What's any of that got to do with passkeys and attestation?
3,176 karma · joined December 14, 2011
What's any of that got to do with passkeys and attestation?
If you sample the CPU usage at 1Hz, the metric is attached to the tick event.
1. A spec 2. A ref implementation
Similar to other projects (e.g. python), if there's complaints about (2), that should trigger an ecosystem of alternative implementations that are guaranteed to be compatible because of (1).
I suspect there's actually quite a few private, separate otel implementations. Maybe these just aren't being contributed as oss?
I feel like we need the angry goose meme here.
"But why are those providers returning incorrect data?"
I thought everyone was "trying so hard to re-invent PGP".
> we do need a single key that can be used for all those things
We do? This is not obvious. Why does my disk encryption key need to be the same that I use to sign binaries that I release?
Which bit of PGP?
The database can live without the web server, but the web server doesn't work without the database.
Therefore webserver ---> database.
Key thing in that these deployment / context / container diagrams don't have a temporal axis. If you want to represent a flow, then you want a diagram where time has directionality, like a sequence diagram.
If I cock up my DNSSEC config, nobody can resolve any records under my org's domain (goodbye internal email!) and you've got to twiddle your thumbs for a period of time waiting for various timeouts to pass (go ask Slack how it went for them).
These things are not the same.
Ah yes. Let's take something that's prone to causing service issues and strap more footguns to it.
It's not worth it, because the cost is extremely quantifiable and visible, whereas the benefits struggle to be coherent.
"More secure" begs the question "against what?", which the blog post doesn't seem to want to go into. Maybe it's secure from hidden tigers.
My favourite DNSSEC "lolwut" is about how people argue that it's something "NIST recommends", whilst at the same time the most recent major DNSSEC outage was......... time.nist.gov! (https://ianix.com/pub/dnssec-outages.html)
Tags are not immutable.
You seem to be mistaking me for someone arguing that anyone is entitled to others' labour?
The restriction is on signing non web certificates with the same root/intermediate as is part of the WebPKI.
There's no rule (that I'm aware of?) that says the CAs can't have different signing roots for whatever use-case that are then trusted by people who need that use case.
My citation is the membership of the CAB.
> IMHO "other relying-party software applications" can include XMPP servers (also perhaps SMTP, IMAP, FTPS, NNTP, etc).
This may be your opinion, but what's the representation of XMPP etc. software maintainers at the CAB?
There's loads of non web, non HTTPS TLS use cases, it's just the CAB doesn't care about those (why should it?).
Knocking down half the towns that the WCML runs through to build more tracks carrying trains that aren't going to stop there would be neither easier nor cheaper than HS2.
My point was that a community is members + values + practices + other stuff. In the case where one member who wants to upend the values and practices of an existing community, "just fork it" is an entirely reasonable response.
If a change is proposed that's completely counter to a community's stated values, then I guess "fork it" is a more appropriate immediate response, because it's hard to see how such a clash could be resolved without fundamental change.
Edit
> Every community is the sum of its members
A community is much more than the sum of it's members.
Building communities is hard. It's not obvious why someone who wants a community on their terms gets to piggyback on an existing community rather than putting the effort in to make their own.
The point of "just fork it" is that if your ideas are popular, then sustainability shouldn't be a problem.
If a user asks for the source, and the distributor says "sure" and then delivers it 12 months later, have they violated the license?
It was on one of the OaF podcasts about dtrace. I worked for Reuters at the time and contempt for their customers was definitely a thread that ran through some parts of that org, even as it made a bunch of us feel very icky.
(I still have a side quest to find / talk to some of the people involved on 'our' side of the fence about this!)
Ironically, this becomes more of a concern the larger the supplier. AWS can live with firing any one of their customers - a smaller outfit probably couldn't.