Redhat
November 12, 2024
Last week I had the opportunity to attend and speak at the International Common Criteria Conference (ICCC) in Doha, Qatar. This was a first in a number of areas: first time keynoting for longer than five minutes, first time attending a compliance-focused conference, first time …
October 31, 2024
Last week I had the opportunity to attend and speak at the OpenSSF SOSS Fusion 2024 event. This is the first full multi-day OpenSSF security event and it was a privilege to be able to attend and speak. I gave the same talk that I did at BSides back in September as I believe it …
September 28, 2024
Earlier this week I had the opportunity to attend and speak at the BSides Edmonton 2024 event. This is a local event that’s been running for a few years and oddly I’ve only been able to make it every second year, usually due to conflicts in my schedule. This year I …
August 9, 2024
Red Hat has been publishing VEX documents for some time now. VEX stands for Vulnerability Exploitability eXchange, and the documents are machine-readable JSON files that describe vulnerabilities and status for them. For example, one CVE could impact a number of different products …
June 5, 2024
Today I had the privilege of being involved in Tidelift’s Upstream 2024 virtual conference. The conference as a whole was fantastic, I watched every talk and there is some really great content there about open source security and how it’s being looked at and …
May 26, 2024
Last month I was in Denver for Red Hat Summit 2024. The keynotes are available on YouTube. This was perhaps the most energetic Summit that I’ve been to, even pre-COVID. There was a lot of activity and, of course, the primary topic was AI. We unveiled InstructLab and our …
February 6, 2024
I’ve had the opportunity to write a few blogs and articles on one of my favourite topics: vulnerability management. In particular, the thinking on risk in this space. What’s acceptable risk? What isn’t?
You can get into the details on the variety of articles …
February 2, 2024
It’s been a fantastic 15 years at Red Hat as of today. Started as a Senior Software Engineer on a very small team focused on incident response for two products (RHEL and JBoss EAP) to end up leading a large organization focused on a significant number of products and …
June 4, 2023
I had the opportunity to attend Red Hat Summit 2023 which you can watch on demand in Boston, MA. Unlike the OSS Summit, this was a 14h door-to-door trip, there and back, due to delays (typically 12h door-to-door). However the annoyance in travel was more than made up for by the …
December 18, 2022
I recently wrote for opensource.com on A new generation of tools for open source vulnerability management (the above image is credited to opensource.com).
This is my first article written there and while the article itself tends to be vendor-agnostic, this truly is an article …
February 18, 2022
Recently I had the opportunity to join a few other Red Hatters to talk about software supply chains with SiliconAngle. They did a writeup “Controlling software supply chain security will require new tools, automation and vigilance” that was great and included the …
February 1, 2022
Published on the Red Hat blog, noting here that Curated, tested and supported: How enterprise vendors mitigate open source supply chain risk was posted yesterday. It’s an article that talks about supply chain risk and associated costs – after all, no software is …
May 9, 2020
Yesterday we had someone at our home to look at replacing the front and back doors. The rep for the company was exceptionally personable and we probably spent more time with him than the simple transaction of selecting and ordering new doors for our home warranted, but my wife …
October 3, 2019
I had a great opportunity this summer to be interviewed by TelecomTV. It feels a little weird to post this here since I don’t typically “self-promote” in any way, however this was a neat experience and I think the points are good. If you’ve been looking …
February 11, 2018
I’m a week behind as the 20th anniversary of “Open Source” was a week ago. Back on February 3, 1998 the term “Open Source” was coined as a result of the decision of Netscape Communications Corp to give away the source code to it’s Netscape …
May 2, 2017
Today is the first day of Red Hat Summit 2017, this year in Boston. I’m not there, but am thoroughly enjoying watching the keynotes and other interviews via TheCube on Summit. One of the big things that we’ve been working on for a while that was announced today is …