inventing fantasy diplomas so people can avoid reading the actual NIS 2 directive?

Maybe we need a "Certified NIS 2 Reader" badge, read the document once, and you're more qualified than half the certifications out there.

#certification #nis2 #cybersecurity

Jean-Baptiste Mailletjbm@infosec.exchange
2025-05-27

I'd add another requirement:
* able to import Pocket data. Pocket can export to CSV, see support.mozilla.org/en-US/kb/e

(Also: the news is spreading in mainstream media, with several lists of alternatives.)

Jean-Baptiste Mailletjbm@infosec.exchange
2025-05-27

Mozilla is shutting down its Pocket service:
support.mozilla.org/en-US/kb/f

I'm looking for an alternative, preferably open source, possibly freemium (I used to pay for Pocket). Bill of requirements:
* browser extension, Firefox / Chrome
* Android application
* eReader (Kobo) would be great, but oh well...
* I don't care about the social part ("trending articles")

Any suggestion?

If you don't know what Pocket is, let's say it resemble a multi-client distributed bookmark service, with a striped down, unobtrusive reading mode:
en.wikipedia.org/wiki/Pocket_(
#mozilla #pocket #readitlater

Jean-Baptiste Maillet boosted:
🌈☔🌦️🍄🌱🍉wmd@chaos.social
2025-05-26

Pretty good description on offices.

#work #religion

Jean-Baptiste Mailletjbm@infosec.exchange
2025-05-22

...but this collides with the EUVD FAQ itself, which refer to the EUVD as related to the NIS2 directive, not the CRA.
Any EU regulation scholar around here?
:thinkgoing:
@adulau

Jean-Baptiste Mailletjbm@infosec.exchange
2025-05-22

...as well as the EUVD.
@adulau

Jean-Baptiste Mailletjbm@infosec.exchange
2025-05-22

Did you know?
CIRCL's vulnerability-lookup is mentioned in the LF/OpenSSF CRA training. (screencap, top left)
vulnerability.circl.lu/
training.linuxfoundation.org/e
@adulau
#circl #vulnerability-lookup #cra

Jean-Baptiste Maillet boosted:
2025-05-21
Jean-Baptiste Maillet boosted:
CVE ProgramCVE_Program
2025-05-20
Jean-Baptiste Mailletjbm@infosec.exchange
2025-05-20

@iFixit France has a reparability index, mandated by law, that shall be displayed for some categories of products (e.g. smartphones):
entreprendre.service-public.fr

More details (in French):
ecologie.gouv.fr/politiques-pu

Jean-Baptiste Mailletjbm@infosec.exchange
2025-05-19

@codegouvfr @ambnum @numerique_gouv C'est beau, c'est grand, c'est noble, c'est français. 🥖

Jean-Baptiste Maillet boosted:

"France Becomes First Government to Endorse UN Open Source Principles, Joined by 19 Organizations"

👉 unite.un.org/fr/news/france-be

The 8 UN #OpenSource principles:

1. Open by default
2. Contribute back
3. Secure by design
4. Foster inclusive participation and community building
5. Design for reusability
6. Provide documentation
7. RISE (recognize, incentivize, support and empower)
8. Sustain and scale

cc @ambnum @numerique_gouv

Jean-Baptiste Mailletjbm@infosec.exchange
2025-05-19

@tinker in Paris in some bus stops, some buses and some subway lines as well.

Jean-Baptiste Maillet boosted:
2025-05-19

The Global CVE (GCVE) allocation system is decentralized approach to vulnerability identification and numbering. The GCVE registry is a key component.

For this reason the registry is digitally signed using an RSA public key with SHA-512.

Thanks to the GCVE Python client, updating your local copy of the registry and verifying its integrity is just one command away:

$ gcve registry --pull

Learn more: gcve.eu

#Vulnerability #CVD #CVE #GCVE #OpenSource #VulnerabilityLookup

A screenshot of a terminal under KDE showcasing the command used in order to pull updates from the GCVE registry.
Jean-Baptiste Maillet boosted:
K. Reid Wightman :verified: 🌻 :donor:reverseics@infosec.exchange
2025-05-19

A password consisting only of lowercase L's, uppercase i's, the number 1 and the | pipe..

I|l11IllIIllIlIlII|

...technically satisfies all password requirements.

Jean-Baptiste Mailletjbm@infosec.exchange
2025-05-16

@metacurity the good ol' days. It must be 10 years or so I did not answered a question (and I never asked one), but my answers still get me some karma points from time to time.

Jean-Baptiste Maillet boosted:
2025-05-16

GCVE-BCP-02 - Practical Guide to Vulnerability Handling and Disclosure has been published.

This is a draft open for review.

🔗 gcve.eu/bcp/gcve-bcp-02/

#vulnerabilitymanagement #gcve #vulnerabilityhandling #vulnerability

Jean-Baptiste Maillet boosted:
-Boulet-bouletcorp2
2025-05-16

Rogatons Rediffusions - 11/04/2023 - "High Tech"
Source: bouletcorp.com/rogatons/2023/0

Titre: HIGH TECH

On voit une sorte de petit monstre qui ressemble à un oursin humanoïde bipède en colère. Il avance l'air mauvais, les mains crispées.
Le monstre: "Je suis le stress du quotidien. Rien de trop méchant. Juste une sorte de bruit de fond électrique, une légère tension permanente"

Boulet est sur son canapé, tablette à la main. Il semble contrarié, et des petites lignes de douleur semblent indiquer qu'il a une migraine. Les mots "Impôts Boulot Actu Covid" flottent au-dessus de sa tête.

Sur sa tablette, il tape la commande "Fichier: sélectionner - Transférer"Un autre monstre arrive d'une autre direction. Il est bipède, informe, et avance voûté avec de très longs bras qui traînent par terre. Son allure générale lui donne un air un peu stupide.

Le monstre: "Je suis une petite contrariété du quotidien. Un petit truc pas grave qui arrive sans raison précise.

Boulet semble surpris par sa tablette qui bugge.
Celle-ci annonce:
Transfert: 12% - Bloqué. Annuler ?
-Non.
Transfert: 12% - Bloqué. Annuler ?

Boulet s'énerve et tape frénétiquement avec son styler sur la tablette qui annonce en boucle:
Transfert: 12% - Bloqué. Annuler ?
Transfert: 12% - Bloqué. Annuler ?

Boulet affiche une expression de rage pure, bouche ouverte et yeux vides.Les deux monstres se rencontrent et se prennent les mains, face à face.
Monstre 1: "L'alchimie est si forte, entre nous !"
Monstre 2: "Oh mon Dieu, que nous arrive-t-il ?"

Leur deux bouches entrouvertes, langue sortie, s'approchent amoureusement tandis qu'ils ferment les yeux, entourés de petits cœurs et de notes de musique.

On les voit ne former plus qu'un contour indistinct, fusionnant dans un grand "ZAP"

Un nuage de fumée s'élève, dans un grondement de plus en plus puissant.Un monstre plein de dents et de griffes se redresse, gigantesque, et hurle: "MA PUISSANCE EST DÉSORMAIS SANS LIMITES ! JE VAIS DÉTRUIRE LE MONDE !"

Boulet pulvérise à coups de poing sa tablette, en hurlant un chapelet d'injures représentées sous la forme de pictogrammes dans lesquels on reconnait un crâne, un champignon nucléaire, Steve Job enpalé, une explosion, et "pomme = caca".
Jean-Baptiste Maillet boosted:
Alexandre Dulaunoya@paperbay.org
2025-05-16

Starting to see (and getting a bit excited about) some components of openwebsearch.eu, and I was wondering if the EU will finally get its own Common Crawl, like dataset (commoncrawl.org).

It seems the crawling results aren't publicly accessible yet, and there's already some discussion about GDPR implications.

At this pace, we're still far from being able to compete with US-scale open data efforts 🤦‍♂️

#europe #commoncrawl #openwebsearch

🔗 pipeline.shared-search.eu/
🔗 pipeline.shared-search.eu/expl

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst