Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dlor
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
19 ms
·
151.
▲
by
dlor
5y ago
I took a look at the design and think there are a few issues with the format as proposed. # The public key is stored with the signature. This should be stored separately. A public key found here is too tempting to use, rendering the signatu
152.
▲
by
dlor
5y ago
Check out sigstore.dev for an implementation of exactly this!
153.
▲
by
dlor
5y ago
I understand the concern around anonymous identities and want to make sure it's always possible to use them. OIDC is really just the protocol, you don't even actually need to use email address-based tokens if you don't want t
154.
▲
by
dlor
5y ago
In my head Grafeas does two things: provide a data schema, and a data store. I think they both still have some value, but the schema is probably more interesting to me at this point.
155.
▲
by
dlor
5y ago
You're pretty much spot on. The problem is less about signing and more about existing PKI for git commit signing. We're working with David Huseby to help refactor the way gpg is coupled with git to enable stronger/different P
156.
▲
by
dlor
5y ago
I'm hoping Rekor can become a place these "attestations" live for open source software artifacts, allowing us to trace all of this stuff back across build systems and environments. We have a long way to go, but it's movi
157.
▲
by
dlor
5y ago
> "Is this software trustworthy?" becomes almost identical to "Is the set of people who wrote and reviewed this software trustworthy?" Yes! Simply being able to trace an artifact back to the set of people who wrote an
158.
▲
by
dlor
5y ago
The price for the water is also several orders of magnitude different. Farms pay 100-1000x less. It's not drinkable so some difference is expected, but this is too much. Raising their price would ultimately increase food prices across
159.
▲
A New Tool Wants to Save Open Source from Supply Chain Attacks
(wired.com)
13 points
by
dlor
5y ago
|
0 comments
160.
▲
A Safer Curl – Bash?
(blog.sigstore.dev)
1 points
by
dlor
5y ago
|
0 comments
161.
▲
Sigstore Project Update – Binary Transparency for JARs
(blog.sigstore.dev)
1 points
by
dlor
5y ago
|
0 comments
162.
▲
Building a security response team in Alpine
(distfiles.dereferenced.org)
1 points
by
dlor
5y ago
|
0 comments
163.
▲
by
dlor
6y ago
We have a similar approach planned in sigstore, but with a slightly different approach to the timestamps by using Transparency Logs. We have some demos here on how to sign git commits: https://github.com/sigstore/cosign
164.
▲
What's Next for Sigstore
(blog.sigstore.dev)
3 points
by
dlor
6y ago
|
0 comments
165.
▲
by
dlor
6y ago
I don't think that's true in practice. Try it. I did here: https://dlorenc.medium.com/whos-at-the-helm-1101c37bf0f1 It's basically impossible with today's tooling and practices to come up with a list of
166.
▲
by
dlor
6y ago
I sort of see this as a situation where an imperfect SBOM is worse than nothing. It would do nothing but add false confidence. I still haven't seen an example of a single supply-chain attack that an SBOM would have prevented.
167.
▲
by
dlor
6y ago
Sort of. The quality of the data this tooling generates varies GREATLY among languages, build systems and environments. For packaged software like Solarwinds, sure you can try to run an SCA tool. But is anyone claiming an SBOM or SCA tool c
168.
▲
by
dlor
6y ago
Maintainer here! That's exactly the idea. We're working with intoto and others to get metadata that we can actually verify, directly from build systems. Rekor is a place to put and find that metadata that's globally visible a
169.
▲
by
dlor
6y ago
My big problem with all the SBOM efforts is that any kind of compliance/accuracy will be best effort and most likely wrong, leading to more problems and blame. This is not as simple as writing down your dependencies. Most people don&#x
170.
▲
The Update Framework and You
(dlorenc.medium.com)
2 points
by
dlor
6y ago
|
0 comments
171.
▲
How to Sign a Release of OSS
(dlorenc.medium.com)
5 points
by
dlor
6y ago
|
0 comments
172.
▲
Cosign – Signed Container Images
(dlorenc.medium.com)
3 points
by
dlor
6y ago
|
0 comments
173.
▲
by
dlor
6y ago
I'm hoping we'll be able to take the good parts and leave the bad. IMO the problem with the app store models is that the certificate system is required, expensive and hard to use. An optional system that is free and easy to use ho
174.
▲
by
dlor
6y ago
Depends what you mean by available :) It's all basically up and running right now in a "sandbox" where we make no promises on integrity or availability but, we're encouraging people to try it out and give feedback. If yo
175.
▲
by
dlor
6y ago
I wasn't involved in those, but probably not :)
176.
▲
by
dlor
6y ago
Oh wow! This is such a nice comment to read. Anything in particular you'd like me to write about?
177.
▲
by
dlor
6y ago
Hah - probably accurate! Someone has to do it though, and I don't mind. One of my goals here is to normalize big companies giving back like this. Even with budget and supportive leadership, spending money on OSS is surprisingly difficu
178.
▲
by
dlor
6y ago
I think that's what's happening here - the PSF will be hiring someone to work 100% on core CPython for a year.
179.
▲
by
dlor
6y ago
All the overthinking on motivations here is entertaining :) Disclosure: I'm the Googler that got this funded. The process was roughly: - We have some extra budget at the end of the year! What are some ways we can spend this to get resu
180.
▲
Know, Prevent, Fix: A framework for shifting discussion around OSS security
(opensource.googleblog.com)
5 points
by
dlor
6y ago
|
0 comments
More ›