Sign in

Matt "msw" Wilson

@msw.bsky.social
791 followers 300 following 210 posts

“For a successful technology, reality must take precedence over public relations, for Nature cannot be fooled.”

PostsRepliesMedia
Matt "msw" Wilson @msw.bsky.social · 26/07/2026
It really /was/ the better technology...
010
Matt "msw" Wilson @msw.bsky.social · 30/06/2026
Apologies, I missed those two words on my small screen.
010
Matt "msw" Wilson @msw.bsky.social · 29/06/2026
That is not correct. The Nitro Hypervisor supports VBS. docs.aws.amazon.com/AWSEC2/lates...
docs.aws.amazon.com
Credential Guard for Windows instances - Amazon Elastic Compute Cloud
Understand the concepts, requirements, and usage of Credential Guard.
100
Matt "msw" Wilson @msw.bsky.social · 25/06/2026
I think this is a reasonable approach to most things in life, especially when you have a large industry consortium motion involved.
010
Matt "msw" Wilson @msw.bsky.social · 25/06/2026
Maintainers deserve a coordinated partnership, not a flood of reports. AWS is committed to securing the projects our customers depend on and building this shared infrastructure alongside the community.
010
Matt "msw" Wilson @msw.bsky.social · 25/06/2026
Frontier AI models have given defenders the ability to find and fix vulnerabilities in open source software at a speed and scale that were never possible before. That's an enormous opportunity for defenders, and Akrites ensures we seize it together.
110
Matt "msw" Wilson @msw.bsky.social · 25/06/2026
We have just launched Akrites at The Linux Foundation, a coordinated industry effort to harden the world’s most critical open source software in the era of AI-assisted vulnerability discovery. www.linuxfoundation.org/press/linux-...
linuxfoundation.org
Linux Foundation and Industry Leaders Launch Akrites to Defend Critical Open Source Software Against AI-Enabled Cyber Threats
Linux Foundation and Industry Leaders Launch Akrites to Defend Critical Open Source Software Against AI-Enabled Cyber Threats
182
Matt "msw" Wilson @msw.bsky.social · 22/06/2026
Severity is not risk
010
Matt "msw" Wilson @msw.bsky.social · 21/06/2026
github.com/spanio/SPAN-...
github.com
GitHub - spanio/SPAN-API-Client-Docs: SPAN API Client Documentation
SPAN API Client Documentation. Contribute to spanio/SPAN-API-Client-Docs development by creating an account on GitHub.
010
Matt "msw" Wilson @msw.bsky.social · 21/06/2026
mstdn.social/@msw/1167825...
mstdn.social
Matt "msw" Wilson (@msw@mstdn.social)
Sometimes the response to a software defect that is discovered, fixed, and disclosed as a "security vulnerability" has a far worse effect than the defect itself. There was never any indication that t...
010
Matt "msw" Wilson @msw.bsky.social · 20/06/2026
There is an API for first generation SPAN, and a HA integration. 2nd generation API is in the works. But it is a very installer-centric product, and not as open / DIY homeowner friendly as it could be.
210
Matt "msw" Wilson @msw.bsky.social · 17/06/2026
when it comes to addressing newly discovered flaws in your software dependencies (some of which might be classified as "security vulnerabilities") ... pruning > patching That's it. That's the post.
010
Matt "msw" Wilson @msw.bsky.social · 09/06/2026
I guess membership such a hypothetical club means promising to not share, despite the GPL giving you all the fundamental permissions needed to do so.
040
Matt "msw" Wilson @msw.bsky.social · 09/06/2026
Personally, I miss the days of Free and Open Source when folks debated if NDAs were compatible (at minimum, in spirit) with the conditions of the GPL. Now, I see the slight possibility of a world where folks rush to share fixes for vulnerabilities in a private club. And if that software is GPL?
150
Matt "msw" Wilson @msw.bsky.social · 21/05/2026
For those who may have forgotten... www.schneier.com/blog/archive...
schneier.com
Random Number Bug in Debian Linux - Schneier on Security
This is a big deal: On May 13th, 2008 the Debian project announced that Luciano Bello found an interesting vulnerability in the OpenSSL package they were distributing. The bug in question was caused b...
020
Matt "msw" Wilson @msw.bsky.social · 21/05/2026
For folks who are thinking about locally patching open-source software to fix what they think is a bug (_especially_ if they think it's a security vulnerability), I think that's a path to www.xkcd.com/424/
xkcd.com
Security Holes
120
Reposted by Matt "msw" Wilson
Cassidy @cassidoo.co · 20/05/2026
Heads up maintainers of packages, this is a big deal: github.com/orgs/communi...
github.com
npm granular access token invalidation to prevent supply chain attacks · community · Discussion #196340
As initially announced on npm’s X channel, we have invalidated granular access tokens with write access that bypass two-factor authentication. This action was taken to help prevent supply chain att...
37424
Matt "msw" Wilson @msw.bsky.social · 19/05/2026
So often I've seen a "it's too hard to triage CVEs, so we should always assume the worst and apply the 'fix' as quickly as possible." Being able to demote a "critical security vulnerability" to "this should be addressed via regularly scheduled maintenance" is a very useful capability.
030
Matt "msw" Wilson @msw.bsky.social · 19/05/2026
Y'all, AI models seem to be *really good* at triaging vulnerabilities that are discovered with AI tooling! Try this prompt: > read gitlab.gnome.org/GNOME/libxml... and tell me if CVE-2026-6732 applies to github.com/libarchive/l... [...] Conclusion Not affected.
  The Vulnerability
                                                                                                    
  The libxml2 issue (GitLab work item #1097) is a type confusion in xmlParseReference() that occurs exclusively when streaming XSD schema validation is active. The bug passes ctxt (parser context) instead of ctxt->userData to SAX characters() / cdataBlock() callbacks. This only causes a crash when xmlSchemaSAXPlug has redirected those callbacks — meaning schema validation must be enabled on the reader/parser. 

How libarchive uses libxml2

  libarchive uses libxml2 solely for parsing XAR archive table-of-contents XML in archive_read_support_format_xar.c. It uses the xmlTextReader pull-parsing API:                           
  - xmlTextReaderRead()
  - xmlTextReaderNodeType()
  - xmlTextReaderConstLocalName()
  - xmlTextReaderConstValue()
  - xmlTextReaderMoveToFirstAttribute() / MoveToNextAttribute()

  It does not call any schema validation functions:
  - No xmlTextReaderSchemaValidate()
  - No xmlSchemaSAXPlug()                                   
  - No xmlSchemaValidateStream()
  - No xmlSchemaNewValidCtxt()
                                                               
  Conclusion
                                                                                                                         
  Not affected. The vulnerable code path requires XSD streaming validation to be plugged into the SAX layer. libarchive  
  never enables schema validation — it just reads XML nodes from XAR TOC data. Without the schema validation SAX plug    
  active, the type confusion in xmlParseReference() cannot be triggered, even if the XML being parsed contains entity    
  references.
110
Matt "msw" Wilson @msw.bsky.social · 19/05/2026
Congrats to you and the team on the launch!
130
Matt "msw" Wilson @msw.bsky.social · 29/04/2026
Super curious what folks think about this 🧵. Especially @adamhjk.me
100
Matt "msw" Wilson @msw.bsky.social · 22/04/2026
And the KIWI operating system image builder now has an example of how to build an attestable AWS Nitro Enclave image! Very cool! github.com/OSInside/kiw...
github.com
Add confidential compute image for AWS by schaefi · Pull Request #2962 · OSInside/kiwi
Add a Trusted Execution Environment in form of an image as a read-only system that is also dm-verity baked. The image build provides PCR measuerd UKI image (kernel+initrd+bootloader). The PCR value...
010
Matt "msw" Wilson @msw.bsky.social · 22/04/2026
Yesterday the QEMU team released 11.0.0, which features a new special purpose accelerator and machine model for AWS Nitro Enclaves. Check it out! www.qemu.org/docs/master/...
qemu.org
AWS Nitro Enclaves — QEMU documentation
140
Matt "msw" Wilson @msw.bsky.social · 25/03/2026
Fun fact: when you have more than 1,000 notices on GitHub, it says you have 1. It should be like tabs in Chrome on mobile devices, where past 100 it shows ":)"
Screenshot showing Inbox, Saved, and Done labels from Github. There's a 1 in a circle
150
Matt "msw" Wilson @msw.bsky.social · 19/03/2026
"Dealing with the rate of change in software development" Asked 17 years, 6 months ago. If only I had a time machine to suggest to folks that they try to enjoy the "good 'ole days". stackoverflow.com/questions/10...
stackoverflow.com
Dealing with the rate of change in software development
I am primarily a .NET developer, and in that sphere alone there are at any given time probably close to a dozen fascinating emerging technologies, some of them real game-changers, that I would love...
032
Reposted by Matt "msw" Wilson
OpenSSF @openssf.org · 17/03/2026
The Linux Foundation Announces $12.5 Million in Grant Funding (via Alpha-Omega and OpenSSF) Anthropic, AmazonWebServices (AWS), GitHub, Google, GoogleDeepMind, Microsoft, OpenAI to Invest in Sustainable Security Solutions for #OpenSource openssf.org/press-releas...
Linux Foundation Announces 12.5 Million in Grant Funding to Advance Open Source Security
073
Matt "msw" Wilson @msw.bsky.social · 09/03/2026
Some folks in and around Free and Open Source Software (FOSS) are asking, "does AI change everything?" If you think that FOSS only exists because software is expensive to write, reuse is efficiency, and AI shifts the economics ("we rewrote Next.js in a week with AI!"), you may be worried. I'm not.
270
Reposted by Matt "msw" Wilson
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 22/12/2025
I added a sentence to the #curl hackerone submission page: "Please present your case briefly and to the point. Do not use an AI to help you blab hundreds of line that will exhaust us to death instead of making us understand your claim."
0102
Matt "msw" Wilson @msw.bsky.social · 05/12/2025
China-nexus cyber threat groups rapidly exploit React2Shell vulnerability (CVE-2025-55182) aws.amazon.com/blogs/securi...
aws.amazon.com
China-nexus cyber threat groups rapidly exploit React2Shell vulnerability (CVE-2025-55182) | Amazon Web Services
Within hours of the public disclosure of CVE-2025-55182 (React2Shell) on December 3, 2025, Amazon threat intelligence teams observed active exploitation attempts by multiple China state-nexus threat g...
000
Matt "msw" Wilson @msw.bsky.social · 04/12/2025
Throwback Thursday... socket.dev/blog/node-js...
socket.dev
Node.js EOL Versions CVE Dubbed the "Worst CVE of the Year" ...
Critics call the Node.js EOL CVE a misuse of the system, sparking debate over CVE standards and the growing noise in vulnerability databases.
010
Matt "msw" Wilson @msw.bsky.social · 04/12/2025
These were the rules when the original plan was made to issue CVEs merely because Node.js versions were EOL. This outcome was easy to predict... nodejs.org/en/blog/vuln...
nodejs.org
Node.js — Updates on CVE for End-of-Life Versions
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
100
Matt "msw" Wilson @msw.bsky.social · 04/12/2025
Why? Because 4.1.13 The state of a Product being EOL, by itself, MUST NOT be determined to be a Vulnerability. www.cve.org/resourcessup....
cve.org
100
Matt "msw" Wilson @msw.bsky.social · 04/12/2025
Vendored deps are not unusual at all... But, unfortunately, misuse of the CVE program is all too common in the NodeJS community. Let's take CVE-2025-23087, CVE-2025-23088, and CVE-2025-23089 for example. All of these CVEs are REJECTED. nodejs.org/en/blog/vuln...
nodejs.org
Node.js — Tuesday, January 21, 2025 Security Releases
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
100
Matt "msw" Wilson @msw.bsky.social · 04/12/2025
> The decision to publish a second CVE for Next.js was made due to these exceptional circumstsances: Next.js does not include React as a traditional dependency - instead, they bundle it "vendored" react2shell.com
react2shell.com
React2Shell (CVE-2025-55182)
100
Matt "msw" Wilson @msw.bsky.social · 04/12/2025
There are definitely PoCs circulating…
000
Matt "msw" Wilson @msw.bsky.social · 04/12/2025
Unpopular opinion: a vulnerability that was disclosed privately by researchers and had a coordinated response from vendors and service operators under an (albeit short) embargo is not a “0-day”.
070
Matt "msw" Wilson @msw.bsky.social · 03/12/2025
4.1.12 The act of updating Product dependencies MUST NOT be determined to be a Vulnerability, regardless of whether the dependencies have Vulnerabilities. www.cve.org/resourcessup...
cve.org
100
Matt "msw" Wilson @msw.bsky.social · 03/12/2025
A public service announcement regarding CVEs: one identified vulnerability gets one CVE. Each vendor doesn't get their own CVE that corresponds to their security bulletin. CVE-2025-66478 is REJECTED as duplicate of CVE-2025-55182 www.cve.org/CVERecord?id...
cve.org
230
Reposted by Matt "msw" Wilson
Kate Holterhoff, PhD @kateholterhoff.com · 03/12/2025
To celebrate #awsreinvent, @redmonk.com has been publishing New Builders conversations w @awscloud.bsky.social leaders every day this week & TODAY IS MY DAY 🎉🎉🎉!! Hear AWS's Ali Maaz & Jessie VanderVeen chat all things #AI & #DevTools w me redmonk.com/videos/insid... www.youtube.com/shorts/Ot0gy...
youtube.com
Not overselling #aideveloper and #devtools as magical at #aws with Ali Maaz & Jessie VanderVeen
YouTube video by RedMonk
0101
Matt "msw" Wilson @msw.bsky.social · 12/11/2025
Unpopular opinion: through an economics lens, the optimal number of CVEs in most software systems is almost never 0.
150
Matt "msw" Wilson @msw.bsky.social · 12/11/2025
Culture eats AI adoption strategy for breakfast, lunch, and dinner.
030
Matt "msw" Wilson @msw.bsky.social · 06/11/2025
"Our only modification part is that, if the Software (or any derivative works thereof) is used for any of your commercial products or services that have more than 100 million monthly active users, or more than $20M in monthly revenue, you shall prominently display 'Kimi K2' on the user interface"
121
Matt "msw" Wilson @msw.bsky.social · 06/11/2025
I mean, honesty is a human trait. The humans who built that particular AI system biased the set of mysterious numbers (through reinforcement, filtering, etc.) so it assembles tokens in a way that conveys information about the properties and limitations of the system they built. That's all.
010
Matt "msw" Wilson @msw.bsky.social · 31/10/2025
#FerryLife #WAWX #Seattle #Sunrise
The sun rises at the horizon, reflecting of the water of Eagle Harbor. The car deck of the Washington State ferry Tacoma is in the foreground.
0122
Matt "msw" Wilson @msw.bsky.social · 04/10/2025
"As adoption has grown, so has our responsibility to ensure the project remains sustainable and continues to thrive. That’s why, with the release of Liquibase 5.0, we are updating the license for Liquibase Community." www.liquibase.com/blog/liquiba...
liquibase.com
Strengthening Liquibase Community for the Future
Liquibase Community now uses the Functional Source License (FSL). Learn what this means for developers, contributors, and enterprises, and how it protects sustainability.
210
Matt "msw" Wilson @msw.bsky.social · 02/10/2025
Metrics are increasingly employed as trust deteriorates. Recommended reading ⬇️ #monktoberfest a.co/d/im8AStV
a.co
The Tyranny of Metrics: Muller, Jerry Z.: 9780691191911: Amazon.com: Books
Buy The Tyranny of Metrics on Amazon.com ✓ FREE SHIPPING on qualified orders
063
Matt "msw" Wilson @msw.bsky.social · 02/10/2025
Ref: Edgar H. Schein sloanreview.mit.edu/article/comi... #monktoberfest
sloanreview.mit.edu
Coming to a New Awareness of Organizational Culture
000
Matt "msw" Wilson @msw.bsky.social · 02/10/2025
“Organizational culture is the pattern of basic assumptions that a given group has invented, discovered, or developed in learning to cope with its problems […], and that has worked well enough to be considered valid, and, therefore, to be taught to new members.” The stories we tell are how we teach.
100
Matt "msw" Wilson @msw.bsky.social · 14/09/2025
"apparently web traffic is down because Google is giving you an answer already in the results, and you no longer have the need to visit a website" I mean, this has been a complaint for a while, even before AI entered the timeline? Who needs to go to a music lyrics website when it's in the Info Box?
000
Matt "msw" Wilson @msw.bsky.social · 14/09/2025
"Piracy lost, but it was always going to lose. Streaming won." But did the reader / listener / viewer win? And did the content creators win? 🤔
120