Live data from Hacker News

Viewing profile — Foxboron

Foxboron

HN member
Joined
Mon, Sep 24, 2012, 2:03 PM UTC
HN karma
3,717
Public activity
592 items

About Foxboron

Arch Linux Developer, security team and reproducible builds.

https://linderud.dev/ https://github.com/Foxboron

[ my public key: https://keybase.io/fox; my proof: https://keybase.io/fox/sigs/LzugxUxnL-9sr_SJ8i6eMsmBZgyt9294JPRa2nnIl8o ]

Recent public activity

  1. comment
    Comment #48517622

    > Could be one or one thousand. Frankly, the exact number doesn't matter. It does. Manually checking a couple of AUR packages is easy. Installing a thousand AUR packages is not som…

  2. comment
    Comment #48506704

    > Expecting users to manually review every single change, for every single AUR package they are using, every single time they do an update or installation is just unreasonable if y…

  3. comment
    Comment #48013878

    > The host key section makes me wonder about doing this with servers, but what are the security guarantees in places like the cloud with that? Are you relegated to a software TPM, …

  4. story
  5. story
  6. comment
    Comment #47626967

    This just reads like a LLM trying to come up with a conspiracy theory around systemd. It somehow got hyper-fixated on "three" for no particular reason and seems like it decided to …

  7. story
  8. comment
    Comment #47268350

    `mkinitcpio` supports both. The `base` hook installs the shell PID 1, the `systemd` hook installs systemd as PID1. The default hook setup was changed with the latest'ish release to…

  9. comment
    Comment #47180883

    > Maintainers: You’re a primary maintainer or core team member of a public repo with 5,000+ GitHub stars or 1M+ monthly NPM downloads. You've made commits, releases, or PR reviews …

  10. comment
    Comment #47171608

    I have reported several spam emails to Github and from what I can tell none has been acted upon.

  11. comment
    Comment #47051946

    I mean, gitlab is only from ~2019. The first hit I could find of a git repository hosted on `archlinux.org` is from 2007; https://web.archive.org/web/20070512063341/http://projects…

  12. comment
    Comment #46862370

    Nor the 20 or so odd reimplementations of various filesystem drivers and LUKS encryption in the grub2 tree. But, who is counting?

  13. comment
    Comment #46787601

    > Sure, but can the system context-switch that PCR between two different users? Right, no it can't. But this was not really something the TPM was suppose to solve.

  14. comment
    Comment #46787219

    UEFI on x86_64 and phones are not comparable when it comes to being "locked down".

  15. comment
    Comment #46786471

    Phones don't implement UEFI.

  16. comment
    Comment #46786287

    > * Secure Boot (vendor-keyed deployments) I wish this myth would die at this point. Secure Boot allows you to enroll your own keys. This is part of the spec, and there are no ship…

  17. comment
    Comment #46711164

    > The TPM has nothing remotely resembling per-user PCRs. The system could extend one of the PCRs, or an NVPCR, with some unique user credential locked to the user directory. Then y…

  18. story
  19. comment
    Comment #46605382

    > Who exactly are you thinking of that needs a job but doesn't have one? That is not your claim. Your claim is that they "are on the payroll of one of the big tech interests or a f…

  20. comment
    Comment #46604901

    > Linux, clang, python, react, blink, v8, openssl... You know what I mean. I stand by what I said. Do you have a counterexample you think is clearly unfunded? They exist[1], but th…

  21. comment
    Comment #46603319

    > but for almost any economically important project all the major contributors and maintainers are on the payroll of one of the big tech interests or a foundation funded by them. "…

  22. comment
    Comment #46559107

    > What else could they do? The government represent the country. If their business model is not welcome there then they withdraw. It's very fair to say "if you insist on those rule…

  23. comment
    Comment #46558813

    And the correct response to that is to write up a threat towards the entire population of a country?

  24. comment
    Comment #46558600

    They are a conglomerate and per Matthews words "an internet infrastructure provider". Why does the local revenue matter when they are serving a global market? EDIT: And fwiw, "Why …

  25. comment
    Comment #46556362

    So blocking Kiwifarms took.. months of activism and loud complaining. Heraled by Matthew as "this is an extraordinary decision for us to make and, given Cloudflare's role as an Int…