Viewing profile — lrvick
lrvick
HN member- Joined
- Sat, Feb 19, 2011, 7:44 AM UTC
- HN karma
- 9,375
- Public activity
- 2,502 items
- HN profile
- View on Hacker News ↗
About lrvick
openpgp4fpr:6B61ECD76088748C70590D55E90A401336C8AAA9
Recent public activity
-
comment
Comment #49224214
Thats just all stuff one puts in a containerfile that generates their disk image. We can build any disk image nix can though with different syntax.
-
comment
Comment #49224203
https://git.distrust.co/public/airgap/src/branch/main/Contai... That containerfile defines an entire deterministic custom OS image, every package, and every configuration etc. Many…
-
comment
Comment #49224171
there are several distros built using stagex to get a disk image like airgapos. Just a containerfile a user writes at the last mile. But when my current "distros" branch lands idea…
-
comment
Comment #49219772
Both statements are valid for StageX
-
comment
Comment #49218782
You can define an immutable, deterministic, and bootable system image for anything from an enclave to a laptop with just the primitives provided by the OCI Containerfile standard. …
-
comment
Comment #49218504
https://stagex.tools
-
comment
Comment #49218497
Anyone looking for a full source bootstrapped, multi-party-signed, container native, and deterministic alternative to nix, check out https://stagex.tools https://codeberg.org/stage…
-
comment
Comment #49215322
Imagine an evil version of this person: https://en.wikipedia.org/wiki/Jo_Zayner
-
comment
Comment #49215236
I am finally able to deliver on years of backlog ideas thanks to the GPUs I racked up in my garage. Having a blast. Everyone I know fully dependent on corpotch seems pretty sad tho…
-
comment
Comment #49215065
So they will not be accepting most security patches. Fun.
-
comment
Comment #49206801
I say this as a fan of a lot of what Framework is doing. Lets not pretend we do not all -know- virtually every SaaS sucks ass at security because it slows down sales. Companies tha…
-
comment
Comment #49204370
I would note that we already have groups of hobbyists in the bay area using CRISPr kits to genetically alter frogs, dogs, and in some cases human DNA at home, and even making MNRNA…
-
comment
Comment #49202041
I am going to be PRing herdr to stagex as it is my daily driver. This will give it a totally independent release process with multiple parties bootstrapping, reproducing, and signi…
-
comment
Comment #49200565
It is not one angry person shutting down the internet or a massive supply chain attack that worries most as a security researcher. I have come to accept such things are way too eas…
-
comment
Comment #49143079
While we are building for a dramatically different threat model, we use quite a few of their llvm patches and are very thankful for their work, and alpine making llvm/musl a viable…
-
comment
Comment #49138318
We use musl+mimalloc by default for our entire production operating systems: https://stagex.tools
-
comment
Comment #49116967
Which is why automated signatures in release pipelines are usually meaningless. Authors must sign their code on their own hardware before it is published so we can tell when the si…
-
comment
Comment #49116947
If an author is not willing to do responsible release engineering they should lose their publishing ability and have their project marked as unmaintained. This would force people t…
-
comment
Comment #49115275
Refusing security patches and bug fixes because an engineer chose to use an auto-complete engine you do not like is categorically negligent. Might as well mandate everyone use a sp…
-
comment
Comment #49114322
Well, they should point users to a project responsible enough to accept huuman reviewed security and bug fixes that happen to have been written by an llm.
-
comment
Comment #49102300
I paid $8 for the recently expired email domain of the sole author of NPM package "foreach", so then control to ship any code I wanted to 70k companies was just a support ticket or…
-
comment
Comment #49102206
That is because Github is not a thing anymore. We are talking about Microsoft.
-
comment
Comment #49102187
It is fascinating how far people will go to do anything else at all other than having authors cryptographically sign their packages like every Linux package manager that matters si…
-
comment
Comment #49077866
It really sounds like you should seek out professional help if you have not alread. Everyone deserves to be happy, and in most cases that is possible with the willingness to pursue…
-
comment
Comment #49042795
> As much as I try to learn about that AI future I will need to return to, and try to prepare to return to work, there is no returning to who I was Changing the way I have worked f…