Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dlor
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
Memory safety is the new black, fashionable and fit for any occasion
(theregister.com)
4 points
by
dlor
4y ago
|
0 comments
62.
▲
Understanding the relationship between FOSS and the “software supply chain”
(chainguard.dev)
3 points
by
dlor
4y ago
|
1 comments
63.
▲
Are SBOMs Good Enough for Government Work?
(chainguard.dev)
1 points
by
dlor
4y ago
|
0 comments
64.
▲
by
dlor
4y ago
I disagree here - these could be targeted and just because we haven't seen impact yet doesn't mean there wasn't any. All it takes is one download from the right person then it can be pivoted into a supply chain attack.
65.
▲
by
dlor
4y ago
I don't want to speculate on exactly how the developer at CircleCI was compromised, but it wouldn't surprise me if it was something like this. They can be pretty easily targeted and it's trivial to get RCE on a developer'
66.
▲
by
dlor
4y ago
These attacks are more and more common and there's still little to actually solve them. We're working on this at Chainguard by starting at the lowest levels (a containerized Linux distro) where we can deliver packages safely. Then
67.
▲
by
dlor
4y ago
CEO here. We use a transparency log (sigstore) instead of a blockchain.
68.
▲
by
dlor
4y ago
Sigstore does this with a transparency log instead of a Blockchain.
69.
▲
Sigstore December Roundup
(blog.sigstore.dev)
1 points
by
dlor
4y ago
|
0 comments
70.
▲
Signatus, ergo securus? Who can sign what with TUF and Sigstore
(blog.sigstore.dev)
1 points
by
dlor
4y ago
|
0 comments
71.
▲
by
dlor
4y ago
Depends exactly what you're trying to create it for. I advocate for doing it during the build process rather than as a step after. We open sourced a few tools that do it automatically for containers: https://github.com/
72.
▲
by
dlor
4y ago
This type of friendly tooling is exactly what was missing from OSV! I look forward to OSV making it easier to manage and deal with vulnerabilities.
73.
▲
Sigstore the Easy Way
(rewanthtammana.com)
1 points
by
dlor
4y ago
|
0 comments
74.
▲
by
dlor
4y ago
Some kind of post-mortem or statement at all about how the GitHub account got compromised, if that's what happened here. It could have also been a researcher checking to see if anyone would notice, or something worse.
75.
▲
by
dlor
4y ago
The issue from the researchers appears to be here: https://github.com/timaakulich/fastapi_toolkit/issues/4 This is definitely pretty strange. Account takeovers happen, but just reverting the commit and closin
76.
▲
Iranian hackers use Log4Shell to mine crypto on federal computer system
(cyberscoop.com)
3 points
by
dlor
4y ago
|
0 comments
77.
▲
by
dlor
4y ago
Basically yes - unless you also keep enough metadata around somewhere for a scanner to know what version of nginx is installed. This can be done out-of-band with an SBOM, or in-band by using package manager metadata.
78.
▲
by
dlor
4y ago
This is basically the definition we used. It's practically important because scanners really do miss software copied in via other mechanisms, and most of them give zero indication about it. For a few basic examples, try running your fa
79.
▲
Software Dark Matter Is the Enemy of Software Transparency
(chainguard.dev)
8 points
by
dlor
4y ago
|
0 comments
80.
▲
by
dlor
4y ago
I'm not going to argue that the NSA report is amazing or terribly well-written, but re-reading it with the principle of charity nullifys many of these rebuttals. For one example, from the rebuttal: > If there is concern that their u
81.
▲
Sigstore Verification of CPython Releases
(python.org)
5 points
by
dlor
4y ago
|
0 comments
82.
▲
NSA, CISA, ODNI Release Software Supply Chain Guidance for Developers
(nsa.gov)
4 points
by
dlor
4y ago
|
0 comments
83.
▲
What Your Scanner Doesn't Find Can Hurt You
(blog.chainguard.dev)
2 points
by
dlor
4y ago
|
0 comments
84.
▲
by
dlor
4y ago
Shameless plug for the gitsign project in sigstore: https://github.com/sigstore/gitsign This isn't supported by GitHub yet but we're hopefully working towards that too.
85.
▲
One-Third of Popular PyPI Packages Mistakenly Flagged as Malicious
(darkreading.com)
4 points
by
dlor
4y ago
|
0 comments
86.
▲
Minimal Container Images: Towards a More Secure Future
(blog.chainguard.dev)
1 points
by
dlor
4y ago
|
0 comments
87.
▲
There's no such thing as vuln-free software, it simply doesn't exist, yet
(blog.chainguard.dev)
2 points
by
dlor
4y ago
|
0 comments
88.
▲
Iron Tiger Compromises Chat App Mimi, Targets Windows, Mac, and Linux Users
(trendmicro.com)
2 points
by
dlor
4y ago
|
0 comments
89.
▲
by
dlor
4y ago
A common gotcha is ca-certs and tzdata.
90.
▲
Adopting Sigstore Incrementally
(blog.sigstore.dev)
8 points
by
dlor
4y ago
|
0 comments
More ›