Salta al contenuto

Piero Bosio Social Web Site Personale Logo Fediverso

Social Forum federato con il resto del mondo. Non contano le istanze, contano le persone
  • 0 Votazioni
    1 Post
    0 Visualizzazioni
    blog@shkspr.mobi
    GDS weighs in on the NHS's decision to retreat from Open Source https://shkspr.mobi/blog/2026/05/gds-weighs-in-on-the-nhss-decision-to-retreat-from-open-source/ Within the UK's Civil Service you occasionally hear the expression "being invited to a meeting without biscuits". It implies a rather frosty discussion without any of the polite niceties of a normal meeting0. In general though, even when people have severe disagreements, it is rare for tempers to fray. It is even rarer for those internal disagreements to spill over into public.Which is what makes GDS's latest guidance so surprising. At the start of the month, NHS England made the bizarre and irresponsible decision to close all their Open Source repositories due to unfounded fears of AI hacking1. Lots of people within the NHS were outraged. As were many outside - with this petition against the move gathering over 2,000 signatures.Within other parts of government there was also alarm. Although I no longer work for Government Digital Service, I was contacted by several concerned people there who remembered all my work on Open Source. The brilliant team in Whitechapel have now published their guidance "AI, open code and vulnerability risk in the public sector".It is brutal.They utterly repudiate the NHS's stance and forensically eviscerate it. I'll let you read the whole thing, but here are a few choice excerpts:Recent public reporting about organisations restricting access to public repositories due to AI-enabled code analysis illustrates how quickly leaders may reach for blanket closure in response to uncertainty.Basically, non-technical managers need to stop over-reacting.Private repositories can create a false sense of security.I think that's the crux of the argument. Closing code doesn't solve the underlying problems.Making code private is not an appropriate mitigation for lack of ownership, patching capability, or operational assurance, so systems that cannot be safely maintained should be remediated or retired.If you are so concerned about the poor security of your systems, you should shut them down completely to mitigate the threat.Closure can become a one-way door.As I said to the BMJ, "nothing lasts longer than a temporary fix".Where code has been developed in the open, making a repository private later may not remove access for a capable adversary as popular repositories are often mirrored or forkedIndeed. A friend of mine has already archived all of the NHS's repositories. You can see the ones they've tried to hide.But the killer blow, I think, is this:Moving code from public to private as a substitute for investment in secure-by-design delivery, ownership and remediation is a warning sign because it reduces sharing and scrutiny, can slow coordinated improvement across government and suppliers, and does not remove the underlying weaknesses in a running service.Exactly! Coding in the open has been shown time and again to produce high quality and secure work. The looming threat of AI vulnerability scanners doesn't change that - security is a shared responsibility. Technical teams need to be well enough resourced to create secure systems; hiding code is as reliable as papering over structural cracks.GDS was created was to be a strong centre with vast technology expertise. This was to counter the frankly shoddy approach to tech in other departments. Back then, a Service Assessment was a way for a department to prove that they were actually capable of designing, launching, and managing a complex IT project.Most departments have become significantly better at the development and running of these sorts of projects, so the raison d'etre of GDS has somewhat waned. Departments feel more confident in running off on their own. Usually I'd celebrate that - it's important that GDS doesn't become a bottleneck and that the talent is distributed throughout the whole Civil Service.But NHS England has always been a bit of a weird one. One of the reasons NHSX was created2 was to ensure that the health service had strong expertise in technology and its deployment. As the Head of Open Technology there, I helped craft the policies which embedded Open Source and Open Standards within it3.I don't know what discussions have taken place within NHS England - although I looking forward to receiving a response to my FOI request. It looks to me like a small group within NHS England have received a report showing some potential vulnerabilities discovered by Mythos. Rather than following their own internal guidance, they've over-reacted and slapped a blanket ban on coding in the open.I fervently hope that this new guidance will encourage DHSC to bring NHS England into line with best practice. If not, perhaps GDS ought to reassert itself as the technical authority with power to veto a department's incomprehensible decisions?Of course, all the budget cuts mean that biscuits cannot be purchased for any meetings. Which may explain some of the morale issues within the Civil Service. Thanks Austerity. Thausterity. ↩︎As of today, they've shut down nearly 200 repositories. More may be coming. ↩︎I was there right before the start of NHSX and helped set it up. ↩︎Which, I suppose, is why I'm bitter and angry that all our hard work is being undone. ↩︎ #AI #gds #government #nhs #nhsx #OpenSource
  • #XSF Announcement

    Mondo xsf android google jabber chat interoperability rtc opensource
    1
    1
    0 Votazioni
    1 Post
    0 Visualizzazioni
    xmpp@fosstodon.org
    #XSF AnnouncementThe XMPP Standards Foundation is officially supporting the 'Keep #Android Open' letter at @keepandroidopen.https://keepandroidopen.org/open-letter/Please support this initiative!#google #jabber #chat #interoperability #rtc #opensource #decentralization #federation #messaging #standards
  • 0 Votazioni
    13 Post
    0 Visualizzazioni
    aamfp@fosstodon.org
    @tynstarActually, you can. And with Linux is even better than Windows.https://docs.qmk.fm/features/unicode@nazgul @JohnLamp
  • 0 Votazioni
    1 Post
    0 Visualizzazioni
    elsaglug@mastodon.uno
    Installazione completata con successo in sede #ElsaGLUG! 🛠️🐧Abbiamo installato #UbuntuStudio 26.04 sul laptop di un nuovo socio. È una distro eccezionale, già configurata e ottimizzata per chi fa produzione audio, video e grafica con strumenti 100% #SoftwareLibero 🎨🎵 Il nostro fedele Tux ha supervisionato le operazioni direttamente dalla tastiera e approva il risultato! 🫡Usate anche voi questa distro? Come vi trovate?#Linux #UbuntuStudio #OpenSource #Poggibonsi #Creativita #FOSS
  • 0 Votazioni
    1 Post
    0 Visualizzazioni
    gyptazy@gyptazy.com
    AI assisted pen testing, coding and arising secvulns. Are we humans still good enough?the last weeks we saw more and more security issues coming up. Let's talk!Sorry, a pretty long blog post about this...https://gyptazy.com/blog/coding-after-ai-are-humans-still-good-enough/#ai #aicoding #coding #opensource #foss #security #infosec #vulns #developer #devops #engineer #ops #fedi #philosophy
  • Windows 9x Subsystem for Linux

    Mondo hackernews windows9x wsl linux subsystem technews opensource
    1
    0 Votazioni
    1 Post
    0 Visualizzazioni
    h4ckernews@mastodon.social
    Windows 9x Subsystem for Linuxhttps://codeberg.org/hails/wsl9x#HackerNews #Windows9x #WSL #Linux #Subsystem #TechNews #OpenSource
  • 0 Votazioni
    7 Post
    0 Visualizzazioni
    metin@graphics.social
    @haui 🙂👍 I wonder how many devs have carefully preserved their complete Amiga sources and assets, ready to be transpiled.
  • What are your plans for this weekend?

    Mondo seagl2026 cfp linux opensource floss foss oss oshw
    1
    0 Votazioni
    1 Post
    0 Visualizzazioni
    seagl@mastodon.social
    What are your plans for this weekend? How about submitting a talk for #SeaGL2026It's easy: https://seagl.org/cfp#cfp is open until end of May. First time speakers also welcomed.#linux #opensource #FLOSS #FOSS #OSS #oshw #free #libre #open #tech #community #event #seattle
  • 🆕 blog!

    Mondo government opensource
    8
    0 Votazioni
    8 Post
    0 Visualizzazioni
    nick@shore.me.uk
    @Edent@mastodon.social you are quoted in a bbc article too - BBC News - 'Millions' of pounds saved by replacing Palantir tech in refugee systemhttps://www.bbc.co.uk/news/articles/c2l2j1lxdk5o
  • Bambu Lab is abusing the open source social contract

    Mondo opensource
    16
    0 Votazioni
    16 Post
    0 Visualizzazioni
    omar@mastodon.bsd.cafe
    @yrabbit You never heard of Louis Rossmann? As Yootoober is not his job, he is free to talk and put his money where his mouth is. @stefano @geerlingguy
  • 0 Votazioni
    2 Post
    0 Visualizzazioni
    evan@cosocial.ca
    @hermes158 you what now
  • Today we are celebrating our first birthday!

    Mondo openstreetmap opensource freesoftware
    21
    0 Votazioni
    21 Post
    0 Visualizzazioni
    schimmelreiter@digitalcourage.social
    @CoMaps Congratulations! You should see the envy in people's eyes when I show them a location which isn't in Google Maps. They always try to tell me first "Google Maps is the best". And then me: "But the data is too old..."
  • 0 Votazioni
    3 Post
    0 Visualizzazioni
    legoktm@wikis.world
    @jay @securedrop yeah, good point, I'll edit it in. (We most likely will have another position available to international folks up soon too)
  • 0 Votazioni
    1 Post
    0 Visualizzazioni
    linuxeasy@mastodon.uno
    Sito JDownloader violato: installer Linux con malware RAT per root access. Una supply chain attack da non sottovalutare per utenti Linux. #JDownloader #Linux #MalwareLinux #CyberSecurity #OpenSourcehttps://www.linuxeasy.org/jdownloader-hackerato-malware-rat-linux/?utm_source=mastodon&utm_medium=jetpack_social
  • 0 Votazioni
    4 Post
    0 Visualizzazioni
    siwek@social.tooinconsistent.com
    @loz welcome! You’re in the right place. :)
  • 0 Votazioni
    1 Post
    0 Visualizzazioni
    opentitus@mastodon.uno
    Fedora 44 Workstation: Il Nuovo Standard per il Desktop Linux! 🚀🔵Basta video fatti con l'intelligenza artificiale! 🚫🤖 È arrivata Fedora 44 Workstation, la release che ridefinisce l'esperienza desktop per sviluppatori e appassionati di tutto il mondo. 🚀https://youtu.be/XbQEza0ihXA@linux#opensourceitalia #unolinux #gnulinux #distro #ita #opensource #Fedora44 #FedoraLinux #TestReale #NoIA #HumanTech #LinuxITA #Informatica #RecensioneOnesta #OpenSource #SoftwareLibero
  • 0 Votazioni
    5 Post
    0 Visualizzazioni
    coscup@floss.social
    COSCUP is not only about “success stories.”We also welcome talks from people who made mistakes, learned from them, and can help others avoid the same pitfalls.
  • 0 Votazioni
    3 Post
    0 Visualizzazioni
    krisfreedain@fosstodon.org
    @Gina thank you! I've wanted to do the Unconference talk for a while now and I'm so stoked to get the opportunity. I believe ASF does publish recordings after the conference is over on their YT channel.
  • 0 Votazioni
    1 Post
    0 Visualizzazioni
    freebsdfoundation@mastodon.social
    Duplicating Your System: Using Duplicity to Back Up Your FreeBSD Desktop.In this Q1 2026 FreeBSD Journal article, Jason Tubnor walks through a practical approach to backing up your FreeBSD system using duplicity, including encrypted backups, incremental chains, parity protection, and S3-compatible storage.Read more:https://bit.ly/4d5AR1v #FreeBSD #OpenSource #ZFS #Backup #SystemsAdministration
  • 0 Votazioni
    1 Post
    0 Visualizzazioni
    ils_alessandria@mastodon.uno
    Proseguono gli incontri sulla creazione di un server casalingo. Prossimo appuntamento, venerdì 8 maggio dalle ore 21 presso la sede di Solero.#linux #opensource #pc #software #lug #homelab @ItaLinuxSociety @linux@diggita.com @linux @opensource