<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[BSD Cafe Lounge]]></title><description><![CDATA[Grab a drink, take a seat. 
Off-topic chat, introductions, and anything that doesn&#x27;t fit elsewhere.]]></description><link>https://billboard.bsd.cafe/category/2</link><generator>RSS for Node</generator><lastBuildDate>Thu, 13 Aug 2026 12:03:21 GMT</lastBuildDate><atom:link href="https://billboard.bsd.cafe/category/2.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 30 Jul 2026 03:20:36 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Smart TVs as residential proxies: a timeline]]></title><description><![CDATA[A follow-up to https://mastodon.bsd.cafe/@82mhz/117002938483503805 @82mhz
The linked article (June 2026) began:

The work at Include Security has us working with AI day in and day out (hacking it, using it, training it, etc). ..

– 18–23 minutes, according to Firefox Reader.
I used AI to get a concise timeline. The text below is taken from Claude's response.

…
The general practice: 2015
The root of it all is Hola VPN / Luminati (Bright Data's predecessor). In May 2015, it was discovered that Hola — a free "VPN" — was quietly turning users' devices into paid exit nodes sold through a sibling brand, Luminati, at up to $20/GB. The discovery came after 8chan's admin, Frederick Brennan, traced a wave of DDoS/spam attacks against his site back to Hola users being abused as a botnet, and outlets like The Register, Fortune/Motherboard, and TechRadar covered it within days. Hola's Luminati brand was described as "the world's largest VPN network," routing HTTP, HTTPS, or TLS requests through millions of idling end-user devices. Luminati (founded 2014) was Hola's mechanism for selling access to its userbase as exit nodes, charging $20 per gigabyte for bandwidth from its free VPN users, and it later rebranded as Bright Data. So the general "your free app is secretly selling your connection as a proxy" pattern is a 2015 story, not a 2026 one.
The smart-TV-specific angle: February 2026
The TV angle specifically is much newer, and predates the IncludeSecurity teardown by about three and a half months. Independent tech journalist Janko Roettgers broke it in his Lowpass newsletter (syndicated by The Verge) in late February 2026: with Bright's SDK, a viewer's smart TV becomes part of a massive global proxy network that crawls and scrapes the web, alongside apps on desktop PCs and mobile devices, with the company claiming roughly 150 million such residential proxies worldwide, gathering data later resold to train AI models. Multiple later write-ups explicitly credit this as the origin point: "Lowpass, syndicated by The Verge, first surfaced the smart-TV angle in February, and this is the technical teardown."
The AI-scraping tie-in and platform response: 2025–early 2026
Around the same period, the broader AI-scraping-via-residential-proxy story was already building: Krebs reported in October 2025 on botnets like Aisuru fueling large-scale AI data harvesting, and Google dismantled the criminal IPIDEA proxy network in January 2026. By April 2026, FlatpanelsHD was reporting that Amazon, Google and Roku had restricted Bright Data and similar residential proxy networks from their app SDKs (Fire TV, Google TV, Roku OS), while Bright Data continued listing LG's webOS and Samsung's Tizen as partners, with over 200 apps on webOS alone.
Your June 2026 post: the deep technical teardown
The IncludeSecurity/Buchodi post you linked was the first to actually reverse-engineer the SDK rather than just report on the business model — documenting the peer channel's weak authentication and the iOS VPN bypass — which is why it got picked up so widely (Hacker News, Krebs, CyberSecurityNews, etc.) even though the underlying phenomenon was already known.
Aftermath
A follow-up Spur.us platform scan in June 2026 quantified the scale: Bright Data, Bright Data Ltd, and Bright SDK accounted for 367 proxy-flagged apps in their dataset, with residential proxy SDKs found in nearly half of scanned LG webOS apps and over a quarter of Samsung Tizen apps. And just last week, Krebs on Security reported LG moving to ban these SDKs from its smart TV apps entirely.
So the short answer: the general practice (apps quietly monetizing users' devices as residential proxy exit nodes) was first exposed in 2015 with Hola/Luminati; the smart-TV-specific version of that story broke in February 2026 via Lowpass/The Verge; and your June 2026 link is the deep technical forensic follow-up, not the original discovery.
]]></description><link>https://billboard.bsd.cafe/topic/313/smart-tvs-as-residential-proxies-a-timeline</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/313/smart-tvs-as-residential-proxies-a-timeline</guid><dc:creator><![CDATA[grahamperrin]]></dc:creator><pubDate>Thu, 30 Jul 2026 03:20:36 GMT</pubDate></item><item><title><![CDATA[High-Quality Chaos | daniel.haxx.se]]></title><description><![CDATA[https://daniel.haxx.se/blog/2026/04/22/high-quality-chaos/ via https://mastodon.social/@bagder/116448188069484288 (2026-04-22) – not recent, but it's news to me.
From today's post about last month's Ottawa FreeBSD Developer Summit:

Michael Winser – Alpha Omega – The Changing Landscape of Open Source Software Security

AI has entered the chat


A frame from Winser's presentation:
[image: 1785197784883-9a762f41-ee1e-471a-9e56-b4100b9d01a5-image.jpeg]

Daniel Stenberg on AI in security ― sentiment over time

From Stenberg's blog post:

…
Everything is AI now
Almost every security report now uses AI to various degrees. You can tell by the way they are worded, how the report is phrased and also by the fact that they now easily get very detailed duplicates in ways that can’t be done had they been written by humans.
The difference now compared to before however, is that they are mostly very high quality.
The reporters rarely mention exactly which AI tool or model they used (and really, we don’t care), but the evidence is strong that they used such help.
We are not unique
I did a quick unscientific poll on Mastodon to see if other Open Source projects see the same trends and man, do they! Friends from the following projects confirmed that they too see this trend. …

Additional tag: AI
― #ai is currently not possible in (NodeBB) BSD Cafe Billboard.
]]></description><link>https://billboard.bsd.cafe/topic/311/high-quality-chaos-daniel.haxx.se</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/311/high-quality-chaos-daniel.haxx.se</guid><dc:creator><![CDATA[grahamperrin]]></dc:creator><pubDate>Tue, 28 Jul 2026 00:26:05 GMT</pubDate></item><item><title><![CDATA[bzfs-1.23.0 is out : r&#x2F;zfs]]></title><description><![CDATA[https://www.reddit.com/r/zfs/comments/1uo72bi/bzfs1230_is_out/

…  bzfs is a CLI for reliable ZFS snapshot replication using zfs send/receive and SSH. It is meant for the boring-but-important corner of infrastructure where "probably replicated" is not the vibe.
The main bit in this release: bzfs can now drive recursive resumable ZFS stream packages …

]]></description><link>https://billboard.bsd.cafe/topic/288/bzfs-1.23.0-is-out-r-zfs</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/288/bzfs-1.23.0-is-out-r-zfs</guid><dc:creator><![CDATA[grahamperrin]]></dc:creator><pubDate>Sun, 05 Jul 2026 17:33:24 GMT</pubDate></item><item><title><![CDATA[[Hardware Open Source]]]></title><description><![CDATA[26/08/02
⇒ reFrame — the ePaper camera

reFrame is an experimental camera with a color ePaper display. Designed to capture and display one photo at a time, making every frame deliberate and memorable.


https://reframe.camera/

]]></description><link>https://billboard.bsd.cafe/topic/286/hardware-open-source</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/286/hardware-open-source</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Fri, 03 Jul 2026 06:20:25 GMT</pubDate></item><item><title><![CDATA[Linux Foundation and Industry Leaders Launch Akrites to Defend Critical Open Source Software Against AI-Enabled Cyber Threats]]></title><description><![CDATA[Thanks, I deleted my duplicate!
]]></description><link>https://billboard.bsd.cafe/topic/281/linux-foundation-and-industry-leaders-launch-akrites-to-defend-critical-open-source-software-against-ai-enabled-cyber-threats</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/281/linux-foundation-and-industry-leaders-launch-akrites-to-defend-critical-open-source-software-against-ai-enabled-cyber-threats</guid><dc:creator><![CDATA[grahamperrin]]></dc:creator><pubDate>Mon, 29 Jun 2026 18:38:28 GMT</pubDate></item><item><title><![CDATA[Stéphane HUC :: Echoes Weekly IT]]></title><description><![CDATA[⇒ Weekly Echoes #2026W32: IT news, round-up, week 32; from 08/03 to 08/09.

https://huc.fr.eu.org/en/news/week-32-2026/

]]></description><link>https://billboard.bsd.cafe/topic/264/stéphane-huc-echoes-weekly-it</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/264/stéphane-huc-echoes-weekly-it</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Sun, 21 Jun 2026 07:40:24 GMT</pubDate></item><item><title><![CDATA[OpenZFS is amazing]]></title><description><![CDATA[
hardware corruption?!

Sometimes, errors occur when the USB connection is physically disturbed.
Other times, there's no obvious explanation. I might be hands-off, with my cat nowhere near, at the time.
]]></description><link>https://billboard.bsd.cafe/topic/251/openzfs-is-amazing</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/251/openzfs-is-amazing</guid><dc:creator><![CDATA[grahamperrin]]></dc:creator><pubDate>Tue, 16 Jun 2026 02:15:47 GMT</pubDate></item><item><title><![CDATA[Code formatting representation in Mastodon]]></title><description><![CDATA[Sorry, I omitted a link to the affected post. It's now linked from above.
Note the lines in the original. The representation in Mastodon is wrapped, no line endings.
]]></description><link>https://billboard.bsd.cafe/topic/244/code-formatting-representation-in-mastodon</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/244/code-formatting-representation-in-mastodon</guid><dc:creator><![CDATA[grahamperrin]]></dc:creator><pubDate>Sat, 13 Jun 2026 02:17:07 GMT</pubDate></item><item><title><![CDATA[Cybersecurity Incident Oracle PeopleSoft ShinyHunters Breach]]></title><description><![CDATA[https://thesiliconreview.com/2026/06/cybersecurity-incident-oracle-peoplesoft-shinyhunters-breach
It's a sensationalist article, which is not a bad thing in this case.
Less sensationally, but critical (9.8/10):

Vulnerability in the PeopleSoft Enterprise PeopleTools... · CVE-2026-35273 · GitHub Advisory Database

For the other three vulnerabilities, all moderate, that are mentioned in the article:

Vulnerability in the PeopleSoft Enterprise PeopleTools... · CVE-2026-21934 · GitHub Advisory Database
Vulnerability in the PeopleSoft Enterprise HCM Shared... · CVE-2026-22019 · GitHub Advisory Database
Vulnerability in the PeopleSoft Enterprise FIN... · CVE-2026-34299 · GitHub Advisory Database

This week's breach is all over the news, I first found it at https://mastodon.opencloud.lu/@BrideOfLinux/116737809000928257 from @BrideOfLinux@mastodon.opencloud.lu
Before Oracle responded:

Is this true? I have not seen a report yet who is affected. : r/oracle

]]></description><link>https://billboard.bsd.cafe/topic/242/cybersecurity-incident-oracle-peoplesoft-shinyhunters-breach</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/242/cybersecurity-incident-oracle-peoplesoft-shinyhunters-breach</guid><dc:creator><![CDATA[grahamperrin]]></dc:creator><pubDate>Fri, 12 Jun 2026 15:45:44 GMT</pubDate></item><item><title><![CDATA[OpenSats]]></title><description><![CDATA[For the record: I don't use Bitcoin, or anything like it.
I learnt of the organisation through Git commit log messages for an open source project – OpenSats Initiative is a sponsor.
]]></description><link>https://billboard.bsd.cafe/topic/228/opensats</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/228/opensats</guid><dc:creator><![CDATA[grahamperrin]]></dc:creator><pubDate>Sat, 06 Jun 2026 09:09:44 GMT</pubDate></item><item><title><![CDATA[Only IT Meme (image, photos, …)]]></title><description><![CDATA[[image: 1782175305024-76e6fcd1-27f9-4871-b6a4-9e6afb51c7e0-image.jpeg]
https://anonsys.net/display/bf69967c-166a-39c2-0b07-20f210082765#gallery-209712756 @scriptkiddie@anonsys.net
]]></description><link>https://billboard.bsd.cafe/topic/222/only-it-meme-image-photos</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/222/only-it-meme-image-photos</guid><dc:creator><![CDATA[grahamperrin]]></dc:creator><pubDate>Fri, 05 Jun 2026 13:28:07 GMT</pubDate></item><item><title><![CDATA[2026 Open Source Security and Risk Analysis Report – Software Governance in the AI Era – Black Duck Software, Inc.]]></title><description><![CDATA[https://www.blackduck.com/content/dam/black-duck/en-us/reports/rep-ossra.pdf

The “Open Source Security and Risk Analysis” (OSSRA) report has been the industry’s definitive look at the state of open source code for a decade. Each year, we analyze anonymized findings from commercial codebases audited by the Black Duck Audit Services team, and this provides an unmatched, real-world view of how open source is used—and sometimes misused—across every major industry. This year’s findings document a pivotal moment: The explosion of AI-assisted development has fundamentally altered the risk landscape for software and the baseline for compliance with new regulatory initiatives such as the EU Cyber Resilience Act (CRA) and the Digital Operational Resilience Act (DORA).

PDF, 44 pages.
Context
Open source organisations weigh in on age attestation
Availability
Noted in Reddit:

… easily found with Google – without completing Black Duck's form, which requires a business email address:

https://www.google.com/search?q="2026+Open+Source+Security+and+Risk+Analysis+Report"+PDF&amp;udm=14

…

]]></description><link>https://billboard.bsd.cafe/topic/221/2026-open-source-security-and-risk-analysis-report-software-governance-in-the-ai-era-black-duck-software-inc.</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/221/2026-open-source-security-and-risk-analysis-report-software-governance-in-the-ai-era-black-duck-software-inc.</guid><dc:creator><![CDATA[grahamperrin]]></dc:creator><pubDate>Wed, 03 Jun 2026 07:08:04 GMT</pubDate></item><item><title><![CDATA[To anyone promoting generative &quot;AI&quot; in any space...]]></title><description><![CDATA[@grahamperrin That was poorly written. Better said that a whole lot of money is being dumped into marketing these product before they are fully baked.
]]></description><link>https://billboard.bsd.cafe/topic/219/to-anyone-promoting-generative-ai-in-any-space...</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/219/to-anyone-promoting-generative-ai-in-any-space...</guid><dc:creator><![CDATA[etrigan63]]></dc:creator><pubDate>Mon, 01 Jun 2026 20:32:09 GMT</pubDate></item><item><title><![CDATA[QEMU: [PATCH] docs&#x2F;devel: relax policy on AI-generated contributions]]></title><description><![CDATA[https://lists.nongnu.org/archive/html/qemu-devel/2026-05/msg07614.html

Until now QEMU's code provenance policy declined any contribution believed to include or derive from AI-generated content.  A blanket ban was easy to maintain while LLM output was rarely usable on its own, but as the tools improved an absolute prohibition has become harder to justify.
…

Via QEMU Shifting On AI Policy To Allow Some AI/LLM-Generated Contributions - Phoronix

comments
discussion in r/linux – the first comment was popular but confused, I responded
mentioned in Policy for AI/LLM contributions (#697) · Issue · alpine/council
boosted in BSD Cafe Mastodon.

The email was copied to Warner Losh (FreeBSD), Alistair Francis (WD), Alex Bennée and Peter Maydell (Linaro), and three people at Red Hat.
]]></description><link>https://billboard.bsd.cafe/topic/217/qemu-patch-docs-devel-relax-policy-on-ai-generated-contributions</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/217/qemu-patch-docs-devel-relax-policy-on-ai-generated-contributions</guid><dc:creator><![CDATA[grahamperrin]]></dc:creator><pubDate>Mon, 01 Jun 2026 02:37:17 GMT</pubDate></item><item><title><![CDATA[Unlawful by design: Exposing the human rights costs of generative AI - Amnesty International]]></title><description><![CDATA[https://www.amnesty.org/en/documents/pol40/0996/2026/en/

This briefing examines how standalone generative AI systems, based on unlawful web scraping, are in conflict with international human rights law (IHRL) and standards through their design, development and deployment. While these technologies promise sophisticated automation and efficiency, they rely on data collection and model training practices that abuse privacy rights, enable discrimination, and threaten freedom of expression and thought. Amnesty International finds that standalone generative AI systems, based on unlawful web scraping, depend on mass invasions of privacy by design, and are fundamentally incompatible with IHRL. As such, Amnesty International is calling for a prohibition of such systems.

PDF, 44 pages.
]]></description><link>https://billboard.bsd.cafe/topic/216/unlawful-by-design-exposing-the-human-rights-costs-of-generative-ai-amnesty-international</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/216/unlawful-by-design-exposing-the-human-rights-costs-of-generative-ai-amnesty-international</guid><dc:creator><![CDATA[grahamperrin]]></dc:creator><pubDate>Sun, 31 May 2026 13:27:06 GMT</pubDate></item><item><title><![CDATA[The Future of Software: When AI writes the code, what do humans do?]]></title><description><![CDATA[https://engineering.oregonstate.edu/all-stories/future-software-when-ai-writes-code-what-do-humans-do
Below the four key takeaways, which I'll not quote here:

At Oregon State University’s AI Week in mid-April, a panel of academic and industry experts, … confronted a question increasingly central to computing, education, and industry: If artificial intelligence writes most of the code, what role remains for human software engineers?
The conversation blended historical reflection, a realistic outlook on the trajectory of technology, and a candid discussion about jobs, changes to university curricula, and public anxiety surrounding AI’s rapid advance. …


Additional tag: #AI (can not be entered in NodeBB).
]]></description><link>https://billboard.bsd.cafe/topic/203/the-future-of-software-when-ai-writes-the-code-what-do-humans-do</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/203/the-future-of-software-when-ai-writes-the-code-what-do-humans-do</guid><dc:creator><![CDATA[grahamperrin]]></dc:creator><pubDate>Sat, 23 May 2026 11:26:53 GMT</pubDate></item><item><title><![CDATA[Misconceptions about the UNIX Philosophy –  Jacob Moody, Posixcafe]]></title><description><![CDATA[https://posixcafe.org/blogs/2024/01/05/0/ @moody@hj.9fs.net

I recently had a discussion with a friend of mine about some talking points that Jonathan Blow made regarding the "UNIX Philosophy" during his interview on Oxide's On The Metal podcast. I'll place an excerpt of the provided transcript here. …

…

There is this idea that to be UNIX means you have multiple tiny programs talking to each other over pipes, and some even take it further to implicate that this communication must be plain text. This classification is a deep misunderstanding of the ideas put forward by UNIX, and yet is a position I see many of my peers share. …

Also:

https://mastodon.bsd.cafe/@jutty/113028308196028999 @jutty@tilde.zone
https://lobste.rs/s/dysrh2
Misconceptions about the UNIX Philosophy – Jacob Moody, Posixcafe : r/unix

]]></description><link>https://billboard.bsd.cafe/topic/196/misconceptions-about-the-unix-philosophy-jacob-moody-posixcafe</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/196/misconceptions-about-the-unix-philosophy-jacob-moody-posixcafe</guid><dc:creator><![CDATA[grahamperrin]]></dc:creator><pubDate>Thu, 21 May 2026 08:43:53 GMT</pubDate></item><item><title><![CDATA[Online forms and surveys]]></title><description><![CDATA[https://billboard.bsd.cafe/post/504 mentioned Framaforms.
From the same period in my Firefox history (July 2025): Yakforms. Related:

Oubliez Framaforms, faites de la place à Yakforms !
Forget Framaforms, make some room for Yakforms !

I don't have a saved password, I do have this in my Firefox history:

Work items · Yakforms Docs · GitLab

– which probably means that I was unable to use Yakforms at the time. An intention to report an issue.
https://redd.it/1m973go (July 2025) reminds me:

I chose to use a CryptPad instance.

Specifically:

https://pad.envs.net/

]]></description><link>https://billboard.bsd.cafe/topic/192/online-forms-and-surveys</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/192/online-forms-and-surveys</guid><dc:creator><![CDATA[grahamperrin]]></dc:creator><pubDate>Wed, 20 May 2026 10:20:16 GMT</pubDate></item><item><title><![CDATA[Framasoft and more]]></title><description><![CDATA[Exactly!
Its goal is to reduce GAFAM's dominance (particularly: Google) 
It "launch" another excellente/amazing/terrible initiative named "Les Chatons" (real FR term, translated too in EN) :

CHATONS – kittens in french – is the Collective of Hosters Alternative, Transparent, Open, Neutral and Solidarity. This collective aims to bring together structures offering free, ethical and decentralised online services in order to allow users to quickly find alternatives that respect their data and privacy to the services offered by GAFAM (Google, Apple, Facebook, Amazon, Microsoft). CHATONS is a collective initiated by the association Framasoft in 2016 following the success of its campaign De-google-ify Internet.

See: https://www.chatons.org/en
]]></description><link>https://billboard.bsd.cafe/topic/191/framasoft-and-more</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/191/framasoft-and-more</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Wed, 20 May 2026 10:06:50 GMT</pubDate></item><item><title><![CDATA[Ploopy Been is here!]]></title><description><![CDATA[
We’re releasing a brand new, open-source mouse design: the Bean, which is a pointing stick mouse (also called a nub mouse).
(…)
As with all of our other kits, the Bean is 3D-printed and fully open-source.
Mechanical files, electrical files, and firmware have all been released, along with documentation on how to make and modify your own. It’s all on Github!


https://ploopy.co/bean/
https://blog.ploopy.co/the-bean-is-here-435
https://github.com/ploopyco/bean-pointing-stick/

]]></description><link>https://billboard.bsd.cafe/topic/162/ploopy-been-is-here</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/162/ploopy-been-is-here</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Tue, 12 May 2026 11:51:16 GMT</pubDate></item><item><title><![CDATA[Mythos finds a curl vulnerability]]></title><description><![CDATA[Linked from the commentary, the gov.uk domain:

Our evaluation of OpenAI's GPT-5.5 cyber capabilities | AISI Work

]]></description><link>https://billboard.bsd.cafe/topic/160/mythos-finds-a-curl-vulnerability</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/160/mythos-finds-a-curl-vulnerability</guid><dc:creator><![CDATA[grahamperrin]]></dc:creator><pubDate>Mon, 11 May 2026 11:18:20 GMT</pubDate></item><item><title><![CDATA[OpenBSD Journal: feed down?]]></title><description><![CDATA[OK, today, we've news about this!

Due to hardware failure, the machine hosting undeadly has gone down last week. Thanks to the kind and swift help from OpenBSD.amsterdam, we're now back online. We will source new hardware for the original machine and hopefully move back again soon.


https://undeadly.org/cgi?action=article;sid=20260511202034

PS : The show must go-in on…
]]></description><link>https://billboard.bsd.cafe/topic/154/openbsd-journal-feed-down</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/154/openbsd-journal-feed-down</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Fri, 08 May 2026 14:21:04 GMT</pubDate></item><item><title><![CDATA[BSD, bottles of water, and positive habits]]></title><description><![CDATA[See:

https://www.rubenerd.au/bsd-bottles-of-water-and-positive-habits/

]]></description><link>https://billboard.bsd.cafe/topic/152/bsd-bottles-of-water-and-positive-habits</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/152/bsd-bottles-of-water-and-positive-habits</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Fri, 08 May 2026 07:27:44 GMT</pubDate></item><item><title><![CDATA[The Road to Gold: How CPS Set a New Standard for Security and Quality in Open Source]]></title><description><![CDATA[
In the world of open source, trust is our most valuable currency. ONAP is a “collection of individual, semi-standalone network automation functions that provide design, orchestration, observability, and automation of network and edge services for operators, cloud providers, and enterprises” (per ONAP). When we build software that powers global telecommunications, “good enough” isn’t an option…


https://openssf.org/blog/2026/05/07/the-road-to-gold-how-cps-set-a-new-standard-for-security-and-quality-in-open-source/

]]></description><link>https://billboard.bsd.cafe/topic/151/the-road-to-gold-how-cps-set-a-new-standard-for-security-and-quality-in-open-source</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/151/the-road-to-gold-how-cps-set-a-new-standard-for-security-and-quality-in-open-source</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Fri, 08 May 2026 06:59:33 GMT</pubDate></item></channel></rss>