ChrisMayLA6, to random
@ChrisMayLA6@zirk.us avatar

We've had #offshoring... then #reshoring (the return of functions previously offshored) & now we have 'friendshoring' - the location of #supplychain nodes in politically friendly countries (allies).

As firms try to shift supply chains (or at least diversify them) to minimise geopolitical #risk we can expect to see the reinforcement of economic blocs in parallel to alliance-formations.

Whether this will raise costs (as European Central Bank warns) & (re)stoke #inflation remains to be seen

krelnik, to Software

Just downloading some updates and checking #SHA hashes, like you do. Insofar as people actually bother, I wonder how many people just look at the first few digits and the last few digits and call it a day. Which raises a question: has anyone ever explored the idea of hash "partial" collisions in a crypto context? I.e. if the first and last 8 hex digits are the same, but the middle could differ. Might be a useful thing for some attackers trying to deposit nasty things in public repositories. #Malware #HashCollisions #Cryptography #Software #InfoSec #SupplyChain

publicvoit, to Bulgaria German
@publicvoit@graz.social avatar

Während die #EU vermutlich noch jahrzehntelang sich in missglückte Cloud-Versuche verheddert (#GAIAX) und zögerlich mit vernünftigen und raschen Schritten in Richtung eigener #Hardware-Entwicklung dahindümpelt, machen die Chinesen schon längst Nägel mit Köpfen, wenn auch noch nicht auf Niveau der USA:

Chinesisches #CPU-Eigengewächs #Loongson 3A6000 holt auf
https://www.heise.de/news/Chinesisches-CPU-Eigengewaechs-Loongson-3A6000-holt-auf-9352611.html

Wir sind auf Jahrzehnte sowas von abgehängt. 😔

#Supplychain #China #Outsourcing

ChrisMayLA6, to random
@ChrisMayLA6@zirk.us avatar

meanwhile in Central America, the #elnino weather system has caused significant draughts & as a result has limited the capacity of the #panama ship canal... watch out for the associated #supplychain disruption as shipments are slowed or re-directed.

Already shipping rates are rising as vessels are tied up in long queues to get through the canal.... the Q. is, if & when this feed through into consumer prices?

Or has the move to 'reshoring' lessened Europe's exposure to such disruption?

phylum, to python

We continue to see packages published to . Over the last few days we've been tracking a series of packages purporting to help with internationalization.

https://blog.phylum.io/obfuscated-pypi-packages-purporting-to-be-i18n-libraries-actually-stealing-telegram-data/

We're also tracking several other campaigns in other ecosystems. More on this to follow.

6d03, to haskell
@6d03@mathstodon.xyz avatar

Homework problem: do this with GHC https://research.swtch.com/nih

#haskell #quine #supplychain #ken

marcel, to random German
@marcel@waldvogel.family avatar

begrüsst seine Besucher des mit einem kleinen .

marcel,
@marcel@waldvogel.family avatar

@ChristinaLekati mentions that spy agencies are talking about campaigns, with a particular focus on .

Attackers ranging from state-sponsored, Cyber Criminals, Competitors, but also Hacktivists.

Her advice: "Be careful, especially if your organization is involved in , important technology , , , or targeted by ."

fosslife, to climate
@fosslife@fosstodon.org avatar
miketheman, to python
@miketheman@hachyderm.io avatar

This is a great talk by @yossarian at @openssf EU
on some of the lessons learned from implementing Trusted Publishers for @pypi

https://youtu.be/Cc7hl_tyKWE?si=hrUw1GJzBHYhLZ0Q

More on Trusted Publishers here: https://docs.pypi.org/trusted-publishers/

arstechnica, to random
@arstechnica@mastodon.social avatar

Report: Amazon made $1B with secret algorithm for spiking prices Internet-wide

Report reveals details about Amazon's secret algorithm redacted in FTC complaint.

https://arstechnica.com/tech-policy/2023/10/report-amazon-made-1b-with-secret-algorithm-for-spiking-prices-internet-wide/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

voron,
@voron@mstdn.party avatar

@arstechnica #Fbillionaires it’s not the cost of production, no it’s not #workers pay, no it’s not #supplychain no it’s not #taxes it’s damn greed it’s #profitsoverpeople #taxtherich

sethmlarson, to python
@sethmlarson@fosstodon.org avatar

#Python 3.12.0 is finally here! 🥳 Let's verify the release process' supply chain integrity using #SLSA and changes to sub-components using #SBOM! 🔐

#opensource #supplychain #security

https://sethmlarson.dev/security-developer-in-residence-weekly-report-13

vsaw, to sustainability
@vsaw@mastodon.social avatar

Google Pixel 8 gets 7 years of guaranteed software updates (Security Fixes + Feature Drops)

What kept them from working eWaste and obsolescence problem apparently were supply chain issues because someone downstream does not want to support their perfectly working hardware with new software

https://arstechnica.com/gadgets/2023/10/the-google-pixel-8-is-official-with-7-years-of-updates/

#eWaste #supplychain #sustainability

vsaw, (edited ) to sustainability
@vsaw@mastodon.social avatar

Google Pixel 8 gets 7 years of guaranteed software updates (Security Fixes + Feature Drops)

What kept them from working eWaste and obsolescence problem apparently were supply chain issues because someone downstream does not want to support their perfectly working hardware with new software

https://arstechnica.com/gadgets/2023/10/the-google-pixel-8-is-official-with-7-years-of-updates/

#eWaste #supplychain #sustainability

TomRaftery, to random

🌲 How compliant is your supply chain with the new EU Deforestation Regulation?
In this #DigitalSupplyChain episode LiveEO Co-CEO Sven Przywarra sheds light on its implications for business continuity, and more!

Link to the full episode => https://www.digitalsupplychainpodcast.com/354320/13678621-satellite-data-the-future-of-supply-chain-compliance-a-dive-with-liveeo🎙️

#SupplyChain #Compliance #EUDR

video/mp4

itnewsbot, to Montreal

Quebec Lures $5 Billion Battery Factory for Electric Cars - The Canadian government matched financial incentives available in the U.S. to attract the... - https://www.nytimes.com/2023/09/28/business/northvolt-battery-factory-quebec.html #inflationreductionactof2022 #electricandhybridvehicles #factoriesandmanufacturing #quebecprovince(canada) #politicsandgovernment #montreal(quebec) #federalaid(us) #automobiles #supplychain #batteries #northvolt #sweden

BishopFox, to Cybersecurity

Be proactive about your #softwaresupplychain security. A well-planned #cybersecurity strategy can prevent costly breaches before they happen. Check out our write-up for more info. https://bfx.social/3r6wqzl

#offensivesecurity #supplychain

inquiline, to random
@inquiline@union.place avatar

Oh you think you've seen the worst global capitalism has to offer? Not unless you've watched this, you haven't:

https://www.youtube.com/watch?v=M0lJc3PMNIg

#SupplyChain #BeltAndRoad #Capitalism

inquiline,
@inquiline@union.place avatar
ChrisMayLA6, to random
@ChrisMayLA6@zirk.us avatar

If & this is a big if, the causes of #inflation in the Uk are now in part the pressure brought by #workers finally getting nearer to catching up with the drop in their real #wages caused by inflation, the BoE may find they are the boys (and girls) who cried wolf.

When inflation was being imported through the #energycrisis, #supplychain issues & the continuing cost impact of #Brexit, they blamed #wages (wrongly), but now wages may be partly contributing to #inflation, no-one will believe them!

ChrisMayLA6, to China
@ChrisMayLA6@zirk.us avatar

Meanwhile in the global ;

At the far end (for many goods) in , there is currently ongoing in factory gate prices;

But, at least presently, it would seem that at various stages in supply chains (as well as regulatory costs inc. ), are swallowing up any extra margin(s) that might be caused by such deflation.

So, it real wages are lagging , taxes are stable & its not the Chinese suppliers, whose pushing up prices?

hmmmm...[scratches head]

sethmlarson, to python
@sethmlarson@fosstodon.org avatar
ChrisMayLA6, to Germany
@ChrisMayLA6@zirk.us avatar

Meanwhile in :

Long the exemplar of continued European industrial success, the impact of increased costs alongside disruptions of the & availability prompted by have led to increasing gloom & pessimism across Germany's sector.

As one Mittlestand owner put it (to the FT): 'I don’t want to talk ill of Germany, but it feels like everything is a bit tired here'!

Perhaps the economic pendulum is once again swinging against the country?

sethmlarson, to python
@sethmlarson@fosstodon.org avatar

New update for Security Developer-in-Residence. Lots of news on "Truststore" 🥳 Overall, bit of a shorter weekly update for last week from all the background work and holidays.

#Python #Security #Opensource #Supplychain

https://sethmlarson.dev/security-developer-in-residence-weekly-report-10

ChrisMayLA6, to chinese
@ChrisMayLA6@zirk.us avatar

Can #European car #manufacturers with #Chinese #electricvehicles?

Not only does #China dominate the electric motors' #supplychain it also dominates world production of #electriccars...

Certainly #Tesla has made massive inroads into the high-end market (& has plans for the lower-cost range) as have other brands, but overall China's lead currently looks to continue for some time.

If you wanted a demonstration of how long-term industrial strategy & policy focus work, this would be it!

luis_in_brief, to random
@luis_in_brief@social.coop avatar

Reading this new #NIST #SupplyChain doc and it has a vicious circle/egg problem. Lots of tooling will need to be built that consumes open source upstream that... won't do these things until tooling is built. There's one way to crack that cycle, of course—money. Almost certainly will be an example of (un?)funded mandates in Tidelift's ONCD RFI response.

https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-204D.ipd.pdf

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • ngwrru68w68
  • khanakhh
  • thenastyranch
  • magazineikmin
  • InstantRegret
  • rosin
  • cubers
  • cisconetworking
  • Youngstown
  • slotface
  • osvaldo12
  • kavyap
  • DreamBathrooms
  • anitta
  • everett
  • tacticalgear
  • ethstaker
  • Durango
  • normalnudes
  • mdbf
  • provamag3
  • tester
  • GTA5RPClips
  • modclub
  • Leos
  • megavids
  • lostlight
  • All magazines