Miki
mikisec.bsky.social
Miki
@mikisec.bsky.social
Cyber security officer by day, a fabulous cookie by night
[6/6] I'm curious about what others think. I think it would be a great OSS project (and potentially it could join OSSF)

ofc it will never be as good as Socket or Snyk, but it should still be a decent line of defense. A lot will integrate with existing tools, e.g., Guarddog
December 29, 2025 at 8:43 PM
[5/6] I have a very solid (and exciting) vision for it and clear & measurable goals written down, and a roadmap. Most things are ready, if all goes well a MVP could likely be done within weeks

Biggest concern: it flops or goals aren't being achieved
I'm most excited about: modularity (→ plugins)
December 29, 2025 at 8:43 PM
[4/6] Security shouldn't be a blocker for growth, it should be affordable without scarifying quality and visibility, especially when supply chain attacks keep going up: we need powerful tools to be accessible to everyone
December 29, 2025 at 8:43 PM
[3/6] Free versions of these products are too basic and create a huge gap in observability, auditing, and capabilities

On top, they are fairly vendor-locked as they are companies trying to sell security products (⇒ for obvious reasons they don't integrate w/ tools from their competition)
December 29, 2025 at 8:43 PM
[2/6] Target audience: small businesses (non-Enterprise) who need visibility (SIEM) & need to protect their developers

There are paid tools on the market for this: Socket, Sonar, Vera Code (and they look amazing!) while their price is right, they cost an arm for small businesses.
December 29, 2025 at 8:43 PM
39C3 - Bluetooth Headphone Jacking: A Key to Your Phone
YouTube video by media.ccc.de
www.youtube.com
December 28, 2025 at 10:57 PM
Reposted by Miki
We disclosed two new RSC vulnerabilities:
- Denial of Service (High): CVE-2025-55184
- Source Code Exposure (Medium): CVE-2025-55183

Patches are available now, please update immediately.

react.dev/blog/2025/12...
Denial of Service and Source Code Exposure in React Server Components – React
The library for web and native user interfaces
react.dev
December 11, 2025 at 8:51 PM
That post was an unexpected (pleasant) rabbithole:
- mcp-scan uses invariant
- Invariant is a tool to write rules (tiny bit similar to Semgrep) to scan MCPs
- Can create rules that detect PIIs
- PIIs are found using the PyPI project presidio

Full of TILs, and tons of neat to play with! Thanks!
December 11, 2025 at 7:58 PM
The main danger though is being unable to fix CVEs without fixing breaking changes first (rushing breaking change fixes because of a CVE are one of the worst thing to do), but urllib3 has a good track record: v1 didn't reach EOL for a very long time thus users have ample time to migrate
December 8, 2025 at 9:58 PM
I think the answer lies in the last paragraph of your article: force the change, otherwise a large portion of users will never do the change
December 8, 2025 at 9:57 PM
Unfortunately with teams with very limited time it can be difficult to address all warnings, they often get dealt with once it breaks (i.e., the breaking change actually occurs).

I learned that opening tickets simply doesn't work, work will never be picked up
December 8, 2025 at 9:54 PM
Looks great!

If it's intended for full-screen viewing: text could be a tiny bit smaller so we can see more code at once (feels a tiny bit too big & I'm able to read the text easily despite my poor eyesight 😉)

If it's meant to be projected or viewed in non-fullscreen mode then don't touch it IMO 👌
December 1, 2025 at 7:32 PM
That's quite interesting, we can find the list of flatpaks having such permission here: github.com/search?q=org...
May 30, 2025 at 8:47 PM
Thank you for sharing! That was an amazing talk. This is really saddening, I hope we manage to slam on the brakes
January 18, 2025 at 10:10 PM
Clever way of making it interesting! Instead of "Ugh, another cookie popup!" :D

Props on them!
January 14, 2025 at 10:17 PM
Darn, you were so healthy in yesterday's FireSide chat! Hope you get well soon!
December 14, 2024 at 6:30 PM
Should we call 911? Are you still alive?
December 12, 2024 at 6:39 PM
Rough start but I'm sure it will get much better, good luck!
December 12, 2024 at 4:32 PM