HNHacker News
TopNewBestAskShowJobs

cedricbonhomme

296 karma · joined October 1, 2012

cedricbonhomme.at.hn

![Profile photo](https://avatars.githubusercontent.com/u/465400?v=4.jpg)

I'm a computer scientist, intensely interested in computer security and privacy. I contribute to many open source projects since more than 20 years.

* You can read more [about me](https://www.cedricbonhomme.org/about). * Some notable [projects](https://www.cedricbonhomme.org/software) to which I contributed. * More on [https://www.cedricbonhomme.org/blog](https://www.cedricbonhomme.org/blog) * [Fosstodon](https://fosstodon.org/@cedric)

submissionscomments
cedricbonhomme··on Pivotick is network graph library to facilitate pivoting
Nice project!
cedricbonhomme··on New Security Vulnerability Database Launches in the EU
yes, it does.
cedricbonhomme··on A client to gather vulnerability-related information from Bluesky
You can find the collected information, in real-time, on Vulnerability-Lookup: https://vulnerability.circl.lu/sightings/
cedricbonhomme··on Vulnerability-lookup version 1.2.0 released with new bundle features
A small description of the project:

""" Vulnerability Lookup facilitates quick correlation of vulnerabilities from various sources (NIST, GitHub, CSAF, PySec, VARIoT, etc.), independent of vulnerability IDs, and streamlines the management of Coordinated Vulnerability Disclosure (CVD). """

https://github.com/cve-search/vulnerability-lookup

cedricbonhomme··on Circos – Circular Visualization
I used Circos quite a lot back in time. It's written in Perl. I was working on a Python visualization tool for analyzing the relationships between different IP, from network traffic capture:

https://github.com/cedricbonhomme/IP-Link

(there is a link to the documentation with some nice chord diagrams.) This one is quite impressive: https://github.com/cedricbonhomme/IP-Link/blob/master/docs/_... nut not easy to read !

cedricbonhomme··on Vulnerability-Lookup Version 1.1.0
vulnerability-lookup version 1.1.0 released with new extension RSS/ATOM support, ability to comment vulnerabilities and many other improvements: https://github.com/cve-search/vulnerability-lookup/releases/...
cedricbonhomme··on Wanted: Feedback on an agent based (with Python SPADE) monitoring back end
And about SPADE: https://spade-mas.readthedocs.io/en/latest/readme.html
cedricbonhomme··on Wanted: Feedback on an agent based (with Python SPADE) monitoring back end
source code currently here: https://github.com/cedricbonhomme/pumpkin
cedricbonhomme··on Libre Tools from the National Cybersecurity Competence Center of Luxembourg
" ...the only entities capable of safely using the AGPL are companies using it to dump source ... "

I stopped reading here. But this will definitely make my day. I won't even start to list examples of companies (private sector, public sector, research, etc.) that are not in this "only entities".

cedricbonhomme··on Libre Tools from the National Cybersecurity Competence Center of Luxembourg
It's (Font Awesome) fa-paper-plane, and not fa-telegram.

No but seriously I admit it's not a good choice. We will change it to something else. I personally never used Telegram, I do not even know how their Website looks like.

cedricbonhomme··on Libre Tools from the National Cybersecurity Competence Center of Luxembourg
indeed, tpxl is right. Affero GPL fits well for Web software (services provided by a server).
cedricbonhomme··on Libre Tools from the National Cybersecurity Competence Center of Luxembourg
I would say this one: https://opensource.nc3.lu/projects/saems/ https://github.com/scandale-project

It's the most recent, really in development. It's about scanning IP ranges, looking for vulnerabilities (in MS Exchange Servers and various things) and sending notifications. Some parts are already used for operational stuff (NMAP Script Engines for example).

An other really interesting project, under AGPL as well: https://opensource.nc3.lu/projects/monarc/

"MONARC is an iterative and qualitative method of risk analysis in four stages, broadly inspired by ISO/IEC 27005." ;-)

And maybe this project: https://github.com/NC3-LU/MOSP As you can see it's a collaborative platform to share security related JSON objects. The nice thing is the object editing user interface automatically generated thanks to the JSON schemas. The project provides an API and is connected to every MONARC instances.

cedricbonhomme··on Libre Tools from the National Cybersecurity Competence Center of Luxembourg
source code of various related projects: https://github.com/NC3-LU/
cedricbonhomme··on Ask HN: If you used to be socially awkward and shy, how did you improve?
Middle in the left. Right most in the new. Easy to check on Flick: https://www.flickr.com/photos/perardi/ ;-)
cedricbonhomme··on Freshmeat.net, 1997-2014 (2014)
Freshmeat was really great. I was a consumer and producer of data. I remember well the announcement of the death of Freshmeat.

This is partly why I did Freshermeat [1]. I am operating an instance dedicated to security projects [2] where you can submit projects.

[1] https://github.com/cedricbonhomme/freshermeat [2] https://open-source-security-software.net

cedricbonhomme··on Improvements for MOSP including easier deployment and Heroku integration
For discussions on new upcoming features: https://github.com/CASES-LU/MOSP/discussions
cedricbonhomme··on OWASP Top 10 2021
Nice, thank you for this list!

It is now possible to import these items in the MONARC security assessment software:

https://objects.monarc.lu/schema/14 ;-)

cedricbonhomme··on Cybersecurity Weather Map with OSM
The source code of this software is here: https://github.com/monarc-project/stats-service

It is a decentralized service, here is more information: https://www.monarc.lu/documentation/stats-service/master/arc...

cedricbonhomme··on A new release of MOSP: A tool for creating, editing and sharing JSON objects
with MOSP there is no Workflow to setup. No need to edit a JSON file, the editor is generated based on the JSON schemas.

And yes, there is an API, which is already integrated with tools such as MONARC (https://github.com/monarc-project/MonarcAppFO).

The API is really easy to use. There is also a client: https://github.com/CASES-LU/PyMOSP

Versioning is planed for the next release.

cedricbonhomme··on Cybersecurity Weather Forcast
Source code: https://github.com/monarc-project/stats-service

Some explanations: https://dashboard.monarc.lu/help

cedricbonhomme··on PyMOSP, a Python library to access MOSP
About what is MOSP: https://objects.monarc.lu/about
cedricbonhomme··on IKEA buys 11,000 acres of U.S. forest to keep it from being developed
Close to the quality of an Apple product.
cedricbonhomme··on IKEA buys 11,000 acres of U.S. forest to keep it from being developed
Personally I hate IKEA because they are selling pure crap.
cedricbonhomme··on Poll: Switching from WhatsApp
This is working for me. I am already using Matrix and now my parents are ready to switch to Matrix (with Element). Thank you Facebook.
cedricbonhomme··on Poll: Switching from WhatsApp
Totally. And now, I will easily convert some members of my family to Matrix.
cedricbonhomme··on Poll: Switching from WhatsApp
Not a good comparison and quite exaggerated...
cedricbonhomme··on A watcher for contributors to various projects: GraphQL with GitHub Actions
Thank you! ;-)
cedricbonhomme··on A watcher for contributors to various projects: GraphQL with GitHub Actions
The repository is self-updated: https://github.com/cedricbonhomme/contributors/blob/master/....
cedricbonhomme··on Username/username is a special repository that adds README.md to your profile
This link is an example. It is needed to be authenticated to GitHub in order to see the result.
cedricbonhomme··on JSON relations in GDPR records of processing activities JSON object
These relations are generated based on refs in JSON schemas with MOSP: https://github.com/CASES-LU/MOSP
Page 1 of 3Next →