Alpha-Omega转发了
Congrats to FreeBSD on a very successful audit. When Alpha-Omega funds an audit we always hope that it will do more than just find vulnerabilities. When it works, an audit catalyzes a new awareness of security priorities in the organization. With the FreeBSD Foundation there was already a long tradition of security but as this audit showed, there's always work to be done. These paragraphs really made me happy: "Beyond discovering and fixing the vulnerabilities themselves, this code audit has also identified patterns and general classes for the vulnerabilities discovered. This helps the project engage with the committers to reduce the future incidence of similar vulnerabilities. "The FreeBSD Foundation recommends using the code audit findings to deliver developer education and training that create a security-conscious development mindset and to steward an Advisory Committee for security to materially support the FreeBSD Project in resourcing security-focused work." This is exactly the kind of lasting impact even a modest audit can have on an organization that primed and ready. The full audit is here: https://lnkd.in/ds9TJxHU It's well worth the read.
?? Yesterday, the FreeBSD Foundation released a report about an audit we conducted on two critical #FreeBSD components. During 6 weeks, our experts Jean-Baptiste Cayrou and Thomas IMBERT dived into the #FreeBSD source code, and managed to find 27 vulnerabilities and issues. ?? BHyve was the first audited component: this is the #FreeBSD hypervisor, in which 22 vulnerabilities have been found. ?? Capsicum was then analyzed: this is #FreeBSD security framework to perform applications sandboxing. This time, 5 vulnerabilities have been uncovered. All the security vulnerabilities and issues have now been patched, and the overall security of the #FreeBSD project as been reinforced ?? https://lnkd.in/gX4F_cUA