Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dlor
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
121.
▲
How to Verify Cosigned Container Images in Amazon ECS
(blog.chainguard.dev)
4 points
by
dlor
5y ago
|
0 comments
122.
▲
by
dlor
5y ago
I'm a maintainer on Sigstore, and we published this blog post in support of this effort too! https://blog.sigstore.dev/sigstore-ruby-ce3591838fe8
123.
▲
Delegation of Authority from the Systems Programming Perspective
(ariadne.space)
3 points
by
dlor
5y ago
|
1 comments
124.
▲
by
dlor
5y ago
Probably not for Go in containers since binaries end up compressed anyway as part of the OCI layers. But Go binaries do get quite large so if you're distributing them other ways, it might be useful.
125.
▲
by
dlor
5y ago
This is a great resource. I'd love to see more reports like it published. CI/CD pipelines often run with highly elevated permissions (access to source code, artifact repositories, and production environments), but they are traditi
126.
▲
by
dlor
5y ago
Yes yes yes yes! For some reason people want a formal specification for everything, even when "N/A" is an applicable option here.
127.
▲
by
dlor
5y ago
CBOR itself is not a draft (that's the fork of msgpack). I think COSE (which is what the post was actually about) is though: https://datatracker.ietf.org/doc/html/rfc8152
128.
▲
by
dlor
5y ago
Author here. I have nothing to do with any of those formats and didn't create or design any. I have no more context than you do either, and was surprised to find that thread on the IETF tracker to begin with.
129.
▲
by
dlor
5y ago
Oh my god the name just clicked. I knew some of the history but didn't catch he named it after himself.
130.
▲
by
dlor
5y ago
Author of the original medium post here. I had simply never heard of COSE at the time of writing this. There was no conspiracy to bury the spec. There are a bunch of vague accusations that I'm trying to profit or rent seek off of one o
131.
▲
What an SBOM Can Do for You
(blog.chainguard.dev)
2 points
by
dlor
5y ago
|
0 comments
132.
▲
Celebrating One Million Entries in Rekor
(blog.sigstore.dev)
1 points
by
dlor
5y ago
|
0 comments
133.
▲
Cosign Image Signing in AWS CodePipeline
(chainguard.dev)
2 points
by
dlor
5y ago
|
0 comments
134.
▲
by
dlor
5y ago
Nothing really yet. Containers got relatively close with Notary V1, I'm focused on fixing that here in sigstore right now. I think Python, Ruby, and NPM would be great targets to go after next!
135.
▲
by
dlor
5y ago
Whoa, sigstore maintainer here. I've never seen or heard of Gossamer before. It seems very similar in design!
136.
▲
The Sigstore Trust Model
(dlorenc.medium.com)
1 points
by
dlor
5y ago
|
0 comments
137.
▲
Zero-friction “keyless signing” with GitHub Actions
(chainguard.dev)
1 points
by
dlor
5y ago
|
0 comments
138.
▲
Busting 5 Sigstore Myths
(chainguard.dev)
4 points
by
dlor
5y ago
|
0 comments
139.
▲
Notary v2 and Cosign
(dlorenc.medium.com)
6 points
by
dlor
5y ago
|
0 comments
140.
▲
Zero Trust Supply Chain Security
(dlorenc.medium.com)
6 points
by
dlor
5y ago
|
0 comments
141.
▲
by
dlor
5y ago
Attacks here are incredibly common. Fortunately they're usually unsophisticated and are just plain crypto mining to steal CPU cycles. Worst case is if a CI system has permissions to deploy to production, which is really common too. Ano
142.
▲
by
dlor
5y ago
The root cause was a chain of known exploits due to very out of date software: * RunC v1.0.0-rc2 was released on Oct. 1, 2016, and was vulnerable to at least two container breakout CVEs. * ACI was hosted on clusters running either Kubernete
143.
▲
by
dlor
5y ago
From the researchers: > So you can imagine our surprise when we were able to gain complete unrestricted access to the accounts and databases of several thousand Microsoft Azure customers, including many Fortune 500 companies. This is bas
144.
▲
Improving the Trust-On-First-Use authentication scheme with transparency
(dlorenc.medium.com)
13 points
by
dlor
5y ago
|
2 comments
145.
▲
by
dlor
5y ago
These GitHub orgs have explicitly opted in and configured the checks, so harassing the developers in those organizations is exactly what the org owners wanted :)
146.
▲
by
dlor
5y ago
Hah! I had something similar awhile ago: https://twitter.com/lorenc_dan/status/1209289792569131008
147.
▲
In Defense of Package Managers
(dlorenc.medium.com)
5 points
by
dlor
5y ago
|
0 comments
148.
▲
Project Sigstore June Update
(blog.sigstore.dev)
3 points
by
dlor
5y ago
|
0 comments
149.
▲
by
dlor
5y ago
Exactly this. The flow should be: * Look up keys that I trust * Check if the signature verifies against any of those keys Key hints can aid in selection here if you have many trusted keys, but you can also just loop through. Not: * verify t
150.
▲
by
dlor
5y ago
Yeah, roughly this. It's only a matter of time before someone gets a signature verification error, then sees the public key here and adds it to their apt policy to get past the error.
More ›