Bonum Certa Men Certa

Sirius ‘Open Source’ Misleading the International Organization for Standardization (ISO) on Security

What if ISO knew the truth?

International Organization for Standardization (ISO) brag



Summary: There are no proper and truly compliance-driven procedures that are being followed, actively used, or even vaguely specified by poor leadership at Sirius ‘Open Source’; it's all improvised, hugely deficient, not even remotely compliant, and changes are sometimes made retroactively due to lapses and mistakes (compliance or merely appearance thereof, albeit only "after the act"); eventually there are attempts to shoot the messengers -- those who have actually cautioned about those concerning things for several years already

THE "Conclusion" part of the report (a document we'll publish tomorrow as PDF) is included at the bottom of this post. Worry not, it's not the end of the series, only the end of this report; we have plenty left to show and to explain after that. We're eager to show to the world what Sirius ‘Open Source’ Inc./Limited/Corporation truly is.



"We're eager to show to the world what Sirius ‘Open Source’ Inc./Limited/Corporation truly is."As a teaser of sorts, consider how poorly the company was handling data and information. It was getting worse over time because skilled people were leaving the company, making way for the "Google is your friend" mantra. This aforementioned mantra was something along the lines of, "trust big companies", you can give them any data we have. Trust them, they're big! Sure, they also spy for a government.

Data of high-profile clients, both past and present, was naturally left scattered all over the place, sometimes even outside the country. And to give just one example (there are so many; some will be covered later this month and next month), colleagues have cognition reports and incremental/full load reports on local -- as in personal and offsite -- machines (this is indirectly related to patients' data) with no protocol or guidelines for removing these. There's potentially sensitive data on people's machines at home and we've already witnessed mistakes made by the clients themselves (like patients' names or similar data showing up by mistake/accident).

THIS SHOULD NEVER HAPPEN!

"There are serious ramifications for data protection and adherence to law..."In a saner world, everything would be uploaded to a firewalled file server located on the client's own network, accessible in some secure fashion, without the data ever leaving the network, not even metadata. But when a company like Sirius handles its E-mail via AWS and AWS is also the host of OTRS (ticketing), one is expected to just upload files to AWS and transmit the stuff over E-mail (i.e. open relays). No encryption. I was repeatedly told off for using PGP in my E-mails.

There are serious ramifications for data protection and adherence to law, as there are unpatched old machines and perhaps backups that contain such files -- a ticking time bomb. And even way after they're no longer a client (years later), the example above serves to show that the problem does not go away. Not even when the contract ends (or gets terminated).

"Clients simply come to assume the reputation earned in past decades persists to date."The sad reality is that the company, Sirius (so-called 'open source'), is terrified about clients finding out how reckless and incompetent the company gradually became. Clients simply come to assume the reputation earned in past decades persists to date. They're trusting a company run by a person divorced twice, whose kids refuse to even speak to him. How can deep trust be established with people who (if they get caught) simply pretend nothing bad happened and instead of apologising would rather get aggressive, even combative, to cover up the abuse?

The text below mentions ISO, security incidents, and then the company's attempts to shoot the messenger (who cautioned about those issues along with many other issues). The in-depth analysis of the witch-hunt will follow after this report is published in full (some time tomorrow).




Conclusion



To summarise, Sirius should simply admit out in the open: "we've deviated away from our mission," and moreover Sirius ignores warnings about security (ISO deserves to know about phonies and posers at security).

Roy internally cautioned about this several times over the years. Later, when some providers suffers security breaches (as Roy predicted) Sirius neither reset the passwords nor left the compromised providers.

To reiterate what was stated at the start, what's alleged here is factually correct and evidence-backed. No URLs are provided, but URLs can be provided shall they be requested. Brevity still matters and much remains to be told.

In regards to the weak accusations leveraged to avoid paying compensation to Roy and Rianne, here again is the gist of the underlying issue/s:

1. no due process 2. no evidence presented (or claims merely alluded to without context/link) 3. gross accusation inflation 4. guilt by association (identical letter, too) 5. the company has a history doing this to couples, e.g. one blind colleague based in Germany; it was very serious and it went to court (cost the company or its Directors -- the founder and his wife -- a lot of money, went on for a long time, settled at the end)

The document is far from complete. Roy and Rianne have documents, have screenshots, links to official documents from Companies House etc. ⬆

Recent Techrights' Posts

Creditors beware: VMS Enterprises Ltd vs Brexit Party (Reform UK Party Ltd)
Reprinted with permission from Daniel Pocock
 
EPO "Cocaine Communication Manager" - Part XVII - A Vote for Campinos This Month (Reappointment) Would be an Endorsement of Cocaine
The harder they try to silence critics, the worse it'll get
The Cyber Show on "Career Scientists" (Resellers of Establishment Brands Like GAFAM)
"The "career scientist" - with PhD and research office by their mid-twenties - follows well oiled tracks and institutional signposts, steering away from controversial or "difficult" subjects."
Reporting Court Matters While Preserving Dignity of Staff
There's a high and growing probability we'll take our appeal to the Court of Appeal next year
Broligarchs Speech-Policing, Faux 'Community' or 'Hub' in 'User-Driven' Clothing
Until a broligarch decides to "flag" inconvenient stories
Gemini Links 02/10/2026: Haiku, Microsoft EEE ('Linux' as a Container in Windows), and ROOPHLOCH 2026 Roundup
Links for the day
Microsoft Promised Them Bonuses, Instead They May Get Laid Off
Laid off or paid off?
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, October 01, 2026
IRC logs for Thursday, October 01, 2026
Lots of People Left Red Hat This Week, No Announcement Made of Layoffs
Companies just find ways and excuses not to announce their layoffs
Gemini Links 01/10/2026: Gemini-to-Web Proxies Considered Harmful, ROOPHLOCH 2026 at Griffith Park Observatory
Links for the day
"SPONSORED FEATURE" of HPE and NVIDIA at The Register MS Has Just Mentioned "AI" 68 Times in One Page!
Meanwhile, grown-ups ignore the hype and get work done without slop
Microsoft's XBox Layoffs Not Finished, Won't be Finished, It's Called "Forever Layoffs"
Microsoft will shut down (XBox) after shrinking it, there's no need to sell anything (a straw man)
IBM's Red Hat Lost Lots of People Today, Chief People Officer (CPO) Dethroned
Headcount falls shortly in secret.
Microsoft is "Pushing Up Daisies" Amid Mass Layoffs (Secret Ones)
"Longtime Microsoft research leader Peter Lee and former LinkedIn CEO Ryan Roslansky to depart"
Links 01/10/2026: "Lawyer Cites ChatGPT-Invented Fake Witnesses in Murder Appeal" and The 'Linux' Foundation Technical Advisory Board (TAB) Has Vacuum
Links for the day
Brigading Against Women - Part XIII - The Offer We Didn't Ask For (and Under Threats to a Lady at the Webhost, a Form of Extortion From America)
Two and a half months ago Garrett made an offer to my wife
Techrights Turning 20 Next Month
Our image is under attack, our finances are constantly under attack and so on
Links 01/10/2026: "Meat Proxies" and "Japan’s Far Right Is Courting Young Voters"
Links for the day
Red Hat Being Phased Out of Existence (Like Many Other Companies That IBM Bought)
The "Red Hat" brand (and badge) is being dissolved some more today [...] IBM is imploding 'creatively'.
IBM Layoffs Cover-up
thelayoff.com is censoring threads
"Restricted Boot" Garrett's State is Now Implementing Kill Switches (Just What We've Warned About All Along)
The underlying concept is hardly new
Brett Wilson LLP Has Had No Annual Report in 16 Months
A cynic might hint that they try to hide something
Reform UK last minute accounts filing
Reprinted with permission from Daniel Pocock
Gemini Links 01/10/2026: "Babel With Better Hardware", Software Input That's Slop, and DWeb Cascadia 2026
Links for the day
Today is D-Day at Red Hat and People Leave in Droves
They said there would be "bluewashing", we're mostly seeing people announcing they're leaving
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, September 30, 2026
IRC logs for Wednesday, September 30, 2026
Gemini Links 30/09/2026: Fish Leather, Slop Formation, and ROOPHLOCH
Links for the day
In a Lot of Europe (or EU) Android (With Linux) is Bigger Than Windows
For example in Greece
Slop-Posting is a New Form of S---posting
We recently caught several more "linux" sites (with "linux" in their domain name) turning to slop
EPO Cocainegate: Lots of Money (Over a Million Euros) for Cocaine Addicts, Not for Children With Special Needs
Next month we'll bring out some more Campinos scandals
High Court victory: Nigel Farage is 'the Company's own candidate'
Reprinted with permission from Daniel Pocock
It Took GNOME's Code of Conduct Committee (CoCC) Over 8 Months to Realise CoC Reports Went Into /dev/null/
It would be ironic if the blunder's culprits were punished for it, would it not?
Links 30/09/2026: Microsoft "OpenAI Ignored Employees’ Warnings About Safely" and "Pentagon Personnel Agency Data Breach Impacts 3 Million People"
Links for the day
The Register MS "Events" As Paid Spam That Promotes and Keeps Afloat Hype About Slop
This dreary sort of media reads like a soup of words, i.e. like the thing it is advertising
Digital Independence in the UK and in Western Europe
We have the technical capacity and skilled personnel to achieve this
IBM's Anderon as a Mass Layoffs Ritual With a Bailout (From US Taxpayers to IBM) and Other Perks
Like those empty promises in the first term of the Cheeto dictator
Gemini Links 30/09/2026: David Bowie, Web Rendering Proxy, Ink and Letters, Gemlog Nostalgia
Links for the day
EPO Annual General Meeting (AGM) Will Speak of Financial State of the EPO's Union
Their work is needed because the EPO breaks the law
Rust Causes Upgrade Issues in Ubuntu
They could just keep GNU coreutils in place (nothing was broken about it) and avoid Microsoft's back doors and TPMs
Losses From Slop Are "Investment", Hundreds of Billions in Debt Are "Growth Opportunity", Layoffs Are "Great to See", and Loss of Business Means "We Need a Slowdown" (for "Safety")
Microsoft is removing staff, as investment is apparently the act of shrtinking
Brigading Against Women - Part XII - Toxic Masculinity, Hunting Women, Will Code for Sex
Who says things like these?
The Microsoft Lunduke Slop Problem
Microsoft Lunduke does not support Software Freedom; he serves to discredit many ideas championed by Free software or ideals articulated which are apolitical for the most part
Links 30/09/2026: "Understanding the LLM Bubble" and "Florida Senate Threatened Legal Action Against Newspapers"
Links for the day
It Looks Like Mass Layoffs at "Nordcloud, an IBM Company" Today (a Day Ahead of Red Hat)
Expect the same from Red Hat next
British Prime Minister Recognises Social Control Media as National Cohesion Problem
one has to wonder if addiction to social control media is not compatible with peace
The Future Isn't Social Control Media (Nothing Will be Left of It, Not Even Archives)
"Error code: 502 Bad Gateway"
GNU/Linux Usage in China is Increasing
China is leaving Microsoft and Windows behind
43 Years of GNU and GAFAM's (Especially Microsoft's) Attacks On It
GNU is very widely used (when people say "Linux commands" they typically mean "GNU programs"), hence it's being attacked a lot
CDMAG Covers Free Software, New Magazine From Decent People
If enough people accessed their site, they would not rely on social control media (third parties, censorship platforms)
Brigading Against Women - Part XI - An Abject Lack of Social Skills (and Not Knowing How to Handle Women)
GGG enjoy - if that's the right term - very bizarre or esoteric sex life
Gemini Links 30/09/2026: Accelerationism, "The Billionaire is Wrong", Rant About LLM-generated Support E-mails
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, September 29, 2026
IRC logs for Tuesday, September 29, 2026