æva black(@aevavoom) 's Twitter Profileg
æva black

@aevavoom

Hacker, opensource geek, public speaker, advocate. Currently works at CISA. All opinions = 💯 mine. 🏍️/🏳️‍🌈/⚧️

ID:18809935

linkhttps://aeva.online/ calendar_today09-01-2009 18:35:08

17,2K Tweets

4,7K Followers

986 Following

Cyber Statecraft(@CyberStatecraft) 's Twitter Profile Photo

The XZ backdoor discovered last month has reignited discussions about the security of OSS.

In this 5x5, we brought together Tobie Langel, [email protected], æva black, Stewart Scott, and CRob to discuss its implication for the OSS community. ⬇️

dfrlab.org/2024/05/01/the…

account_circle
Erin Reed(@ErinInTheMorn) 's Twitter Profile Photo

1. In a landmark ruling, the United States 4th Circuit Court of Appeals rules 'gender identity is a protected characteristic,' and that state coverage bans on trans care are unconstitutional.

This will have far-reaching impacts.

Subscribe to support my journalism. Let's dig in.

1. In a landmark ruling, the United States 4th Circuit Court of Appeals rules 'gender identity is a protected characteristic,' and that state coverage bans on trans care are unconstitutional. This will have far-reaching impacts. Subscribe to support my journalism. Let's dig in.
account_circle
Ildiko Vancsa(@IldikoVancsa) 's Twitter Profile Photo

A new, episode of the My Open Source Experience Podcast is now live!

PhilRobb and I are chatting with æva black about in , challenges, good practices and more!

Catch the episode on YouTube (youtube.com/@MyOpenSourceE…) or through RSS (feeds.acast.com/public/shows/6…)

A new, episode of the My Open Source Experience Podcast is now live! @PhilRobb and I are chatting with @aevavoom about #security in #opensource, challenges, good practices and more! Catch the episode on YouTube (youtube.com/@MyOpenSourceE…) or through RSS (feeds.acast.com/public/shows/6…)
account_circle
Ian Coldwater 📦💥(@IanColdwater) 's Twitter Profile Photo

every time you meet or exceed the bars they set they magically become no longer legitimate. it’s almost like the whole thing was an entirely arbitrary gatekeeping exercise and the only way to win is not to play

account_circle
steve o'grady(@sogrady) 's Twitter Profile Photo

Rob Underwood the biggest issue, honestly, is that people have taken for granted the gains that open source has made - and its future - and don't realize that both are under threat.

but there are signs - tiny ones, so far - that maybe that's changing. or could.

account_circle
The Associated Press(@AP) 's Twitter Profile Photo

BREAKING: The Swedish parliament passed a law lowering the age required for people to legally change their gender from 18 to 16. apnews.com/article/sweden…

account_circle
Jen Easterly🛡️(@CISAJen) 's Twitter Profile Photo

The XZ Utils compromise highlights the urgent need for software manufacturers to sustain the open source ecosystems they depend on. Read my teammates Jack Cable & æva black's blog on how Cybersecurity and Infrastructure Security Agency is approaching open source with a mindset: go.dhs.gov/JHf

The XZ Utils compromise highlights the urgent need for software manufacturers to sustain the open source ecosystems they depend on. Read my teammates @jackhcable & @aevavoom's blog on how @CISAgov is approaching open source with a #SecureByDesign mindset: go.dhs.gov/JHf
account_circle
Eric Geller(@ericgeller) 's Twitter Profile Photo

CISA's æva black and Jack Cable say the XZ Utils supply-chain incident highlights need for more investment: 'Companies consuming open source software must contribute back — either financially or through developer time — to ensure a sustainable ecosystem.' cisa.gov/news-events/ne…

account_circle
Cybersecurity and Infrastructure Security Agency(@CISAgov) 's Twitter Profile Photo

CISA advisors Jack Cable and æva black describe in our latest blog how we are responding to the XZ Utils compromise and how every tech manufacturer should take a approach to securing open source software: go.dhs.gov/JHf

CISA advisors @jackhcable and @aevavoom describe in our latest blog how we are responding to the XZ Utils compromise and how every tech manufacturer should take a #SecureByDesign approach to securing open source software: go.dhs.gov/JHf
account_circle
Mark Atwood(@_Mark_Atwood) 's Twitter Profile Photo

The xz attack was not because it was open source. The attack failed because it was open source. The way this attack works for non-open source is the attacker spends 2 years getting an agent hired by contract software development vendor, they sneak it in, nobody finds out.

account_circle
ashley williams(@ag_dubs) 's Twitter Profile Photo

i can't believe i have to say this but the takes where people are saying 'money won't solve OSS sustainability' ... they are saying something extremely narrow - so much so that it is barely worth saying

account_circle
ehashman@cloudisland.nz 🇵🇸(@ehashdn) 's Twitter Profile Photo

If you're looking for my takes on the xz exploit and addressing maintainer burnout/sustainable FOSS development, I gotchu over on masto: cloudisland.nz/@ehashman/1121…

account_circle
Glitch 💻😺(@glitchfur) 's Twitter Profile Photo

Linux doesn't need antivirus. In fact the malware just comes bundled in your core packages sometimes, as a treat.

account_circle
Erin Reed(@ErinInTheMorn) 's Twitter Profile Photo

On Transgender Day of Visibility, I think about how often visibility is granted to transgender people but not a voice.

How many newspapers, TV networks, legislative chambers, and more grant trans people 'visibility' but no agency.

How our stories are so rarely told by us.

account_circle
æva black(@aevavoom) 's Twitter Profile Photo

Public details of the xz hack mirror what so many maintainers have been worried about because most tech stacks are deeply dependent on volunteerism — so, burn out is a security concern.

Responsible Consumers
must be
Sustainable Contributors

account_circle