-
Notifications
You must be signed in to change notification settings - Fork 41
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Resources to help protect developers (humans) from attacks similar to the xz backdoor compromise #142
Comments
for a very good timeline on the incident: https://boehs.org/node/everything-i-know-about-the-xz-backdoor |
Just want to post a couple of links with decent references to social engineering: https://www.ibm.com/topics/social-engineering However, it doesn't appear that there's anything open source developer specific resources - training or guides - so we may need to create our own document geared for the OS community based upon all the information that's currently out there. |
I saw this similar example from 2020 in the Software Supply Chain Security newsletter that we may want to reference:
|
I've been reviewing and collecting some government created resources around Insider Threat. The organizations and resources I've looked at so far are below. The main challenge is very few of the behaviors/indicators of potential insider threat are relevant in the OSS community. Same with the mitigations. So, the fun part will be understanding/documenting the "normal" behavior for the OSS community and then extrapolating the indicators where insider threat activity is a possibility. An exciting challenge to say the least. Resources so far: CISA resources NATO CCDCOE |
Thanks @underkay. @SecurityCRob could you take an action for our meetings to see if our non-US members have access to the .gov resources? Thanks! |
We discussed today in our call about the need to find, identify, and evangelize resources that are available to developers and maintainers to help detect social engineering, identify and defend against bully behaviours pressuring maintainers into making choices they otherwise would not have, and to help them cope with stress, self-care, and have a network of persons or resources to be able to reach out to in times of crisis.
We will be collaborating together to help assemble these resources and then make plans to help share them with the community.
The text was updated successfully, but these errors were encountered: