

我國因莫德納疫苗無法穩定到貨,除原本優先接種疫苗名單第一至第三類人員和孕婦,仍維持間隔28天施打第二劑外,其他都宣佈推遲為間隔10至12週。雖然已是同島不同命,但現在等第二劑的民眾更是焦慮,因為到底能不能在12週內順利完成接種得到足夠的保護力,竟然也得不到政府的保證?在此提醒中央疫情指揮中心,到...

 新世紀エヴァンゲリヲン ED Fly Me To T...

❤️ 心樸市集 👉🏻 @chunplace ⠀ 🇹🇼(中文) 📣🌺心樸市集的元氣補給箱來囉!!!!🌺📣 當天即可到家!! 來店自取不限距離!來店自取再折 $100!! 訂購連結: https://bit.ly/3iY43x2 現在可以送雙北了 心樸市集大直店除了...

🥲 這次的影片在最後加了一小段新聞擷取來讓大家練練聽力。👇🏻是中文翻譯喔! 「5月17日,國營台灣電力公司因突然急遽上升的耗電量而於晚間8點50分開始,在台灣特定區域實施停電措施。此次耗電量突增起因於在日益增加的國內新冠疫情案例下,大部分人選擇待在家中造成,而興達發電廠發電機的失靈更加劇了此次的...

    Moderna COVID-19 vaccine
    Get your second shot 4 weeks (or 28 days) after your first.
    You should get your second shot as close to the recommended 4-week interval as possible. However, your second dose may be given up to 6 weeks (42 days) after the first dose, if necessary. You should not get the second dose early. ​There is currently limited information on the effectiveness of receiving your second shot earlier than recommended or later than 6 weeks after the first shot.



    SAGE recommends the use of the Moderna mRNA-1273 vaccine at a schedule of two doses (100 µg, 0.5 ml each) 28 days apart. If necessary, the interval between the doses may be extended to 42 days.
    Studies have shown a high public health impact where the interval has been longer than that recommended by the EUL. Accordingly, countries facing a high incidence of COVID-19 combined with severe vaccine supply constraints could consider delaying the second dose up to 12 weeks in order to achieve a higher first dose coverage in high priority populations.
    Compliance with the full schedule is recommended and the same product should be used for both doses.



    This Informal Retreat has been called to discuss how Asia-Pacific can collaborate to move through the COVID health crisis, and to accelerate the post-COVID economic recovery. Chinese Taipei will address these two topics specifically.
    On COVID-19, Chinese Taipei has had an excellent record so far. With a population of 23 million, over the last year and half, and in spite of a recent surge which has now abated, we have had a total of about fifteen thousand infected cases (.07% of the population), and 763 deaths (3 out of one hundred thousand).
    We believe that our experience and know-how gained can help other APEC members. We have been, and continue to be willing to help. We have donated masks and other medical supplies to other APEC members in the past and are ready and willing to share our anti-COVID-19 know-how with you.
    At the same time, WE NEED HELP! Our vaccination coverage at present is less than 20%. Although the U.S. and Japan have been generous in donating vaccines to us, and our private institutions have succeeded in procuring ten million doses of vaccines, we still need more vaccines, and need them sooner! Most other APEC members need help as well. We must ask for help from the APEC members that possess and produce more vaccines than they themselves need.
    On re-vitalizing Post-COVID economy, Chinese Taipei urges free trade among APEC members and in the world, after giving consideration to vital national security needs.
    In the past seven decades, free trade has enabled vibrant growth in most APEC economies. Free trade is merely a way in which each APEC economy contributes its own competitive advantage and every APEC member benefits.
    Recently, however, we note with concern the tendency to want self-sufficiency or “on-shoring” of semiconductor chips. We must point out that in the past many decades free trade has greatly helped the advance of semiconductor technology. In turn, the ever greater complexity of the technology has caused the supply chain to go “off-shore”.
    It would be highly impractical to try to turn back the clock. If it is tried, cost will go up and technology advance may slow. What may happen is that after hundreds of billions and many years have been spent, the result will still be a not-quite-self-sufficient, and high-cost supply chain.
    We do recognize national security concerns, and believe that for security applications, a self-sufficient supply chain within one’s own borders is prudent. However, for the much larger civilian market, a supply chain substantially based on free trade system is by far the best approach.
    In summary, on COVID-19, Chinese Taipei can help, is ready and willing to help with its know-how, but also needs more vaccines sooner, along with many other APEC members. On Post-COVID economic re-vitalization, Chinese Taipei urges free trade, after giving consideration to vital national security concerns.



    Ref: https://security.googleblog.com/2021/06/introducing-slsa-end-to-end-framework.html

    今天要探討的是一個由 Google Blog 於上個月所推廣的軟體安全性框架,該框架名為 SLSA,全名則是 Supply Chain Levels for Software Artifacts,中文部分我不知道該怎麼翻譯才可以精準達到意思,所以建議就唸英文就好了。

    該框架的目的是希望於整個軟體生產鏈中能夠進一步的去提升且確保所有產物的完整性(Integrity 這個詞該怎麼翻呢..)。

    文章中用了一個很簡易的流程來清楚的解釋到底何謂 Software Supply Chain 以及整個流程中可能會有什麼問題。

    Software Supply Chain 一個範例譬如
    1. 開發者撰寫程式碼,並且提交到遠方的 SCM Repository
    2. SCM Repo 因為程式碼改變,所以觸發相關的 CI/CD 流程
    3. CI/CD 建置結束後則需要打包整個程式碼,產生最後的 Package.
    4. 產生後的 Packet 則可以正式上場使用

    1. Source Integrity
    2. Build Integrity.

    Source Integrity 這邊主要是針對 Source Code 相關的問題,譬如
    1. 開發者是否有意的故意塞入一些會不懷好意的程式碼到 SCM Repo 內。
    範例: Linux Hypocrite commits, 之前美國某大學研究團隊基於研究嘗試上傳一些不太好的程式碼而影響的討論風波
    2. SCM 的管理平台是否可能被惡意攻擊
    範例: PHP 事件: 之前自架的 PHP Git Server 被攻擊者惡意攻擊並且塞入兩筆不懷好意的 Commit

    而 Build Integrity 本身則是有更多不同的面向,譬如
    1. SCM 觸發 CI/CD 過程是否有可能有問題
    範例: Webmin 事件,攻擊者去修改團隊的建置系統去使用沒有被 SCM 所記錄的修改檔案。
    2. CI/CD 建置系統本身被攻擊
    範例: SolarWinds 事件,攻擊者攻破建置系統去安裝一些軟體來修改整的建置流程
    3. CI/CD 建置過程中引用到錯誤的 Dependency
    4. 攻擊者上傳一些惡意產物到應該只有 CI/CD 系統才可以存取的場所。
    ... 等

    目前來說, SLSA 還處於非常早期階段,經由業界的共識來思考每個領域有什麼好的措施與指引來避免與偵測系統是否被攻破。其最終目標狀態是希望能夠根據環境自動產生出一套可整合到系統中的產物,並且最後可以給出 SLSA 憑證來給平台或是建置後的 Package。

    對 SLSA 這個專案有興趣看看的請參考原始連結,內容不長但是頗有趣的