3 ms·
Consider, for the age and minisign/signify use-case: https://gossamer.tools https://gossamer.tools
by CiPHPerCoder 5y ago
Consider, for the age and minisign/signify use-case: https://gossamer.tools https://gossamer.tools
- ameliaquining 5y agoI haven't heard of this before. How does it compare to Sigstore? (Also, the use case here is clearly much, much narrower than for age and minisign. Which is good, assuming the problem it solves is the problem you have, but should still be noted.)
- dlor 5y agoWhoa, sigstore maintainer here. I've never seen or heard of Gossamer before. It seems very similar in design!
- CiPHPerCoder 5y agoGossamer is a 2017 design of an idea that was first published in 2015. However, it was exclusively focused on the PHP community from its inception, so it's unsurprising that nobody's heard of it.
- rectang 5y agoWhat ecosystems are out there where I can flick a switch and say 1. "automatically install signed releases" or 2. "automatically install releases signed by multiple identities"? Are any of the big language-specific ecosystems capable of that? (npm, crates.io, composer, PyPI, CPAN, Maven, rubygems, etc.)
- dlor 5y agoNothing really yet. Containers got relatively close with Notary V1, I'm focused on fixing that here in sigstore right now. I think Python, Ruby, and NPM would be great targets to go after next!
- lmm 5y agoIt's not quite flick a switch, but with maven you can specify which keys you trust to sign which of your dependencies (anything published to maven central is required to be signed). E.g. here's one of my libraries: https://github.com/m50d/tierney/blob/master/free/keys.properties https://github.com/m50d/tierney/blob/master/free/keys.proper...
- rectang 5y agoIs there a straightforward way to use attestations to gate automatic updates? For example, it would be nice to delay automatic updates of WordPress plugins and themes until after there is more than just the uploader's identity as a single point of failure guaranteeing that the update is genuine. (Obviously the perfect way to do things given enough developer resources is to review all code yourself before installing manually, but it would be nice to improve situations where those resources are not available.)
- CiPHPerCoder 5y agoYes: https://github.com/paragonie/libgossamer/blob/master/docs/tutorials/01-configuring-gossamer-client.md#step-two-configure-your-attestation-policy https://github.com/paragonie/libgossamer/blob/master/docs/tu... The intention was to allow security vendors to offer code reviews of open source dependencies, and you can choose which you trust. This mechanizes Linus's Law and ensures there's an audit trail with "many eyeballs".
- rectang 5y agoThis seems like critical prerequisite infrastructure, which is fantastic — although not yet what I was asking for. As far as I can tell there is not yet a way for individual WordPress installations to actually benefit. However, it seems that work is underway: https://gossamer.tools/project/wordpress https://gossamer.tools/project/wordpress > The intention was to allow security vendors to offer code reviews of open source dependencies What I care most about is just quorum publishing where multiple independent identities sign a release, so that an attacker has to compromise multiple trusted identities to execute a supply chain attack. I'm not too excited about reviews beyond that. The main thing is to upgrade collective ecosystem security by hardening automatic updates.
- CiPHPerCoder 5y agoSolving the problem you care about requires doing what I just said. :) And, yes, there is a lot of work necessary to get WordPress to use Gossamer. I can't guarantee a deadline right now, but 2022 looks hopeful.
- Zamicol 5y agoGossamer looks similar to Google's Trillian which is written in Go. https://transparency.dev https://transparency.dev https://github.com/google/trillian https://github.com/google/trillian
- CiPHPerCoder 5y agoMore specifically, Trillian is analogous to Chronicle, which is what Gossamer uses as its underlying ledger. But yeah, there's a lot of similarities. You're on the right track. :)