Christian Folini

@christian-folini.ch

Web application security guy with a passion for OWASP's open source WAF projects and National Cyber Strategy. Maintains "Swiss Cyber Security" starter pack and cherishes his small collection of medieval helmets.

I'm very lucky that @minimus.io considers the work I do for Kubernetes to be part of my job. That isn't true for most maintainers. Projects are failing or suffering attacks because of a lack of contributors from companies built on top of them, and that's *everyone's* problem. dev.to/katcosgrove/...

When Projects Fail: Why Companies Should Treat Open Source as Infrastructure

Maintaining an open source project is hard. It requires managing a group of people who are largely...

dev.to

Ein halbes Jahr ist seit dem Launch von #Apertus verstrichen. Für die @nzz.ch am Sonntag habe ich untersucht, was daraus geworden ist. Das Fazit ist ernüchternd: Kaum jemand nutzt es. Und ausgerechnet der wichtigste Partner setzt auf Anthropic und OpenAI. www.nzz.ch/wirtschaft/n... (Geschenk-Link)

Schweizer KI Apertus: ETH-Projekt wird kaum produktiv genutzt

Ein halbes Jahr nach dem Launch nutzt noch kaum jemand das Schweizer KI-Modell Apertus. Es liegt nicht nur am fehlenden Geld.

nzz.ch

“We should be questioning how power formed in a way that enabled a handful of people—in service of their quarterly returns—to make socially significant decisions on behalf of everyone else, without scrutability, without clarity, and without democratic oversight.” - @meredithmeredith.bsky.social

I dreaded this moment a lot: Moving to a new phone. But as much as I loved my DOOGEE phone, the security update policy is not sustainable / not existing so I moved to a Fairphone yesterday. Long 🧵

My comments in @WIRED about AI-powered information operation systems. The threat aren't bots posting fakes but coordinated, persistent, human-like agent networks that manufacture the appearance of debate, consensus, disagreement. Eloquent, adaptable, detail-heavy, threads.

Bild

Whenever a big cloud service goes down I think of the Swiss gov exec who ridiculed me on a panel when I claimed it's a little known secret, but it's actually possible to run your own servers without any dependency to somebody else's computer.

For a couple of days I see a new wave of attacks hitting our WP installation. Hundreds of IPs hitting /wp-login.php. Like 10 times the normal amount of requests despite fail2ban blocking them really fast. The best defense (and there are many layers of defense) has been installing WP in a subfolder.