Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
raphinou
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
31.
▲
by
raphinou
3mo ago
Good timing for me too. I'm currently looking for a first customer with whom I'd possibly shape the product a bit. The development phase was fun, now comes the hard part. Additionally I'm working on a security related product
32.
▲
by
raphinou
4mo ago
Putting finishing touches on an open source multi sig solution to authenticate digital artifact, aiming to increase security of the software supply chain. It's open source, completely self hostable, incl internally, support air gapped
33.
▲
Sunset of the Consumer Version of Gemini Code Assist on GitHub
(developers.google.com)
2 points
by
raphinou
4mo ago
|
0 comments
34.
▲
by
raphinou
4mo ago
The open source project I'm working on aims to authenticate artifact downloads (project name is asfaload, in short it is a sigstore alternative). My understanding is that in a post-quantum world, the private key can be derived from an
35.
▲
by
raphinou
4mo ago
I've been working on a new project using ed25519 signatures and discovered they are not quantum resistant.... I went with ed25519 due to possibility of using openssh keys. Any opinion on this choice at the light of this article and oth
36.
▲
by
raphinou
5mo ago
I agree! It's amazing to require the visitor to edit the url to go from blog to main site. For my projects I pay attention to avoid this as I find it so annoying. I want visitor that are interested to have easy access to the website!
37.
▲
by
raphinou
5mo ago
When will we finally sign artifacts? I'm not only complaining, I also work on a solution (asfaload) that I want easy to use. As it is multisig, such platform breaches become impossible. Below is the doc of the CLI, i'm looking fo
38.
▲
by
raphinou
5mo ago
I've had good experience with authelia. Simple and light to self host.
39.
▲
by
raphinou
5mo ago
I'm very happy using docker swarm on a single host with traefik as reverse proxy using the setup described here: https://dockerswarm.rocks/ Super easy deployment of additional apps, defined completely in one file (incl
40.
▲
by
raphinou
5mo ago
My understanding was they would process a refund, but no further compensation? Otherwise why would they look for an account to process the refund? English is not my first language, so I might have misunderstood....
41.
▲
by
raphinou
5mo ago
Thanks for the positive feedback! It combines administration features and end user interace. The definition of data structure is not very intuitive, and that would be the first and most important thing to fix. I think a lot of people get lo
42.
▲
by
raphinou
5mo ago
Backed by postgres, using the crosstab function. Developed and deployed on Linux Ui through the browser, built with https://websharper.com/ Thanks for the star!
43.
▲
by
raphinou
5mo ago
I have such a project I just can't shut down: https://myowndb.com/ I started it 20 years ago, with ruby on rails. I neglected it but then decided to rewrite it in F# and publish it as open source ( https://gi
44.
▲
by
raphinou
5mo ago
What solution do you use for declarative deployments? Last time I looked there was no default option?
45.
▲
by
raphinou
6mo ago
From my understanding the checkmarx attack could have been prevented by the asfaload project I'm working on. See https://github.com/asfaload/asfaload It is: - open source - accountless(keys are identity) - using a
46.
▲
by
raphinou
6mo ago
Am I missing something? I'm genuinely surprised it was not deployed from the start on a dedicated server. Don't you make a cost analysis before deploy? And if the cost analysis was ok at initial deploy, why wait to have such a dif
47.
▲
by
raphinou
6mo ago
Working on Asfaload, a multisig sign-off solution applied to release artifacts authentication. It is: - open source - accountless(keys are identity) - using a public git backend making it easily auditable - easy to self host, meaning you ca
48.
▲
by
raphinou
6mo ago
Yes, that's why I aim to make the checks transparant to the user. You only need to provide the download url for the authentication to take place. I really need to record a small demo of it.
49.
▲
by
raphinou
6mo ago
Here's the GitHub repo of the backend code: https://github.com/asfaload/asfaload There's also a spec of the approach at https://github.com/asfaload/spec I'm looking for early teste
50.
▲
by
raphinou
6mo ago
Artifact attestation are indeed another solution based on https://www.sigstore.dev/ . I still think Asfaload is a good alternative, making different choices than sigstore: - Asfaload is accountless(keys are identity) while
51.
▲
by
raphinou
6mo ago
One (amongst other) big problem with current software supply chain is that a lot of tools and dependencies are downloaded (eg from GitHub releases) without any validation that it was published by the expected author. That's why I'
52.
▲
by
raphinou
6mo ago
Just like the title
53.
▲
by
raphinou
6mo ago
I'm working on a multi signature solution that helps to detect unauthorized releases in the case of an account hijack. It is open source, self hostable, accountless and I am looking for feedback! Website: https://asfaload.co
54.
▲
by
raphinou
6mo ago
The agents run in a container and have an other git identity configured. It happens that agents commit code and I don't want to push it accidentally from outside the container, which is where I work.
55.
▲
by
raphinou
6mo ago
In my project's readme I put this text: "There is no commit by an agent user, for two reasons: * If an agent commits locally during development, the code is reviewed and often thoroughly modified and rearranged by a huma
56.
▲
by
raphinou
6mo ago
I'm working on a multi signature system for file authentication that can detect unauthorized file publications. It is self-funded, open source, auditable, self hostable, accountless. I'm looking for testers and feedback, don'
57.
▲
by
raphinou
7mo ago
I've installed https://getaurora.dev/en/ , another atomic Linux distro, for a non technical user and find it really good. I've read arguments that its architecture was better than kalpa, but I don't find
58.
▲
by
raphinou
7mo ago
I'm working on a multisig sign-off solution, with the first use case being file downloads like GitHub releases authentication: https://github.com/asfaload/asfaload I'm coming from F# and find rust a good comp
59.
▲
Never Bet Against x86
(osnews.com)
71 points
by
raphinou
7mo ago
|
120 comments
60.
▲
by
raphinou
7mo ago
It was the gigaset gs190. I've used it quite some time with e/os, but one day the automatic updates stopped working and I discovered this reinstallation requirement.
More ›