106 karma · joined October 8, 2021
> It's wild to me that the monthly cost of the #NixOS cache infrastructure could fund the entire Arch Linux infrastructure costs for a year.
> It's 6 times the amount Arch get in monthly donations, and ~4 times Debian gets in monthly donations.
The other "bonus" is that due to CT it leaks the internal name to basically everyone on the internet. It may or may not be a problem but definitely something to be aware of.
It looks like these yaml files are not k8s files that I already have?
Also, is it open source? (I couldn't find a link to source on mobile)
Hackers can compromise python.org and sign stuff with a key advertised there. But the site is just one point. It's much harder to hack python.org and also their GitHub and Twitter account (and DNS and dozens of other supported services).
Keyoxide makes the signing key links on multiple sites thus raising a bar for accepting fake key. It's not a silver bullet obviously. Just makes the attack harder to pull and is machine readable (instead of making humans check the keys).
Thanks!
I was wondering... Is there a good book teaching Blender fundamentals covering more recent versions?
Yep. Especially given that basically all modern laptops (and some PCs) ship with TPMs and ssh can use it via the TPM PKCS#11 lib. I'm using that daily on multiple machines and it's working great.
> 95% of the unwraps in our codebase are in unit tests.
There's a crate for that: https://crates.io/crates/testresult
Hmm... I was under the impression that up until TLS 1.3 the client cert was sent in the clear during session negotiation...