3 ms·
Yeah, adding a privacy/retention policy would be a good idea. Under the hood its pretty simple (and open source), just an AWS lambda squashing the commits and
by analogj 9y ago
Yeah, adding a privacy/retention policy would be a good idea.
Under the hood its pretty simple (and open source), just an AWS lambda squashing the commits and stripping metadata before pushing to Github. Potentially you could tie the commit to an IP address, but I'm not logging any of that info.
I'm not really sure how I can prove that the code I'm running is the code you'll find on GH though.
- mappu 9y ago>I'm not really sure how I can prove that the code I'm running is the code you'll find on GH though. I think this attestation is something Amazon (and other cloud providers) could offer in the future - they're the only ones who can really prove it. "I, Amazon AWS, do solemnly declare that the code running on {service} is {git hash}"
- analogj 9y agoyeah, I guess thats how Docker does it. Automated builds tied to a github repo.
- michaelmior 9y agoThat lets you trust the image. Trusting software which is actually running somewhere seems harder.
- BinaryIdiot 9y agoOnly issue with that aspect is if they still allow configuration (I mean they'd sorta have to) and what if you could exploit a testing configuration to do whatever activity you want to hide? You could get the badge from AWS but still do what you wanted. Honestly not sure there is a good solution for that.
- michaelmior 9y agoYou could always have a script which strips down things to only necessary configuration values for production and then generates a tarball that could be verified. It seems like it would be possible to get down to a subset of settings that could take on any value while still allowing you to trust the service. Of course, if the settings don't have to be secret, they could also just be baked in as well.
- benatkin 9y agohttps://zeit.co/now https://zeit.co/now has a way to get the source, by going to /_src on a deployment. It's turned off by default for paid accounts, but can be turned on. It also has a way to get it from the API, along with the URL of the deployment. Glitch comes to mind, too.
- paulie_a 9y agoWhy? Personally I see those policies as a joke with zero credibility or recourse
- synotna 9y agoDepends where you choose to reside, they are enforceable in e.g. Europe