back to article OpenSSF sings a Siren song to steer developers away from buggy FOSS

Securing open source software may soon become a little bit easier thanks to a new vulnerability info-sharing effort initiated by the Open Source Security Foundation (OpenSSF). Dubbed OpenSSF Siren, the threat intelligence sharing group aims to “aggregate and disseminate threat intelligence” to provide real-time security …

  1. Apprentice of Tokenism
    Facepalm

    What’s the point?

    > instead intending it to serve as a "post-disclosure means of keeping the community informed of threats and activities after the initial sharing and coordination."

    So another vulnerability blog funded by companies.

    Perhaps those companies should instead just fund a group of developers whose sole task is to immediately provide fixes for new vulnerabilities? You know, provide them to the quoted lone open-source-dev projects?

    1. Michael Wojcik Silver badge

      Re: What’s the point?

      Yeah. "There are too many sources of vulnerability information, so here's another!"

      I'm really not seeing how this helps.

  2. Bebu
    Windows

    Sirens?

    If I recall correctly the sirens' song lured unsuspecting mariners onto fatal rocks to perish.

    Odysseus had his crew lash him to the mast while they filled their own ears with beeswax so the crew rowed their vessel safely passed the sirens.

    Odd choice of name I would have thought. Klaxon or "Cloister Bell*" might have been a better choice.

    More like a shipping weather forecast so perhaps "Rockall." ;)

    * for the Whooligans :)

    1. CRConrad

      “Siren” is also a synonym for...

      Well, “klaxon”, more or less. See Wikipedia | Siren (alarm) and Wiktionary | siren (noun, sense 7). I'm pretty sure it was this sense of the word they meant.

      “Siren” also has the advantage of being exactly the same word in many languages, whereas “klaxon” is pretty much limited to English – and Italian and Catalan, judging from Wikipedia's “Other Languages” links. Which refer to car horns, not general alarm devices... Because that's what “klaxon” redirects to even on English WP. Seems it's your usage that is parochial, not the SSH developers’.

    2. CRConrad

      Further re: Sirens?

      From Mother Beeb herself: Even in peaceful countries be ready for a siren blast (emphasis added).

  3. Anonymous Coward
    Anonymous Coward

    Odysseus’ Near Undoing

    Men, wait… give me back my tablet and untie me! A prince in Troy just emailed me, he’s come across a large sum of money… I need to see what’s attached!

    1. phorkar

      Re: Odysseus’ Near Undoing

      Created an account just to upvote this comment. Silent lurking anonymity dashed on the rocks of the sirens.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like