Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
colek42
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
colek42
2mo ago
I really wish they would support SPIFFE/SPIRE
2.
▲
Show HN: CI/Lock – signed evidence of what your CI ran
(cilock.dev)
1 points
by
colek42
3mo ago
|
0 comments
3.
▲
Show HN: CI/lock – supply-chain attestation CLI, from the Witness creators
(cilock.dev)
1 points
by
colek42
3mo ago
|
0 comments
4.
▲
by
colek42
3mo ago
In 2016 I was working for an organization that wanted a video streaming web app, but could not tolerate any latency. In the past, we solved this with an NAPI extension in Firefox. They removed this for good security reasons, but it left o
5.
▲
by
colek42
4mo ago
There are ways to do it. Send me a message, and I can make an intro to the person we use.
6.
▲
by
colek42
4mo ago
We built https://aflock.ai/ (open source) to help with this. Constraining activity tends to work well
7.
▲
by
colek42
6mo ago
DSSE is great for this, if you need more schema use in-toto
8.
▲
by
colek42
6mo ago
We started a "science project" taking concepts from Multi Level Security to constraining AI agents. https://aflock.ai/ . The idea is to have different data zones, and if an Agent accesses from a private zone, they
9.
▲
by
colek42
7mo ago
We love Dapr's durabletask-go. https://pkg.go.dev/github.com/dapr/durabletask-go
10.
▲
by
colek42
7mo ago
Where is your line, copy editing, drafting, reorganizing? You are going to have a busy, boring, and angry life if you want to comment on every post that has signs AI touched it.
11.
▲
by
colek42
7mo ago
My job is to communicate quickly and clearly, AI helps me do my job faster and more efficiently. But thanks for telling me how I should do my job. You come off as both ignorant and arrogant.
12.
▲
by
colek42
7mo ago
That is quite an ignorant statement to make. I spent three years in combat, and am permanently disabled from my service.
13.
▲
Anthropic vs. DoD: "Any lawful use" is a fight about control
2 points
by
colek42
7mo ago
|
8 comments
14.
▲
by
colek42
7mo ago
Bingo, DoD does not want Anthropic to set guardrails on the technology it buys. If they don't want to abide they are free to deny service. We all know how that will turn our for them with the current administration. All while the Do
15.
▲
by
colek42
7mo ago
The voters and congress tell the military how to use technology, not Anthropic. Shifting the decision to Anthropic takes away power from the citizenship. Edit: The point is, go vote if you don't agree with what the administration is
16.
▲
by
colek42
1y ago
We just built a new version of the witness run action that tracks the who/what/when/where and why of the GitHub actions being used. It provides "Trusted Telemetry" in the form of SLSA and in-toto attestations. htt
17.
▲
by
colek42
1y ago
When I saw the tj-actions attack, I decided it was time to finally implement action wrapping with our `witness-run-action`. This will generate signed attestations on exactly what the actions are doing. We have some more testing to do befor
18.
▲
Shifting 'Shift Left' and What We Can Learn from Uber
(productgovernance.substack.com)
2 points
by
colek42
2y ago
|
0 comments
19.
▲
Shifting 'Shift Left' and What We Can Learn from Uber
(productgovernance.substack.com)
1 points
by
colek42
2y ago
|
0 comments
20.
▲
by
colek42
2y ago
I've been thinking about this a lot. First, the author should replace security with compliance. Currently they are two different things. There is a huge divide between compliance teams and developers, they speak completely different
21.
▲
How to Shift Compliance Left – A Letter to Developers
(productgovernance.substack.com)
3 points
by
colek42
2y ago
|
0 comments
22.
▲
Shifting Compliance Left – A Letter to Compliance Teams
(productgovernance.substack.com)
2 points
by
colek42
2y ago
|
0 comments
23.
▲
by
colek42
3y ago
We would love for you to talk about this at one of our in-toto community meetings. Let me know if you are interested. contact info is in the comments, or feel free to stop by #in-toto on CNCF slack
24.
▲
by
colek42
3y ago
Provenance is NOT injecting secret data into the build process. Provenance (scoped to supply chain security) is a document that describes the process in which the artifact goes through to become an artifact, to include all steps such as
25.
▲
by
colek42
3y ago
Step one is actually wanting to improve security. Those IoT companies have no motivator. Most of our business is with Federal/Defense and Finance. Those companies will only change if liability changes or the regulatory environment f
26.
▲
by
colek42
3y ago
I think if we can sufficiently isolate the build process we can solve this problem. Lot's of opportunity with our project Witness to add extra isolation. It is something we are working on. However, the real supply chain security &qu
27.
▲
Building an Effective Enterprise Software Supply Chain Policy
(testifysec.com)
1 points
by
colek42
4y ago
|
0 comments
28.
▲
Witness is a pluggable framework digital attestation
(github.com)
3 points
by
colek42
4y ago
|
1 comments
29.
▲
by
colek42
4y ago
Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.
30.
▲
Keyless Signing of Digital Attestations with Witness and SigStore
(testifysec.com)
1 points
by
colek42
4y ago
|
0 comments
More ›