Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
trishankdatadog
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
31.
▲
Contrasting Transparent Logs and the Update Framework
(ssl.engineering.nyu.edu)
2 points
by
trishankdatadog
7y ago
|
0 comments
32.
▲
by
trishankdatadog
7y ago
Do you follow @nntaleb?
33.
▲
by
trishankdatadog
7y ago
You're also supposed to delete any dependencies you no longer need after compiling. This image might be unnecessarily large. https://stackoverflow.com/questions/46221063/what-is-build-d...
34.
▲
by
trishankdatadog
7y ago
BTW, Stadia is incredible, but the lack of high-quality big-name games is disappointing...
35.
▲
by
trishankdatadog
7y ago
One of the lead researchers and developers here. AMA!
36.
▲
Cloud Native Computing Foundation Announces TUF Graduation
(cncf.io)
1 points
by
trishankdatadog
7y ago
|
1 comments
37.
▲
by
trishankdatadog
7y ago
Thanks, Thomas!
38.
▲
by
trishankdatadog
7y ago
I am perfectly aware that Binary Authorization for Borg is for binaries running inside Google. I am saying that our solution provides almost the opposite: publicly-verifiable assurance that you are running legitimate binaries, despite being
39.
▲
by
trishankdatadog
7y ago
On a related note, we have built an E2E-verified, tamper-evident CI/CD pipeline for the Datadog Agent integrations [1]: the Agent will trust and install only integrations that correspond to source code that have signed by our developer
40.
▲
by
trishankdatadog
7y ago
If you don't trust the hardware, then don't use it. I'm not sure what solution would fit your threat model, other than building your own.
41.
▲
by
trishankdatadog
7y ago
Gentoo org was hacked on GitHub, and had their source code modified. Luckily, their private build infrastructure used only their own personal git repo, which required signing all commits (and presumably checking them). https://ww
42.
▲
by
trishankdatadog
7y ago
Yes, it's so easy with this YK setup that there's no reason not to do it. The only exception is during rebase, but there's an option in GPG to disable signing then. I sign all my commits so that everyone knows it was most lik
43.
▲
by
trishankdatadog
7y ago
I don't think so. That's what TouchID is for, and we are thinking of storing signing keys in that secure enclave in the future.
44.
▲
by
trishankdatadog
7y ago
Quality discussion, both of you, thanks!
45.
▲
by
trishankdatadog
7y ago
The GPG applet is inside the YubiKey and running entirely on there, to the best of my knowledge. Update: new YKs with new firmware are apparently able to provide proofs that the keys were generated on hardware. https://news.ycomb
46.
▲
by
trishankdatadog
7y ago
It's trivial to make backup YubiKeys. Just takes another 5m, and storing it in a secure place. I'll make a note in our README that we do do this.
47.
▲
by
trishankdatadog
7y ago
We're aware of hardware vulns like ROCA (we used to check the exact version of the YK, now we support only the major version 5). We're taking the risk anyway because the benefits of having the private keys generated and stored ent
48.
▲
by
trishankdatadog
7y ago
Good idea, will make a note, thanks!
49.
▲
by
trishankdatadog
7y ago
No, but try unplugging the YubiKey and trying again. Also, the script officially supports only YubiKey 5, but I've heard that 4 works if you remove the code that checks the version.
50.
▲
by
trishankdatadog
7y ago
No, sorry.
51.
▲
by
trishankdatadog
7y ago
If you care about who produced your source code, yes.
52.
▲
by
trishankdatadog
7y ago
To the best of my knowledge, if you trust the YubiKey firmware, and assuming that it behaves correctly, the private keys are generated on the YubiKey itself, and cannot be exported.
53.
▲
by
trishankdatadog
7y ago
That guide is great --- really helped me out when I started! Then I realized why no one uses GPG in practice: this stuff is way too hard even for security experts. That's why I believe in making things as easy and usable as possible w&
54.
▲
by
trishankdatadog
7y ago
Done, thanks!
55.
▲
by
trishankdatadog
7y ago
Interesting. This hasn't been my experience, so not sure what's going on yet...
56.
▲
by
trishankdatadog
7y ago
Yes! We are primarily a macOS shop, so I don't see us supporting Linux very much, but you are more than welcome to fork :)
57.
▲
by
trishankdatadog
7y ago
Main contributor here! Let me know if you have questions.
58.
▲
Show HN: GPG on macOS and YubiKey
(github.com)
150 points
by
trishankdatadog
7y ago
|
57 comments
59.
▲
by
trishankdatadog
7y ago
"Does your setup, or in-toto in general, get all the way into the weeds of clang, libc, the python VM, or whatever supporting tooling goes into building and running the Agent?" Not yet. This chicken-and-egg problem will take time
60.
▲
by
trishankdatadog
7y ago
The Datadog TUF + in-toto implementation is discussed in more detail here[1]. Let me know if you have questions! [1] https://www.datadoghq.com/blog/engineering/secure-publicatio...
More ›