Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Foxboron
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
18 ms
·
181.
▲
by
Foxboron
4y ago
Frankly, I got a Lenovo T14 Gen 3, 12th gen Intel. It's the worst laptop I've had in a decade. They spent 6 months fixing an issue where two internal DP ports where visible to the driver which caused the kernel to not survive a su
182.
▲
by
Foxboron
4y ago
Well, the dead account has some links which I won't repost. Feel free to reach out over IRC or email if you want other/more links I guess. From what I gather is that the conflict around the website started at 35C3 with the posters
183.
▲
by
Foxboron
4y ago
Well, I don't know what to tell you. There isn't anything published around this. But you can maybe find traces of the posters on social media. They where an iteration of the "Birds doesn't exist..." posters which wa
184.
▲
by
Foxboron
4y ago
>I left the CCC in 2020 after C3 crew decided that the cock.li mail-service is a fascist and started, escalated, and carried out an attack on its administrator Vincent Canfield [1]. You choose to ignore the anti-trans posters they hung u
185.
▲
by
Foxboron
4y ago
> Good VPN company (one of the best) and good idea (sounds like USB Armory). But the best it can do is assure that their VMs are not logging anything and keep other promises. Will they also be able to share details of their hosting setup
186.
▲
by
Foxboron
4y ago
During Chaos Communication Camp in 2019 we held a veryvery improvised screening of Hackers. The people at the Norwegian hackerspace I was with had never seen the movie, clearly this was a mistake we needed to fix! For those unaware of CCCam
187.
▲
Pam Bypass: when null(is not)ok
(linderud.dev)
3 points
by
Foxboron
4y ago
|
0 comments
188.
▲
by
Foxboron
4y ago
So you , the user, can verify what the server is running :) Disclaimer: I work on this.
189.
▲
by
Foxboron
4y ago
It's the same abstraction layer though. The implementation for all three is bound to be different.
190.
▲
by
Foxboron
4y ago
So essentially this seems like another implementation of what toolbox and distrobox is implementing. https://github.com/containers/toolbox/ https://github.com/89luca89/distrobox With the down
191.
▲
by
Foxboron
4y ago
The same way LetsEncrypt makes compromised TLS certificates (almost) useless; short-lived certificats. What the sigstore project does is having an oauth portal which can authenticate one of your online identities. It uses this to sign a tem
192.
▲
by
Foxboron
4y ago
There has been some movement to improve on this, but it's a bit of work getting a signing enclave setup so we can sign binaries.
193.
▲
by
Foxboron
4y ago
cure53 has an impeccable reputation and delivered some of the best security analysis there is. Most of them are also public and on github. https://github.com/cure53/Publications
194.
▲
by
Foxboron
4y ago
I wrote sbctl to try and make sure self-enrolling keys is completely painless https://github.com/Foxboron/sbctl
195.
▲
by
Foxboron
4y ago
That would be against the current UEFI spec. I get that people are cynical and expect this to happen but I don't think it will. There are however going to be a lot more issues self-enrolling keys going forward.
196.
▲
by
Foxboron
4y ago
>And if Microsoft stops signing your bootloaders it is an automatic death sentence for your distribution, as you can no longer boot the LiveCD without "scary prompts" and/or fiddling with the BIOS setup. Not really? Severa
197.
▲
by
Foxboron
4y ago
This is a misnormer though. Secure Boot and kernel modules are not inherently dependent on each other. However modern Linux distribution carry out-of-tree patches which throws the Secure Boot keys into the Linux platform keyring and enforce
198.
▲
by
Foxboron
4y ago
Not really. We don't have any contextual information around the patches so that would be hard to infer.
199.
▲
by
Foxboron
4y ago
The kernel.org transparency log is a git repository maintained by Konstantin Ryabitsev. What I did, and the post describes, is a monitor for this log. It also doubles as a verifier which can check if all commits in a kernel release is actua
200.
▲
by
Foxboron
4y ago
It does use electron. The source code is available on github. https://github.com/mullvad/mullvadvpn-app
201.
▲
by
Foxboron
5y ago
I personally vividly hallucinate tabs, chords, shapes and scales while playing. Sometimes with it overlaying on the fretboard. Arguably this depends on how you learn and memorize, but I don't think you can discount the visual element o
202.
▲
by
Foxboron
5y ago
We have been working on it since around 2015/2016. Most of the progress has been happening the past 2 years.
203.
▲
by
Foxboron
5y ago
Yes, many times. Arch reproduces all published packages and reproducing a package as a user is as simple as running `repro pkgname.pkg.tar.gz`. https://reproducible.archlinux.org/ https://github.com/archlinu
204.
▲
Debug Packages and Debuginfod
(archlinux.org)
3 points
by
Foxboron
5y ago
|
0 comments
205.
▲
by
Foxboron
5y ago
>Hopefully this guide will stay up to date given the "move fast, break things, wontfix" approach the systemd authors currently have with the project. The core dependency principles around targets, services and startup does not
206.
▲
by
Foxboron
5y ago
Well, we also have a very nice manpage viewer. I think systemd.directives(7) is an often overlooked manpage. https://man.archlinux.org/man/systemd.directives.7
207.
▲
Systemd by Example
(systemd-by-example.com)
496 points
by
Foxboron
5y ago
|
69 comments
208.
▲
by
Foxboron
5y ago
I'm no historian either. I believe there is multiple overlapping efforts that has been cropping up over the years without necessarily being aware of each other. It would be interesting to collect the published research and blogs and ge
209.
▲
by
Foxboron
5y ago
>This probably should be made clearer, but: Reproducible builds are necessary for the security of any such system. It's outlined in earlier blog posts. >Consequently, the inclusion of reproducible build verification is taken as a
210.
▲
by
Foxboron
5y ago
Generally speaking, Transparency Logs for securing software distribution has been a research topic since around 2015, I also wrote my master thesis on the subject. Sigstore is a Transparency Log intended for provenance and software artifact
More ›