Live data from Hacker News

Viewing profile — adityasaky

adityasaky

HN member
Joined
Sun, Jun 18, 2017, 11:46 AM UTC
HN karma
70
Public activity
30 items

About adityasaky

Ph.D. Candidate at New York University | Software Supply Chain Security | Maintainer of in-toto and gittuf

Recent public activity

  1. story
  2. comment
    Comment #38012665

    Hey Will, thanks! The paper is from quite a few years ago now and the reference is for a subset of gittuf's threat model, specifically the metadata manipulation / reference state a…

  3. comment
    Comment #38012601

    As others have said, read access for refs / directories is a bit more complicated than just embedding a secret in the repository given how Git works. We have more exploring to do b…

  4. comment
    Comment #38012571

    At present, gittuf's access control policies are centered around _write_ permissions rather than _read_. That said, we want to re-use some of the same policy semantics to build _re…

  5. comment
    Comment #38012554

    > does it also filter/escape ANSI Sequences in messages and author names? Not at present! Do you have a link or so I could use to familiarize myself? I'm curious if and how it'd fa…

  6. comment
    Comment #38012507

    It's multi-pronged and I imagine adopters may use a subset of features. Broadly, I think folks are going to be interested in a) branch/tag/reference protection rules, b) file prote…

  7. comment
    Comment #38012469

    Yes! We have clean integration with other tools in the Git ecosystem on our roadmap.

  8. comment
    Comment #38007806

    Our alpha release is this week! We have pretty much everything in place for us to cut the tag and publish the first binaries. The next thing is to kick its tires a bit, we have som…

  9. comment
    Comment #38007662

    I’m one of the maintainers of gittuf, happy to answer questions!

  10. comment
    Comment #35290281

    You've also got to factor in all the software that relies on projects developed primarily on GitHub.

  11. comment
    Comment #34345112

    Strange, I hadn't come across that before. Not sure what they're trying to achieve, deny they ever had a leak?

  12. comment
    Comment #34326447

    Even then, you want to revoke those credentials rather than try to wipe it from history, no?

  13. comment
  14. comment
    Comment #32260625

    I haven't read the paper but if Wikipedia serves as a detection tool, I don't particularly see a problem using it. Perhaps the real problem is the non-Wikipedia, canonical systems …

  15. story
  16. comment
    Comment #30451053

    https://fiftytwo.in/story/madras-check/ Here’s an essay from last year that talks about him, his sister, and the culture of chess in Chennai.

  17. comment
    Comment #28221540

    How does that work when we're considering stationary first responders though?

  18. comment
    Comment #24629258

    Note: OpIndia is far from an unbiased source.

  19. comment
    Comment #24236521

    Unfortunately (this may have changed in recent times), they often don't update the public repos in line with their releases. They put them out all at once later. Also, last I check…

  20. story
  21. story
  22. story
  23. comment
    Comment #22873842

    As I understand it, federation enables two separate instances of some particular service to interact. They can still use single sign-on independently for their own authentication n…

  24. story
  25. story