HNHacker News
TopNewBestAskShowJobs

decodebytes

545 karma · joined February 24, 2021

submissionscomments
decodebytes··on Kubescape – tool for testing if Kubernetes is deployed securely
ask the codecov folks if it is.
decodebytes··on On the link between great thinking and obsessive walking
This is sad. Just enjoy walking through the woods, all the different colors and use that as time to reflect. You can still think about work and coding blocks you need to overcome, but spare yourself the IDE in front of your eyes. This is just symptomatic of how we are at an extreme with how we need to be productive, all of the time.
decodebytes··on Obstructive Sleep Apnea Is Associated with Low Testosterone Levels
Do you drink any caffeine at all?

I used to think (or I believe was told), that two cups and no more before noon is ok, but found my sleep was just an utter mess. I tried everything , sleep test, black out curtains, magnesium, CBD oil, melatonin, yet it never occurred to me it could be coffee as I never drank it outside of the morning.

I cut out caffeine completely. Had a horrible withdrawal; headache from hell, back ache , neck ache, everything ache, but then around day 6 or 7 I did something I had not done in years - slept all night AND had a vivid dream (showing I was in deep REM sleep).

decodebytes··on Packaging Con 2021: a conference for package management devs and communities
it seems to be pay what you can afford.
decodebytes··on Sigstore – A new standard for signing, verifying and protecting software
Perhaps this this will put you at rest a little. The project was founded in Red Hat along Purdue University (Santiago, part of Arch Linux security team) and Google joined via GOST (The google open source security team). GOST are funded to help improve Open Source Security, they are not there to create products (they are the team that are funding the rust module work in the linux kernel). They were happy to join sigstore as Red Hat were already there first as stewards of it being open source / community centric. I also know Dan Lorenc who heads up the team and he is a great guy and very knowledgable about FOSS and Open Source.

If there were any evil intent, I am telling you know, I would be kicking up a storm.

Sorry about the "completely untrue" statement, that was not helpful. It's just we face so much unneeded FUD all the time.

decodebytes··on Sigstore – A new standard for signing, verifying and protecting software
you're free to take a parse, or even create your own project or fork.
decodebytes··on Sigstore – A new standard for signing, verifying and protecting software
One of the founders here, this is completely untrue. It's a project funded under the Linux Foundation and the service will be completely run by the Linux Foundation, the exact same mode as used for Let's Encrypt.
decodebytes··on Sigstore – A new standard for signing, verifying and protecting software
It's under the Linux Foundation, a non profit org and you also missed the third founder Purdue University for whatever reason. We also have community members from NYU, Arch Linux, Debian an Alpine Linux (plus folks from the rust community, python etc).

Red Hat and Google helps to show that money will be behind running the service (funded through the Linux Foundation)

This is the same set up with Let's Encrypt . Linux Foundation > ISRG > Let's Encrypt with money funded by corporate sponsors.

Money needs to come from somewhere when you run a critical service.

decodebytes··on Sigstore – A new standard for signing, verifying and protecting software
It supports GPG if you really want to use it (no idea why someone would want to in this day and age).
decodebytes··on Sigstore – A new standard for signing, verifying and protecting software
Good question, cosign is a client that works with containers OCI / registries. We are also develop clients to work with pypi, rust cargo and cases such as helping to protect against curl | bash attacks
decodebytes··on Sigstore – A new standard for signing, verifying and protecting software
yep, you got it.

And further to this, anyone could stand up their own sigstore service. In fact we expect some of the bigger oss projects to do just that.

decodebytes··on Sigstore – A new standard for signing, verifying and protecting software
https://twitter.com/decodebytes/status/1404540227474046980
decodebytes··on Sigstore – A new standard for signing, verifying and protecting software
This is where the transparency log comes in, certificate signing is openly auditable. It's the same as certificate transparency, malicious or mistakenly administered certificates are openly auditable (instead of being a transaction that occurs behind the doors of a commercial CA).
decodebytes··on Sigstore – A new standard for signing, verifying and protecting software
This is where the transparency log comes in. The hash / signature and public key (by way of a signed x509 certificate) are hashed into an tamper resistant immutable merkle tree. This makes it hard to tamper with the hash. However a bad hash could still be put into the tree, but this is sort of a feature not a bug aspect of a transparency log, anyone can audit the log and see those bad entries. You as an individual are not susceptible to a targeted attack, you see what everyone else sees.

This is an idiom borrowed from certificate transparency. You kind of want the badly signed certs to be recorded, as they can be monitored and audited for. Everything is out in the open in the plain light of day.

decodebytes··on Sigstore – A new standard for signing, verifying and protecting software
One of the co-founders here.

sigstore will be a non profit / free to use service. Think Let's Encrypt for software signing.

My hope is that we shift the paradigm so that consuming untrusted software via packages / dependencies etc becomes as unappealing as serving a website over just plain ole HTTP has now become.

In order to make that shift, open source communities require a free and easy to use service and this is what we hope sigstore will become, which is why it's a Linux Foundation project with all code being developed and maintained by a community.

decodebytes··on Golang Security Checker
Not sure, if you're aware. I was replying to the comment asking for the same tool, but for rust.
decodebytes··on Golang Security Checker
grep for unsafe
decodebytes··on Bitcoin Cryptography: Simply Explained
This is quite a nice introduction to cryptography on it's own, there is not Bitcoin aspect to it at all.

It introduces what cryptography (very basic number shift cyphers) and then brings in hashing , symmetric / asymmetric encryption and the finally elliptic curves.

decodebytes··on As lockdowns lift, media firms brace for an “attention recession”
It really is. The stuff facebook serves to me is just so badly wrong it's hilarious that they are taken someone's money to show me an add which if anything is going to result in me even less likely to buy the product
decodebytes··on I, Token: The untold story of the hole in Bitcoin's heart
Not here to defend bitcoin, but that's not true. You can buy all three of those (to varying degrees in different countries).
decodebytes··on A Large-Scale Security-Oriented Static Analysis of Python Packages in PyPI
One of the Bandit maintainers here (the tool used for this research). static analysis results cannot be used for the overall security posture of an application.

Bandit can and has often found vulnerabilities, but its not something you can run and expect accurate results every time.

It requires human review as it will get things wrong and require adjustments to skip false positives at each later run.

decodebytes··on I went to the office for the first time. I fucking hated it
I disagree.

Right now some of the most cutting edge technology is developed within Open Source communities, predominantly resourced by geographically spread folks from different companies / independents - all using tools to communicate / collaborate.

I think this is a case of argue your limitations and they are yours.

decodebytes··on Is Aging Inevitable?
There was a documentary in the UK which I just cannot remember the name of anymore. They have an African tribe (father and mother) exchange places with a middle class father and mother in a UK suburb. One interesting element was how the Africans were appalled that they put their mother into a care home, this was just unacceptable in their view.
decodebytes··on Technical Introduction to the Use of Trusted Platform Module 2.0 with Linux [pdf]
Anyone interested in leveraging a TPM, it's worth a look at the open source project https://keylime.dev

In regards to dane-pgp highlighting Intel TXT / tboot, Keylime does not use this. It measures via grub and a uefi shim (for measure boot) for run time file monitoring, it uses the Linux Kernels IMA.

decodebytes··on John Lewis slams UK education system and offers staff literacy lessons
They are not asking for math geniuses?
decodebytes··on Jim Whitehurst to step down as IBM President
I am at RH right now, engineering. Things have really not changed. I will be honest I am a little nervous that Jim has left, but I think on the whole it's still a great place to work right now. In 3-5 years , who knows?
decodebytes··on Why Can’t I Sleep?
outuled the iron thing already, had a blood panel and levels were very good.
decodebytes··on Why Can’t I Sleep?
Hey, I have this really bad. Around 7-8pm I feel like I want someone to pull on my legs hard and they get an antsy feeling where I cannot keep them still. When I then go to bed, my legs kick and jerk , my wife has complained about me actually kicking her in the shins and drawing blood from my toenails.

I have heard of medication, such as Dopamine agonists, but got concerned they might have other side effects.

May I ask what your Dr has prescribed to you>?

decodebytes··on Apple employee group rejects planned return to the office
> I never understood why someone would live over an hour away from where they work

property prices.

decodebytes··on Apple asks staff to return to office 3 days a week starting in early September
Surely if they have crippling social anxiety, being stuck in an office all day with others where they are expected to socialise no matter how bad their anxiety might be playing up on any given day, is far worse?

Also the only social part I referenced was coffee with close friends. I think drinking a coffee with an understanding friend(s) is much easier then being around 20+ colleagues for 8 hours straight.

← PreviousPage 3 of 4Next →