Live data from Hacker News

Viewing profile — lrvick

lrvick

HN member
Joined
Sat, Feb 19, 2011, 7:44 AM UTC
HN karma
9,375
Public activity
2,502 items

About lrvick

https://distrust.co https://caution.co https://hashbang.sh https://lance.dev

openpgp4fpr:6B61ECD76088748C70590D55E90A401336C8AAA9

Recent public activity

  1. comment
    Comment #49224214

    Thats just all stuff one puts in a containerfile that generates their disk image. We can build any disk image nix can though with different syntax.

  2. comment
    Comment #49224203

    https://git.distrust.co/public/airgap/src/branch/main/Contai... That containerfile defines an entire deterministic custom OS image, every package, and every configuration etc. Many…

  3. comment
    Comment #49224171

    there are several distros built using stagex to get a disk image like airgapos. Just a containerfile a user writes at the last mile. But when my current "distros" branch lands idea…

  4. comment
    Comment #49219772

    Both statements are valid for StageX

  5. comment
    Comment #49218782

    You can define an immutable, deterministic, and bootable system image for anything from an enclave to a laptop with just the primitives provided by the OCI Containerfile standard. …

  6. comment
    Comment #49218504

    https://stagex.tools

  7. comment
    Comment #49218497

    Anyone looking for a full source bootstrapped, multi-party-signed, container native, and deterministic alternative to nix, check out https://stagex.tools https://codeberg.org/stage…

  8. comment
    Comment #49215322

    Imagine an evil version of this person: https://en.wikipedia.org/wiki/Jo_Zayner

  9. comment
    Comment #49215236

    I am finally able to deliver on years of backlog ideas thanks to the GPUs I racked up in my garage. Having a blast. Everyone I know fully dependent on corpotch seems pretty sad tho…

  10. comment
    Comment #49215065

    So they will not be accepting most security patches. Fun.

  11. comment
    Comment #49206801

    I say this as a fan of a lot of what Framework is doing. Lets not pretend we do not all -know- virtually every SaaS sucks ass at security because it slows down sales. Companies tha…

  12. comment
    Comment #49204370

    I would note that we already have groups of hobbyists in the bay area using CRISPr kits to genetically alter frogs, dogs, and in some cases human DNA at home, and even making MNRNA…

  13. comment
    Comment #49202041

    I am going to be PRing herdr to stagex as it is my daily driver. This will give it a totally independent release process with multiple parties bootstrapping, reproducing, and signi…

  14. comment
    Comment #49200565

    It is not one angry person shutting down the internet or a massive supply chain attack that worries most as a security researcher. I have come to accept such things are way too eas…

  15. comment
    Comment #49143079

    While we are building for a dramatically different threat model, we use quite a few of their llvm patches and are very thankful for their work, and alpine making llvm/musl a viable…

  16. comment
    Comment #49138318

    We use musl+mimalloc by default for our entire production operating systems: https://stagex.tools

  17. comment
    Comment #49116967

    Which is why automated signatures in release pipelines are usually meaningless. Authors must sign their code on their own hardware before it is published so we can tell when the si…

  18. comment
    Comment #49116947

    If an author is not willing to do responsible release engineering they should lose their publishing ability and have their project marked as unmaintained. This would force people t…

  19. comment
    Comment #49115275

    Refusing security patches and bug fixes because an engineer chose to use an auto-complete engine you do not like is categorically negligent. Might as well mandate everyone use a sp…

  20. comment
    Comment #49114322

    Well, they should point users to a project responsible enough to accept huuman reviewed security and bug fixes that happen to have been written by an llm.

  21. comment
    Comment #49102300

    I paid $8 for the recently expired email domain of the sole author of NPM package "foreach", so then control to ship any code I wanted to 70k companies was just a support ticket or…

  22. comment
    Comment #49102206

    That is because Github is not a thing anymore. We are talking about Microsoft.

  23. comment
    Comment #49102187

    It is fascinating how far people will go to do anything else at all other than having authors cryptographically sign their packages like every Linux package manager that matters si…

  24. comment
    Comment #49077866

    It really sounds like you should seek out professional help if you have not alread. Everyone deserves to be happy, and in most cases that is possible with the willingness to pursue…

  25. comment
    Comment #49042795

    > As much as I try to learn about that AI future I will need to return to, and try to prepare to return to work, there is no returning to who I was Changing the way I have worked f…