Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
CiPHPerCoder
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
91.
▲
by
CiPHPerCoder
5y ago
Academic conferences are usually "comfortable" environments with plenty of air conditioning. It might undermine the prestige a bit if we did that. Or maybe it'd have a different charm than the norm.
92.
▲
by
CiPHPerCoder
5y ago
It's not about "valid" or "no more valid". It's about context. If you want to distrust a security vendor for greenlighting something that was found to be vulnerable the following week , you'd probably be
93.
▲
by
CiPHPerCoder
5y ago
I like your style. We should start StateFairCon someday
94.
▲
by
CiPHPerCoder
5y ago
It's like ransomware for research
95.
▲
by
CiPHPerCoder
5y ago
Whenever I speak at a tech event, my attendance cost is free. (I'm still on the hook for flight and hotel, usually.)
96.
▲
by
CiPHPerCoder
5y ago
Incidentally, https://sso.tax
97.
▲
by
CiPHPerCoder
5y ago
> So you're imagining that a bunch of people trying to break into security work will do work for free in hopes of gaining potential employers'/clients' trust? We're talking about open source software. People are
98.
▲
by
CiPHPerCoder
5y ago
Yes, it's called a timestamp. Revocation of trust here isn't automated. "I just greenlit ransomware" is a very different category than "Attacks got better, as they do".
99.
▲
by
CiPHPerCoder
5y ago
I think I understand why it makes you uncomfortable. I do think they're two separate problems, and must be solved independently. Left unsolved, what you're experiencing is mostly bad optics rather than a dependent nastiness. It&#x
100.
▲
by
CiPHPerCoder
5y ago
This is about PHP code (i.e. written in the scripting language, PHP), not the PHP interpreter. Since it's a scripting language, your build artifacts will be one of: - .diff / .patch - .zip / .tar / .tar.gz - .phar (rarel
101.
▲
by
CiPHPerCoder
5y ago
https://defuse.ca/triangle-of-secure-code-delivery.htm was published in July 2014, which included Userbase Consistency Verification as a requirement... so I think that's when the use of transparency logs in solving t
102.
▲
by
CiPHPerCoder
5y ago
Rust is delightfully forward-thinking. Thanks for sharing.
103.
▲
by
CiPHPerCoder
5y ago
These are two separate things, and it's perilous to conflate them. The OSS developer is providing software that anyone can use under whatever license terms for free. How they monetize this is entirely their responsibility. Choosing a p
104.
▲
by
CiPHPerCoder
5y ago
>I also think the true meaning of attestations is a bit murky. The `spot-check` and `code-review` attestations are about source code, `reproduced` is about the build artifact, and `sec-audit` is somewhere in the middle (ideally both). Bu
105.
▲
by
CiPHPerCoder
5y ago
> I don't get it, who is going to pay for the time and energy required to audit everything? Not everything has to be audited. That's why there's different levels of attestations. In terms of economic incentives: If you&#
106.
▲
Solving Open Source Supply Chain Security for the PHP Ecosystem
(paragonie.com)
80 points
by
CiPHPerCoder
5y ago
|
28 comments
107.
▲
by
CiPHPerCoder
5y ago
> Then Google should just hire 100,000 devs this year, why not? Hold up that's actually a good idea. It would help a lot of entry level devs bulk up their resume and learn hands on skills. This would lead to an influx of sorely need
108.
▲
by
CiPHPerCoder
5y ago
I am stoked for updating all my systems to use Linux 5.17 now.
109.
▲
by
CiPHPerCoder
5y ago
Well, I'm not so sure that insincere has negative connotations in English anymore, given how ubiquitous this behavior is. But point taken.
110.
▲
by
CiPHPerCoder
5y ago
> I am sorry, I don't know how to phrase it in English without ruining the nuance. It's a mix of calculating, cunning, and a bit flirtatious? The closest word I can think for what you describe is insincere . See also: almost e
111.
▲
by
CiPHPerCoder
5y ago
Their MVP is a slide deck, or a sales website.
112.
▲
by
CiPHPerCoder
5y ago
Enjoy your vulnerabilities
113.
▲
by
CiPHPerCoder
5y ago
This is a good thing. Separate tool for separate use cases. Bug jedisct1 if you want YubiKey support for minisign.
114.
▲
by
CiPHPerCoder
5y ago
What is your bar for "audited"? I've reviewed both the design and implementation for age in the past and only found nitpicky things to improve (mostly related to HKDF). I can take a fresh look and make a pretty PDF on paragon
115.
▲
by
CiPHPerCoder
5y ago
> So, it's brand new. Got it. No. Brand new means completely new . Something that's going on 3 years old isn't brand new anymore. A more appropriately term is relatively new . Civilization is relatively new compared to
116.
▲
by
CiPHPerCoder
5y ago
No, Thomas was talking about rage. https://github.com/str4d/rage
117.
▲
by
CiPHPerCoder
5y ago
Confusing the two is perilous. https://blog.cryptographyengineering.com/2016/03/21/attack-o...
118.
▲
by
CiPHPerCoder
5y ago
> But what I believe someguydave was referring to was stuff like smartcard/Yubikey support, not different uses of encryption and signing. https://twitter.com/FiloSottile/status/1474941666545086465 ¯\_(ツ)_&
119.
▲
by
CiPHPerCoder
5y ago
> GnuPG has stood up pretty well for three decades Make sure you also look for libgcrypt, which had a lot of cryptographic weaknesses in the 2010s. https://www.cvedetails.com/vulnerability-list/vendor_id-4711...
120.
▲
by
CiPHPerCoder
5y ago
I don't read your wiki, so no, you were not the cause of it. This list item was prompted by a private discussion with friends.
More ›