Comments by "K" (@Kane0123) on "NDC Conferences" channel.

  1. 8
  2. 3
  3. 3
  4. "And that's what I'm changing about my own behaviour" - a level of reflection and thoughtfulness that everyone should strive for. Two things I kept thinking about throughout the chat. How would this change if we included opensource contributions as part of existing anti-exploitation in the supply chain paperwork? I have needed to sign several of these as part of client engagements, I wonder how transparency about what opensource tech we use and how we contribute to it would cause some reflection at a corporate level. I contribute to open source projects that I pull in as dependencies when delivering projects. But I guess my hope is that the underlying parts that I don't consider (things like xz fall into this) are already being taken care of it because its too hard for me an individual to go through the entire chain to allocate the individual dollars between everyone. But for someone like Microsoft, either you say you've vetted the entire chain (and thus could do that attribution) or you acknowledge you haven't (and thus can't talk to me about the security it offers). You can't know everything except how to contribute to those background pieces. I hope David gives more talks - regardless of whether its around opensource or not. -Kane, a person who just got 45minutes of solid information followed by an hour of solid reflection after paying $20 for premium, of which a fraction of a cent will go to NDC, of which 0% will go to David. Thanks to those who paid full whack at NDC London.
    3
  5. 1
  6. 1