101010.pl is one of the many independent Mastodon servers you can use to participate in the fediverse.
101010.pl czyli najstarszy polski serwer Mastodon. Posiadamy wpisy do 2048 znaków.

Server stats:

575
active users

#silverbullet

0 posts0 participants0 posts today

I was recently asked about whether signed commits would have prevented the #xz attack. The tl;dr is "no."

It's very important that the non #infosec community understands what a #digitalsignature does and doen't do. The notion that there's a #silverbullet for every technical, social, or trust problem is part of what makes #cybersecurity so hard to implement well.

#OpenPGP signatures rely on the system clock for setting the timestamp of a signature when signing the metadata and content of a commit. The author and committer dates can both legitimately differ from the timestamp of the signature for a number of reasons, or be made exactly the same rather trivially.

#Git history is a directed acyclic graph, not a cryptographic #blockchain, so a commit is just the delta between objects in the current treeish and the parent treeish in the graph. The signed metadata includes the current parent's SHA hash, but there's nothing stopping you from moving commits around and re-signing the new commits. If you couldn't do this, then you couldn't rebase, squash, do non-fast-forward merges, or cherry-pick.

This doesn't mean you can forge someone else's signature without access to their key material, but the attack wasn't the result of forged metadata or account impersonation. Signing wouldn't prevent commits by someone with commit access to the repository; it would just show that commits associated with Jia Tan were also signed by Jia Tan's private key. That provides no useful security control here. This was not a Git problem.

***POLL TIME*** - Do you make #notes / #tasks / #todos in electronic form? Do you like making #Lists? If so, HOW? #Trello? #OneNote? txt files in your #Dropbox? #Silverbullet? send yourself emails? TheBrain?

In particular WHY that particular method? need cross device/platform? 2 b available online? What (about this, or any method) are challenges to you? Do you struggle to organize your notes? What would you wish was better?

Y? am working on a thing that *may* help.

Boosts appreciated :)

#NowPlaying #FullAlbum If I remember correctly, I got this album by SIlver Bullet around the same time I got Hijack's The Horns of Jericho in the early 90s. Fun times... 😆

Silver Bullet - Bring Down The Walls No Limit Squad Returns, links to the album on songwhip here:
songwhip.com/silver-bullet/bri

SongwhipBring Down The Walls No Limit Squad Returns by Silver BulletListen to "Bring Down The Walls No Limit Squad Returns" by Silver Bullet on any music platform - Free smart music links by Songwhip