Skip to main content

Questions tagged [security]

For questions about security practices as applied to open source software.

4 votes
1 answer
335 views

Companies selling products containing embedded software, tend to ban the presence of any software licensed under GPLv3, LGPLv3 or AGPLv3, to avoid the anti-tivoization clause. The reason for this is ...
ruben2020's user avatar
  • 5,046
18 votes
2 answers
5k views

This might be a basic question, but I’ve been wondering: what happens if the GitHub account of a well-known open-source project is compromised? Could malicious code be added, or an unauthorized update ...
Vijay sai Nallani's user avatar
1 vote
1 answer
191 views

Recently, I engaged in a discussion on what would be the most befitting model for a piece of software sitting on top of an electronic voting system i.e. being in charge of collecting and summarzing ...
Pasato's user avatar
  • 119
4 votes
1 answer
1k views

Disclaimer: The plugin's dev has put a lot of work into it, so I don't wanna talk bad about the plugin!! I'm only working in IT since 2 years and from his Github profile he seems way more experienced, ...
Boommeister's user avatar
6 votes
6 answers
1k views

To what extent can we verify the identity of a particular mobile device, over NFC, in an entirely transparent manner? Consider the following situation: A large organization currently handles access ...
Wayfaring Stranger's user avatar
39 votes
7 answers
5k views

Take as an example the Italian app "Immuni" (https://github.com/immuni-app), used by the government to trace contacts exposure against COVID-19. Since many people were afraid about how the ...
ABCplus's user avatar
  • 501
-1 votes
2 answers
229 views

Password vaults, which utilize public and (likely passwordized) private keys to host and protect principally-non-human-memorized-passwords, are a kind of SaaS that remotely stores and supplies ...
oleosecuritet's user avatar
8 votes
3 answers
2k views

I have a question about Open Source programs. How can I sure an open source program is safe and isn't spying on me? For example, I installed Firefox on Linux and how can I sure this program is safe! ...
Nongeek's user avatar
  • 81
4 votes
1 answer
364 views

We use an older verion of dojo in our product and our upgrade to newer version needs lot of overhauling of the product code - which is not possible at this wee hour. But we need to get rid of this ...
Bipin Chandra's user avatar
46 votes
2 answers
11k views

When a developer creates a binary from the code and puts it in the releases section, does it match the code in a restrictive way so there is no chance that malicious code is compiled into it? How does ...
laimison's user avatar
  • 563
6 votes
2 answers
2k views

Many corona apps are developed in the moment, and some of them e.g. In Germany are open source. Many people fear to be spied by this app. Im definitely Not one of them. Still it raised the question ...
Ludi's user avatar
  • 161
2 votes
0 answers
63 views

The ZHST_IMS_Package 1.0.0 was installed through Application insights nugget packages. As part of black duck scan found this has issue with license and reported as "License Not Found". I found this ...
Rajesh's user avatar
  • 29
1 vote
1 answer
126 views

I have an API that I created myself here: https://db.ygoprodeck.com/api-guide/ I get roughly 20,000 requests per day on it but have asked by a couple of people to open source it. I look into this ...
GenesisBits's user avatar
1 vote
0 answers
154 views

I'm thinking about developing an open-source web application where users can enter trips that they have done (touristic or commuting) and then view statistics and maps created from this data. From the ...
Daniel's user avatar
  • 133
6 votes
2 answers
182 views

I created Zipios version 2.x in 2015 based on an existing library and inherited the old version (0.1.5) as a result... In June 2019, I got an email from Mike Salvatore who reported having a problem ...
Alexis Wilke's user avatar

15 30 50 per page