Otto Kekäläinen
banner
ottoke.bsky.social
Otto Kekäläinen
@ottoke.bsky.social
Posts on open source software, technology, business and the environment. More at https://optimizedbyotto.com/
I had an interesting discussion about software supply-chain security with @josh.bressers.name in the Open Source Security podcast last week: opensourcesecurity.io/2025/2025-11...

#opensource #security
Detecting XZ in Debian with Otto Kekäläinen
In this episode, Josh and Otto dive into the world of Debian packaging, exploring the challenges of supply chain security and the importance of transparency in open source projects. They discuss Otto’...
opensourcesecurity.io
November 12, 2025 at 7:28 AM
Subscribe to the Open Source Security podcast (opensourcesecurity.io) on your favorite platform and check out the latest episode where I am talking about how I did the XZ Utils analysis in Debian.
November 3, 2025 at 5:21 PM
Big shoutout to @anarazel.de for spotting the XZ backdoor in March of 2024! 🙌
My new post explores how the malicious changes showed up in Debian’s import of the upstream version and if the Debian maintainer could have seen them: optimizedbyotto.com/post/xz-back...

#Linux #OpenSource #Cybersecurity
Could the XZ backdoor have been detected with better Git and Debian packaging practices?
The discovery of a backdoor in XZ Utils earlier this year shocked the open source community, raising critical questions about software supply chain security. This post explores whether better Debian p...
optimizedbyotto.com
October 19, 2025 at 5:24 PM
Reposted by Otto Kekäläinen
#Ubuntu 25.10 “Questing Quokka” Is Now Available for Download, This Is What’s New 9to5linux.com/ubuntu-25-10...

#Linux #OpenSource
Ubuntu 25.10 "Questing Quokka" Is Now Available for Download, This Is What's New - 9to5Linux
Ubuntu 25.10 "Questing Quokka" distribution is now available for download powered by Linux kernel 6.17 and using the GNOME 49 desktop.
9to5linux.com
October 9, 2025 at 8:45 AM
Awesome to see #Omarchy getting more visibility! 🔥 Fireship’s vid youtu.be/DC2p3kFjcK0 spreading the #Linux desktop to 500k+ viewers is huge!
I don't use this distro myself, but I still cheer for anything that helps motivate Windows users to make the switch.
There's a new Linux distro in town for developers...
YouTube video by Fireship
youtu.be
September 27, 2025 at 4:00 PM
Tired of wrestling with TLS certs and CAs for your database? MariaDB 11.8's zero-configuration TLS requires no manual setup 🚀
Check out security management tips at
optimizedbyotto.com/post/zero-co...
#MariaDB #DatabaseSecurity #OpenSource
Zero-configuration TLS and password management best practices in MariaDB 11.8
Locking down database access is probably the single most important thing for a system administrator or software developer to prevent their application from leaking its data. As MariaDB 11.8 is the fir...
optimizedbyotto.com
September 14, 2025 at 3:45 PM
I got hooked on browsing @openalternative.co's "Most Popular" list.

The list at openalternative.co?sort=pagevie... is an absolute gem in finding what are the trending state-of-the-art open source programs out there 🔥
September 12, 2025 at 5:22 AM
Seeing David Heinemeier Hansson so excited about #Linux on the desktop and building his ultimate #webdeveloper setup omarchy.org is inspiring!
Check out the first 5 minutes of the video on the front page 📽️
Omarchy
An opinionated Arch + Hyprland Setup by DHH
omarchy.org
August 28, 2025 at 6:45 PM
Are you contributing to Debian? Check out my best practices for submitting and reviewing Merge Request on Salsa, #Debian's #GitLab instance.

optimizedbyotto.com/post/debian-...
Best Practices for Submitting and Reviewing Merge Requests in Debian
Historically the primary way to contribute to Debian has been to email the Debian bug tracker with a code patch. Now that 92% of all Debian source packages are hosted at salsa.debian.org — the GitLab ...
optimizedbyotto.com
August 18, 2025 at 3:57 PM
Reposted by Otto Kekäläinen
Debian Linux version 13 has been officially released. Let the celebration begun ...

micronews.debian.org
Debian micronews
micronews.debian.org
August 9, 2025 at 3:47 PM
Debian 13 "trixie" has been released! 🥳
Official release notes at www.debian.org/News/2025/20...

#debian #debian13 #trixie #opensoruce
Debian -- News -- Debian 13 "trixie" released
www.debian.org
August 9, 2025 at 7:01 PM
#DebConf25 started today with 460+ registered attendees in Brest, France. Hoping to see many attendees in all 3 of my talks :)
#opensource #debian #linux
July 14, 2025 at 12:50 PM
Is your company planning to start contributing to open source? 🚀 My new post shares best practices for corporate upstream contributions, spanning things from legal compliance (CRA is coming!) to reputation & quality: optimizedbyotto.com/post/best-pr...
#OpenSource #SoftwareEngineering #CRA #SBOM
Corporate best practices for upstream open source contributions
This post is based on presentation given at the Validos annual members’ meeting on June 25th, 2025.\n
optimizedbyotto.com
June 30, 2025 at 1:54 PM
If you are integrating LLMs with databases, check out github.com/bytebase/dbh... - a universal MCP server connecting to MariaDB, TiDB, PostgreSQL and more
#opensource #mcp #AI
GitHub - bytebase/dbhub: Universal database MCP server connecting to MySQL, PostgreSQL, SQL Server, MariaDB.
Universal database MCP server connecting to MySQL, PostgreSQL, SQL Server, MariaDB. - bytebase/dbhub
github.com
June 21, 2025 at 8:05 AM
MariaDB 11.8 LTS is now officially available. Read about vector support and other new features at mariadb.com/resources/bl...
#mariadb #opensource
MariaDB Community Server 11.8 LTS is Now Available | MariaDB
Learn what’s new in the recently released MariaDB Community Server 11.8 LTS release and tech preview release of MariaDB Enterprise Platform 2026.
mariadb.com
June 5, 2025 at 12:50 PM
Planning to create .deb packages? 🚀

See my recommended workflow for new Debian packages when upstream uses git: optimizedbyotto.com/post/debian-...

#Debian #Git #OpenSource
Creating Debian packages from upstream Git
In this post, I demonstrate the optimal workflow for creating new Debian packages in 2025, preserving the upstream git history. The motivation for this is to lower the barrier for sharing improvements...
optimizedbyotto.com
May 25, 2025 at 8:41 AM
Google Summer of Code 2025 projects announced! Thrilled that 9 students got approved for #Debian. I'll mentor 2 to enhance #GitLab CI for 27,000+ git repos on salsa.debian.org
summerofcode.withgoogle.com/programs/202...
#GSoC #OpenSource
May 13, 2025 at 4:00 PM
Career news: I've left AWS to dedicate the time to full-time #OpenSource development, focusing on #Debian, #Linux, and critical digital infrastructure.

Why? Open source has won, now we need to focus on *maintaining* it 🛠️

Read more at optimizedbyotto.com/post/full-ti...
Going Full-Time as an Open Source Developer
After careful consideration, I’ve decided to embark on a new chapter in my professional journey. I’ve left my position at AWS to dedicate at least the next six months to developing open source softwar...
optimizedbyotto.com
April 16, 2025 at 11:13 AM
💻🌟 Students! Want a #GoogleSummerOfCode project? I’ll mentor you to improve Salsa CI, @gitlab.com CI pipeline used by 27k+ packages in @debian.bsky.social.
See optimizedbyotto.com/post/debian-... & apply by Apr 8!
#GSoC #OpenSource
Debian Salsa CI in Google Summer of Code 2025
Are you a student aspiring to participate in the Google Summer of Code 2025? Would you like to improve the continuous integration pipeline used at salsa.debian.org, the Debian GitLab instance, to help...
optimizedbyotto.com
March 25, 2025 at 7:46 AM
Do you know what ActivityPub, AT Protocol, Farcaster, Lens and Nostr are?

Check my latest optimizedbyotto.com/post/distrib... about the state of decentralized social media in 2025, with stats 📊

#decentralized #fediverse #web3
Will decentralized social media soon go mainstream?
In today’s digital landscape, social media is more than just a communication tool — it is the primary medium for global discourse. Heads of state, corporate leaders and cultural influencers now broadc...
optimizedbyotto.com
March 9, 2025 at 7:26 PM
I've begun exploring @beeper.com to manage my Telegram, WhatsApp, and #Matrix messages in one app. It’s impressive – and #opensource too.

Have you used it? Could this be the ultimate solution for messaging app sprawl?

www.beeper.com
February 28, 2025 at 6:00 AM
February 16, 2025 at 8:41 PM
Are you in Vancouver and keen to learn cryptography and zero-knowledge proofs? There are still a few spots left at the workshop this weekend by Wanseob Lim from the Ethereum Foundation.

Details: lu.ma/al7b7sox

#Cryptography #ZeroKnowledge #Ethereum
Zero Knowledge Weekend Workshop Vancouver · Luma
Note: This workshop is designed specifically for students and individuals passionate about becoming leaders in their local Zero-Knowledge (ZK) cryptography…
lu.ma
February 8, 2025 at 3:33 AM
Heading to #FOSDEM2025? Join thousands of fellow open source enthusiasts! I'll be there - hit me up if you want to meet up and chat about code, community, or anything in between! 🙌 #OpenSource #Database
January 29, 2025 at 7:10 AM