Viewing profile — colek42
colek42
HN member- Joined
- Wed, Oct 21, 2015, 2:22 AM UTC
- HN karma
- 485
- Public activity
- 203 items
- HN profile
- View on Hacker News ↗
About colek42
github.com/in-toto/witness github.com/in-toto/archivista
cole at testifysec.com
Recent public activity
-
comment
Comment #49127962
I really wish they would support SPIFFE/SPIRE
- comment
-
story
Show HN: CI/Lock – signed evidence of what your CI ran
I helped create Witness, donated it to the CNCF/in-toto ecosystem, and worked on the NIST 800-204D "pipeline observer" guidance. CI/Lock is the next version of that work, and it's …
- story
-
comment
Comment #48406449
In 2016 I was working for an organization that wanted a video streaming web app, but could not tolerate any latency. In the past, we solved this with an NAPI extension in Firefox. …
-
comment
Comment #48151998
There are ways to do it. Send me a message, and I can make an intro to the person we use.
-
comment
Comment #48054937
We built https://aflock.ai/ (open source) to help with this. Constraining activity tends to work well
-
comment
Comment #47608485
DSSE is great for this, if you need more schema use in-toto
-
comment
Comment #47433008
We started a "science project" taking concepts from Multi Level Security to constraining AI agents. https://aflock.ai/ . The idea is to have different data zones, and if an Agent a…
-
comment
Comment #47218953
We love Dapr's durabletask-go. https://pkg.go.dev/github.com/dapr/durabletask-go
-
comment
Comment #47207073
Where is your line, copy editing, drafting, reorganizing? You are going to have a busy, boring, and angry life if you want to comment on every post that has signs AI touched it.
-
comment
Comment #47201797
My job is to communicate quickly and clearly, AI helps me do my job faster and more efficiently. But thanks for telling me how I should do my job. You come off as both ignorant and…
-
comment
Comment #47198059
That is quite an ignorant statement to make. I spent three years in combat, and am permanently disabled from my service.
-
story
Anthropic vs. DoD: "Any lawful use" is a fight about control
I served 12 years infantry, then built targeting tools at JSOC vs ISIS. Now I lead a team building AI tools automating the compliance process. I’ve got opinions on Anthropic + DoD …
-
comment
Comment #47156849
Bingo, DoD does not want Anthropic to set guardrails on the technology it buys. If they don't want to abide they are free to deny service. We all know how that will turn our for th…
-
comment
Comment #47156055
The voters and congress tell the military how to use technology, not Anthropic. Shifting the decision to Anthropic takes away power from the citizenship. Edit: The point is, go vot…
-
comment
Comment #43932081
We just built a new version of the witness run action that tracks the who/what/when/where and why of the GitHub actions being used. It provides "Trusted Telemetry" in the form of S…
-
comment
Comment #43478659
When I saw the tj-actions attack, I decided it was time to finally implement action wrapping with our `witness-run-action`. This will generate signed attestations on exactly what t…
- story
- story
- story
-
comment
Comment #42112707
I've been thinking about this a lot. First, the author should replace security with compliance. Currently they are two different things. There is a huge divide between compliance t…
- story
- story
-
comment
Comment #38523868
We would love for you to talk about this at one of our in-toto community meetings. Let me know if you are interested. contact info is in the comments, or feel free to stop by #in-t…