Damus
Lance R. Vick profile picture
Lance R. Vick
@Lance R. Vick

FOSS || GTFO

* Security Engineer
* Cypherpunk
* Founder of #! (hashbang.sh), stagex.tools
* Co-founder of Distrust.co, Caution.co
* Church Of Cryptography Priest

#infosec #security #opensource #foss #sysadmin #cryptoanarchy #cypherpunk #embedded #puzzles #privacy #locksport #programming #linux #homelab

Relays (1)
  • wss://relay.ditto.pub – read & write

Recent Notes

Lance R. Vick profile picture
Veritasium just dropped a video on ethics of the FOSS movement, right to repair, digital sovereignty, and the idea that closed source software has absolutely no role in supply chain security.

In recent years my teammates and I have shifted our entire careers to FOSS supply chain security engineering in spite of constantly being told our work is a waste of time. We feel seen!

https://yewtu.be/watch?v=aoag03mSuXQ

Shameless plugs @ https://caution.co https://distrust.co and https://stagex.tools
❤️1
Morten Linderud · 9w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqedgeqhpw9d36qq3kwdw37t3ahxu73lp0ypvpavqmvcuvlt8shsjqjh7q3a Thanks!
Lance R. Vick profile picture
I should wait until this release is published next week, but I am too excited.

Stagex is the first production ready Linux distro to be:

- 100% deterministic
- 100% full source bootstrapped
- Maintainer signed on every commit and review
- Reproduced and signed by multiple maintainers on every artifact
- OCI container native
- LLVM/compiler-rt/libunwind native

https://codeberg.org/stagex/stagex/pulls/757

All the confs that turned us down and the people who said it could not be done can eat my entire ass.
Morten Linderud · 9w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqedgeqhpw9d36qq3kwdw37t3ahxu73lp0ypvpavqmvcuvlt8shsjqjh7q3a Slight note, a lot of the Reproducible Build patched in the distros like Debian and Arch Linux are from OpenSUSE and Bernard Wiedermann. Please also credit them :)
Lance R. Vick profile picture
If you claim to be building decentralized FOSS for censorship resistant finance, privacy, or communication and you collaborate via Zoom, Slack, Telegram, Twitter, Github, or Discord: you are full of shit.
Lance R. Vick profile picture
Anyone that says they are looking for a "Full Stack Engineer" has no idea that the "full stack" skills needed to make the next bullshit megacorp scale include physics, electronics, kernel debugging, CPU architecture, OS hardening, networking, scaling, databases, privacy, applied cryptography, etc, in addition to "frontend" and "backend".

Full stack engineers do not actually exist and you look amateur if you publish job descriptions requesting one.

Sorry to be the one to tell you.
note1fyvrk...
Lance R. Vick profile picture
@Blain Smith

Thanks! Good to know at least someone has done it for 0-10

For strictly the ability to communicate with parents when away from home, I suspect a handheld HAM radio or Meshtastic messenger is a possible option. Or just wifi messaging via a tablet that can only do that.

I don't have (or want) a smartphone or to have my family dependent on Google, Apple, or cellular carrier ecosystems, so alternative distance communication for kids away from home will be a need.
Lance R. Vick profile picture
Good news everyone. Cloudflare and GCP are down!

Everyone that told me self hosting my infrastructure was a waste of time can bite me.

Yes it was a lot of work. I earned this level of smugness.

100% of my shit is still online.
Lance R. Vick · 52w
I have audited or done security due diligence on a -lot- of fintech companies and the status quo should terrify most people. In fact, I challenge anyone to show me a single crypto-asset custodian tha...
Lance R. Vick profile picture
"But but MY favorite custodian has multiple people use multiple keys. They can't all be hacked at once!"

Yeah, they do that shit on macbooks controlled by JAMF that the IT team can control at any time. Also they do it with unsigned packages from Brew that any of 500+ internet randos can also change at any time without accountability.
Lance R. Vick profile picture
I have audited or done security due diligence on a -lot- of fintech companies and the status quo should terrify most people.

In fact, I challenge anyone to show me a single crypto-asset custodian that does not grant one, or even hundreds of people, the power to do irreversible transfers of tens of millions of dollars alone.

Seriously, show me just one.

These companies are an open buffet for state actors, or often even any mildly motivated teen skiddies.
1
Lance R. Vick · 52w
"But but MY favorite custodian has multiple people use multiple keys. They can't all be hacked at once!" Yeah, they do that shit on macbooks controlled by JAMF that the IT team can control at any time. Also they do it with unsigned packages from Brew that any of 500+ internet randos can also change...
Lance R. Vick profile picture
Saw a Tesla with an american flag license plate border and a plate that read "LYVFREE".

While I don't actually condone such actions, it was in that moment I truly understood where people get the urge to set a Tesla or two on fire.

Teslas have become the urban equivalent of big pickup trucks with truck nuts and flags flying off the back.