Live data from Hacker News

Viewing profile — colek42

colek42

HN member
Joined
Wed, Oct 21, 2015, 2:22 AM UTC
HN karma
485
Public activity
203 items

About colek42

Founder of TestifySec, and maintainer of Witness and Archivista

github.com/in-toto/witness github.com/in-toto/archivista

cole at testifysec.com

Recent public activity

  1. comment
    Comment #49127962

    I really wish they would support SPIFFE/SPIRE

  2. comment
  3. story
    Show HN: CI/Lock – signed evidence of what your CI ran

    I helped create Witness, donated it to the CNCF/in-toto ecosystem, and worked on the NIST 800-204D "pipeline observer" guidance. CI/Lock is the next version of that work, and it's …

  4. story
  5. comment
    Comment #48406449

    In 2016 I was working for an organization that wanted a video streaming web app, but could not tolerate any latency. In the past, we solved this with an NAPI extension in Firefox. …

  6. comment
    Comment #48151998

    There are ways to do it. Send me a message, and I can make an intro to the person we use.

  7. comment
    Comment #48054937

    We built https://aflock.ai/ (open source) to help with this. Constraining activity tends to work well

  8. comment
    Comment #47608485

    DSSE is great for this, if you need more schema use in-toto

  9. comment
    Comment #47433008

    We started a "science project" taking concepts from Multi Level Security to constraining AI agents. https://aflock.ai/ . The idea is to have different data zones, and if an Agent a…

  10. comment
    Comment #47218953

    We love Dapr's durabletask-go. https://pkg.go.dev/github.com/dapr/durabletask-go

  11. comment
    Comment #47207073

    Where is your line, copy editing, drafting, reorganizing? You are going to have a busy, boring, and angry life if you want to comment on every post that has signs AI touched it.

  12. comment
    Comment #47201797

    My job is to communicate quickly and clearly, AI helps me do my job faster and more efficiently. But thanks for telling me how I should do my job. You come off as both ignorant and…

  13. comment
    Comment #47198059

    That is quite an ignorant statement to make. I spent three years in combat, and am permanently disabled from my service.

  14. story
    Anthropic vs. DoD: "Any lawful use" is a fight about control

    I served 12 years infantry, then built targeting tools at JSOC vs ISIS. Now I lead a team building AI tools automating the compliance process. I’ve got opinions on Anthropic + DoD …

  15. comment
    Comment #47156849

    Bingo, DoD does not want Anthropic to set guardrails on the technology it buys. If they don't want to abide they are free to deny service. We all know how that will turn our for th…

  16. comment
    Comment #47156055

    The voters and congress tell the military how to use technology, not Anthropic. Shifting the decision to Anthropic takes away power from the citizenship. Edit: The point is, go vot…

  17. comment
    Comment #43932081

    We just built a new version of the witness run action that tracks the who/what/when/where and why of the GitHub actions being used. It provides "Trusted Telemetry" in the form of S…

  18. comment
    Comment #43478659

    When I saw the tj-actions attack, I decided it was time to finally implement action wrapping with our `witness-run-action`. This will generate signed attestations on exactly what t…

  19. story
  20. story
  21. story
  22. comment
    Comment #42112707

    I've been thinking about this a lot. First, the author should replace security with compliance. Currently they are two different things. There is a huge divide between compliance t…

  23. story
  24. story
  25. comment
    Comment #38523868

    We would love for you to talk about this at one of our in-toto community meetings. Let me know if you are interested. contact info is in the comments, or feel free to stop by #in-t…