545 karma · joined February 24, 2021
I used to think (or I believe was told), that two cups and no more before noon is ok, but found my sleep was just an utter mess. I tried everything , sleep test, black out curtains, magnesium, CBD oil, melatonin, yet it never occurred to me it could be coffee as I never drank it outside of the morning.
I cut out caffeine completely. Had a horrible withdrawal; headache from hell, back ache , neck ache, everything ache, but then around day 6 or 7 I did something I had not done in years - slept all night AND had a vivid dream (showing I was in deep REM sleep).
If there were any evil intent, I am telling you know, I would be kicking up a storm.
Sorry about the "completely untrue" statement, that was not helpful. It's just we face so much unneeded FUD all the time.
Red Hat and Google helps to show that money will be behind running the service (funded through the Linux Foundation)
This is the same set up with Let's Encrypt . Linux Foundation > ISRG > Let's Encrypt with money funded by corporate sponsors.
Money needs to come from somewhere when you run a critical service.
And further to this, anyone could stand up their own sigstore service. In fact we expect some of the bigger oss projects to do just that.
This is an idiom borrowed from certificate transparency. You kind of want the badly signed certs to be recorded, as they can be monitored and audited for. Everything is out in the open in the plain light of day.
sigstore will be a non profit / free to use service. Think Let's Encrypt for software signing.
My hope is that we shift the paradigm so that consuming untrusted software via packages / dependencies etc becomes as unappealing as serving a website over just plain ole HTTP has now become.
In order to make that shift, open source communities require a free and easy to use service and this is what we hope sigstore will become, which is why it's a Linux Foundation project with all code being developed and maintained by a community.
It introduces what cryptography (very basic number shift cyphers) and then brings in hashing , symmetric / asymmetric encryption and the finally elliptic curves.
Bandit can and has often found vulnerabilities, but its not something you can run and expect accurate results every time.
It requires human review as it will get things wrong and require adjustments to skip false positives at each later run.
Right now some of the most cutting edge technology is developed within Open Source communities, predominantly resourced by geographically spread folks from different companies / independents - all using tools to communicate / collaborate.
I think this is a case of argue your limitations and they are yours.
In regards to dane-pgp highlighting Intel TXT / tboot, Keylime does not use this. It measures via grub and a uefi shim (for measure boot) for run time file monitoring, it uses the Linux Kernels IMA.
I have heard of medication, such as Dopamine agonists, but got concerned they might have other side effects.
May I ask what your Dr has prescribed to you>?
property prices.
Also the only social part I referenced was coffee with close friends. I think drinking a coffee with an understanding friend(s) is much easier then being around 20+ colleagues for 8 hours straight.