's Avatar

@ostifofficial

55
Followers
33
Following
89
Posts
02.12.2024
Joined
Posts Following

Latest posts by @ostifofficial

Meetup 010: Bitcoin Core Audit: From Static Review to Fuzzing w/ Robin David
Meetup 010: Bitcoin Core Audit: From Static Review to Fuzzing w/ Robin David YouTube video by Open Source Technology Improvement Fund (OSTIF)

Miss our last OSTIF meetup?

You can catch the recording here of Robin David, Software Security Researcher and Research Lead at Quarkslab, presenting "Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure".

www.youtube.com/watch?v=J1Y1...

#OSTIF #bitcoin

10.03.2026 15:12 👍 0 🔁 0 💬 0 📌 0
Preview
Kea and Stork Projects Audited In mid-2025 ISC contracted with OSTIF to identify an external organization to audit our Kea and Stork code for security issues.

ISC is pleased to announce the results of code audits for our Kea DHCP and Stork graphical management software projects! Thank you to @ostifofficial.bsky.social and the ICANN Grant Program for their support and assistance.

Read more about the audits at www.isc.org/blogs/2026-t...

04.03.2026 14:33 👍 1 🔁 1 💬 0 📌 0
Preview
Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure w/ Robin David · Luma Description This talk explores the internals of the Bitcoin protocol and its reference implementation, Bitcoin Core, whose first version was written by Satoshi…

Don't miss tomorrow's OSTIF meetup with Robin David, Software Security Researcher and Research Lead at Quarkslab, presenting "Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure".

luma.com/gjnorzq0

#OSTIF #OpenSource #bitcoin

03.03.2026 15:39 👍 1 🔁 0 💬 0 📌 0
Post image

OSTIF is proud to share the results of our security audit of Stork, an open source project developed by the Internet Systems Consortium (ISC) that acts as an administrative interface for monitoring, maintaining, and surveilling Kea servers.

ostif.org/stork-audit-...

#OSTIF #Stork #7ASecurity

03.03.2026 15:28 👍 2 🔁 0 💬 0 📌 0

While there is a lot to address, an important point of this story sticks out to us at OSTIF- that it was best practices, the secondary review of code before a push, that caught this before disaster struck.

27.02.2026 11:37 👍 0 🔁 0 💬 0 📌 0
The Internet Was Weeks Away From Disaster and No One Knew
The Internet Was Weeks Away From Disaster and No One Knew YouTube video by Veritasium

We, like everyone else, couldn't look away from the Veritasium video on the XZ vulnerability.

Watch the video here www.youtube.com/watch?v=aoag... to learn more details about this incredible story of open source security and community.

#OSTIF #Veritasium #XZ

27.02.2026 11:37 👍 1 🔁 0 💬 1 📌 0
Post image

For the past 4 years, OSTIF has run a Managed Audit Program for the CNCF. We’ve audited 33 projects in that time, working with maintainers all over the world to reinforce the security health of cloud native open source for billions of end users.

Read the full report here: ostif.org/cncfmanagedp...

26.02.2026 16:24 👍 0 🔁 0 💬 0 📌 0
Meetup 009: High Assurance Cryptography and the Ethics of Disclosure w/ Nadim Kobeissi
Meetup 009: High Assurance Cryptography and the Ethics of Disclosure w/ Nadim Kobeissi YouTube video by Open Source Technology Improvement Fund (OSTIF)

Miss yesterday's amazing audit meetup "High Assurance Cryptography and the Ethics of Disclosure" w/ @nadim.computer ?

Catch the video here www.youtube.com/watch?v=TdOX...

Make sure you're subscribed for notifications of any new meetups! luma.com/ostif-meetups

#OSTIF #meetup #audit

26.02.2026 15:30 👍 1 🔁 0 💬 0 📌 0
Preview
Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure w/ Robin David · Luma Description This talk explores the internals of the Bitcoin protocol and its reference implementation, Bitcoin Core, whose first version was written by Satoshi…

Join us next Wednesday for an OSTIF meetup with Robin David, Software Security Researcher and Research Lead at Quarkslab, presenting "Bitcoin Core Audit: From Static Review to Fuzzing — Inside Bitcoin’s Testing Infrastructure". luma.com/gjnorzq0

#OSTIF #OpenSource #bitcoin

26.02.2026 02:44 👍 1 🔁 0 💬 0 📌 0
Preview
Powered by LimeSurvey – The Freshest Online Survey Tool Create surveys in seconds with LimeSurvey. Easy to use, secure, and trusted by professionals worldwide. Get started free and unlock fresh insights today!

Reminder: The Sovereign Tech Agency is gathering feedback from open source maintainers and contributors working with technology standards to inform the Agency's future work and new initiatives.

➡️ survey.sovereigntechfund.de/999999?lang=...

25.02.2026 16:22 👍 1 🔁 2 💬 1 📌 0
Preview
High Assurance Cryptography and the Ethics of Disclosure w/ Nadim Kobeissi · Luma Description Formally verified cryptographic libraries are increasingly deployed in critical systems, marketed as providing the highest level of assurance…

TODAY: Join my livestreamed talk on my Cryspen findings and ask me questions! 5:00pm Paris time, coordinated with @ostifofficial.bsky.social.

Register here: luma.com/xc4yuezb?tk=...

25.02.2026 12:08 👍 1 🔁 2 💬 1 📌 0
Sovereign Tech Agency and OSTIF Security Audit Report – OSTIF.org

Our work with @sovereign.tech over the past two years resulted in 9 published audits with 6 more underway. OSTIF doesn't take lightly the responsibility we feel to help make a more resilient and secure open source ecosystem. Read more in our 2 year report: ostif.org/sovereigntec...

23.02.2026 17:10 👍 3 🔁 0 💬 0 📌 0
Preview
High Assurance Cryptography and the Ethics of Disclosure w/ Nadim Kobeissi · Luma Description Formally verified cryptographic libraries are increasingly deployed in critical systems, marketed as providing the highest level of assurance…

RSVP fornext week's OSTIF meetup with Nadim Kobeissi, Senior Applied Cryptography Auditor at Cure53 presenting "High Assurance Cryptography and the Ethics of Disclosure".

RSVPing adds the event to your calendar and lets us know you're coming!

luma.com/xc4yuezb

#OSTIF #OpenSource #disclosure

18.02.2026 17:28 👍 1 🔁 0 💬 0 📌 0
zlib Audit Complete! – OSTIF.org

Zlib is an open source lossless data-compression library for use on virtually any computer hardware and operating system.

Read about the audit process and results here 👉 ostif.org/zlib-audit-c...

17.02.2026 15:18 👍 0 🔁 0 💬 0 📌 0
Post image

The Open Source Technology Improvement Fund is proud to share the results of our security audit of zlib.

Thanks to the efforts of 7ASecurity and the Sovereign Tech Fund, this project underwent a holistic security review.

See 🧵 below 👇

#OSTIF #7ASecurity #audit #zlib

17.02.2026 15:18 👍 0 🔁 0 💬 1 📌 0
Preview
High Assurance Cryptography and the Ethics of Disclosure w/ Nadim Kobeissi · Luma Description Formally verified cryptographic libraries are increasingly deployed in critical systems, marketed as providing the highest level of assurance…

We look forward to the great conversations that happen when you can get passionate folks together to talk open source security!

Make sure to RSVP to add the event to your calendar and let us know you're coming: luma.com/xc4yuezb

12.02.2026 15:08 👍 0 🔁 0 💬 0 📌 0
Post image

Join us in 2 weeks on Wednesday, February 25th, for an OSTIF meetup with Nadim Kobeissi, Senior Applied Cryptography Auditor at Cure53 presenting "High Assurance Cryptography and the Ethics of Disclosure".

#OSTIF #OpenSource #disclosure

12.02.2026 15:08 👍 1 🔁 0 💬 1 📌 0
Preview
High Assurance Cryptography and the Ethics of Disclosure w/ Nadim Kobeissi · Luma Description Formally verified cryptographic libraries are increasingly deployed in critical systems, marketed as providing the highest level of assurance…

I'm giving a talk soon about my Cryspen findings, in collaboration with @ostifofficial.bsky.social. Happening online, will be live-streamed.

Register here: luma.com/xc4yuezb?tk=...

11.02.2026 16:10 👍 1 🔁 1 💬 0 📌 0
Post image

This month's Community Spotlight shines on Peter Hunt, Principal Software Engineer at Red Hat who has contributed to both of OSTIF's audits of CRI-O (cri-o.io). Come check out our interview!

ostif.org/feb-2026-com...

#OSTIF #Spotlight #RedHat

10.02.2026 16:03 👍 0 🔁 0 💬 0 📌 0
Video thumbnail

🆓 🎉 It's Free Open Source Software Month! Learn open source skills for FREE!

From Linux fundamentals to Kubernetes, secure software, and emerging tech, check out Linux Foundation Education’s free learning library today: training.linuxfoundation.org/resources/

#OSS #CloudNative #Linux #Kubernetes

09.02.2026 14:14 👍 19 🔁 13 💬 0 📌 1

We couldn't have done it without: @sovereign.tech @cncf.io @lfenergy.bsky.social @aswf.io @quarkslab.bsky.social @shielder.com @trailofbits.bsky.social @openssf.org @opensource.org @puerco.mx @funnelfiasco.bsky.social @nadim.computer @adamshostack.bsky.social @openforumeurope.org and so many more!

02.02.2026 18:59 👍 5 🔁 1 💬 0 📌 0
2025 Annual Report – OSTIF.org

Presenting our 2025 annual report! In our report, you’ll see that OSTIF's story and mission are intertwined. OSTIF will continue to fight for open source infrastructure and the privacy rights of users for as many decades as you’ll let us.

Our statement and report link: ostif.org/2025-annual-...

30.01.2026 15:06 👍 3 🔁 2 💬 0 📌 1
Preview
The Sovereign Tech Fund invests in Scala

Congratulations to the Scala team for securing investment in open source infrastructure with the @sovereign.tech! We're proud to contribute to this effort, and look forward to the future of Scala and this endowment's positive impact: scala-lang.org/blog/2026/01...

29.01.2026 18:45 👍 1 🔁 1 💬 0 📌 0
Post image

@lfenergy.bsky.social EVerest underwent a security engagement facilitated by us with auditing by @quarkslab.bsky.social. This holistic security work impacts millions of EV charging stations worldwide. Read more at our blog:
ostif.org/everest-secu...

20.01.2026 17:48 👍 1 🔁 1 💬 0 📌 0
Post image

We conducted the first public third-party security assessment of EVerest, an open-source firmware stack for electric vehicle charging stations, deployed in hundreds of thousands of charging points worldwide.
The audit was mandated by @ostifofficial.bsky.social 🙏

blog.quarkslab.com/everest-secu...

20.01.2026 16:45 👍 2 🔁 2 💬 0 📌 0
Post image

Having previously undergone an OSTIF security audit in 2022, Cloud Native Computing Foundation (CNCF) project CRI-O received another review in late 2025. Security auditing was performed by X41 D-Sec GmbH, and their report is available to read on our blog: ostif.org/cri-o-audit-...

13.01.2026 19:27 👍 1 🔁 0 💬 0 📌 0
Post image

Releasing today is our security audit of Internet Systems Consortium's Kea project. The project received holistic security improvements and recommendations from Ada Logics. Read more about the work performed and results to the project at our blog: ostif.org/kea-security...

12.01.2026 16:12 👍 1 🔁 0 💬 0 📌 0
Post image

OSTIF is proud to announce our membership in the Open Policy Alliance, an organization dedicated to the uplifting of open source in public knowledge and understanding! Excited to be involved in the Open Source Initiative's advocacy. Ready about it at the press release: ostif.org/ostif-joins-...

09.01.2026 15:38 👍 0 🔁 0 💬 0 📌 0
Preview
Thunderbird Send Security Audit with OSTIF and 7ASecurity - The Thunderbird Blog As we get ready for the Thunderbird Pro launch, we want every service we offer to be secure and worthy of the trust our community places in us. That means being honest about where we stand today and t...

Sorry for the hiccup with our tag in the previous post! Our thanks again to @ostifofficial.bsky.social for their help with this important audit, which you can again read about in our blog post:

blog.thunderbird.net/2025/12/thun...

10.12.2025 17:06 👍 11 🔁 3 💬 0 📌 0
Preview
Thunderbird Send Security Audit with OSTIF and 7ASecurity - The Thunderbird Blog As we get ready for the Thunderbird Pro launch, we want every service we offer to be secure and worthy of the trust our community places in us. That means being honest about where we stand today and t...

We are building tech you can trust.

Thank you to @ostifofficial.bsky.social and 7A Security for their collaboration on the security audit for Thunderbird Send, our end-to-end encrypted file transfer service (coming to everyone soon, open source now).

blog.thunderbird.net/2025/12/thun...

10.12.2025 15:24 👍 16 🔁 4 💬 0 📌 0