<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>opensource on Dendritic Tech</title>
    <link>https://dendritictech.com/tags/opensource/</link>
    <description>Recent content in opensource on Dendritic Tech</description>
    <generator>Hugo -- gohugo.io</generator>
    <copyright>&amp;copy; 2020. All rights reserved.</copyright>
    <lastBuildDate>Sat, 11 Jan 2020 14:38:09 -0800</lastBuildDate><atom:link href="https://dendritictech.com/tags/opensource/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>NPM Maintainers Security Review</title>
      <link>https://dendritictech.com/post/npm-maintainers-security-review/</link>
      <pubDate>Sat, 11 Jan 2020 14:38:09 -0800</pubDate>
      
      <guid>https://dendritictech.com/post/npm-maintainers-security-review/</guid>
      <description>After brief investigation of the top 1,000 downloaded NPM Packages, we found that a number of the package maintainers accounts have insufficient protection against basic account takeover methods. This could affect a number of downstream projects, some of which help host basic and foundational infrastructure in modern, digital society.
In the tech world, we stand upon the shoulders of giants.
If those giants have weak security authenticating their identities, they may crumble.</description>
    </item>
    
    <item>
      <title>36c3 Talks and Toys - Part 2</title>
      <link>https://dendritictech.com/post/36c3-talks-and-toys/</link>
      <pubDate>Tue, 31 Dec 2019 06:27:56 -0800</pubDate>
      
      <guid>https://dendritictech.com/post/36c3-talks-and-toys/</guid>
      <description>&lt;p&gt;Reflections on hardware, talks, and other interactions at the 36th Chaos Communication Congress.&lt;/p&gt;</description>
    </item>
    
  </channel>
</rss>
