Damus

Recent Notes

David Chisnall (*Now with 50% more sarcasm!*) · 15w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqql3j2atrzrjdefdhu6g0v85g3lm204ygmel625n723yl354ps68se50nxx Oh, Access was an amazing RAD tool for CRUD applications! It's such a shame that they bundled the worlds worst database with it. I did some consulting for a company that used Access as...
abadidea · 17w
One of the virtues of big open source projects is that little happens behind closed doors. However, since 99% of what they discuss just isn’t interesting to downstream end users, they forget that ...
thepwnicorn profile picture
@nprofile1q... you're right but simultaneously I've seen more than one open source project poop the deck by not thinking at all how their communication would be perceived by both users and the developer community. I know it's sometimes difficult as with everything being public you got to not only be a developer but also wear many other hats. In some cases it's quite astonishing though how much projects fail to read the room and consider the most obvious optics. See e.g. the Anthropic and Blender example. Though obviously the same can be set about some community members crossing the line with harassment.
Lesley Carhart :unverified: · 21w
If anyone’s checked it out I’d love feedback 🙃
thepwnicorn profile picture
@nprofile1q... it's looking really good! I like the premise of an insider threat, the false trail of information, different approaches one can take, and various ways intrusion may get detected. It seems to be well-suited for good story telling and mechanics that drive the story forward. Haven't had the chance to run it yet, but shared it with fellow friends who are into TTRPGs.
Security Writer :donor: · 61w
Gimmie your spiciest takes on platform managed keys vs customer managed keys. I’ll start… if you can’t manage your own keys, you probably shouldn’t be managing infrastructure* *I’ll give s...
thepwnicorn profile picture
@nprofile1q... apart from controlling their lifecycle they don't fundamentally change anything about the security of your data. The assumption is still that your cloud provider is unable to extract them from the HSM. Additionally, there is a difference between having a CMK that is merely used for wrapping data keys and actually controlling the key used for encrypting, decrypting, signing, or verifying the data.
thepwnicorn · 71w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnddaehgu3wwp6kyqpqu0zwym39375temydu688gzrxp2aqnhr0yek6u286kfxsyjg46mjsh4cl5w nostr:nprofile1qy2hwumn8ghj7un9d3shjtnddaehgu3wwp6kyqpq3whtzm3urt5tqtju80hhs3rdfc4pd3gwk73hryglk60ve7aupecqfqkdkv Example can be seen here: https://github.com/CycloneDX/bom-examples/blob...
Security Writer :donor: · 71w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnddaehgu3wwp6kyqpqql3j2atrzrjdefdhu6g0v85g3lm204ygmel625n723yl354ps68s0unejy a commercial SBoM wouldn’t, but an engineering one definitely would.