HN user

Foxboron

3,717 karma

Arch Linux Developer, security team and reproducible builds.

https://linderud.dev/ https://github.com/Foxboron

[ my public key: https://keybase.io/fox; my proof: https://keybase.io/fox/sigs/LzugxUxnL-9sr_SJ8i6eMsmBZgyt9294JPRa2nnIl8o ]

Posts78
Comments505
View on HN
github.com 2mo ago

Show HN: SSH-TPM-agent · Release v0.9.0

Foxboron
6pts3
vinyl-cache.org 3mo ago

Vinyl Cache and Varnish Cache

Foxboron
54pts26
linderud.dev 4mo ago

Acme device attestation, smallstep and pkcs11: attezt

Foxboron
2pts0
linderud.dev 6mo ago

Personal Infrastructure Setup 2026

Foxboron
3pts0
linderud.dev 7mo ago

Self-hosting DNS for no fun, but a little profit

Foxboron
6pts0
www.nrk.no 1y ago

The Hunt for Darcula

Foxboron
5pts0
antiz.fr 1y ago

Arch Linux now has an official WSL image

Foxboron
5pts0
lwn.net 1y ago

A Report from the 2024 Image-Based Linux Summit

Foxboron
36pts3
linderud.dev 1y ago

SSH CA with device and identity attestation: SSH-tpm-ca-authority

Foxboron
2pts0
github.com 1y ago

Sbctl 0.15 – Secure Boot key manager

Foxboron
2pts0
stiankri.substack.com 2y ago

TPM Performance:(

Foxboron
5pts0
whynoipv6.com 2y ago

Why No IPv6?

Foxboron
66pts176
0pointer.net 2y ago

A re-introduction to mkosi – A Tool for Generating OS Images

Foxboron
2pts0
linderud.dev 2y ago

Stream to Chromecast with resolved, vlc and bash

Foxboron
82pts35
archlinux.org 2y ago

Arch Linux bugtracker migration to Gitlab completed

Foxboron
120pts71
github.com 2y ago

Show HN: sbctl – Secure Boot key manager

Foxboron
57pts3
linderud.dev 2y ago

Store SSH keys inside the TPM: SSH-tpm-agent

Foxboron
3pts0
github.com 2y ago

Show HN: ssh-tpm-agent – SSH agent for TPMs

Foxboron
86pts38
linderud.dev 3y ago

Store age identities inside the TPM: age-plugin-tpm

Foxboron
3pts0
mullvad.net 3y ago

The Mullvad Browser

Foxboron
1182pts419
dawidpotocki.com 3y ago

MSI's (in)Secure Boot

Foxboron
194pts149
monthly-reports.archlinux.page 3y ago

Arch Linux in November 2022

Foxboron
3pts0
linderud.dev 3y ago

Coredumpctl, delve and debug packages for Go

Foxboron
1pts0
lwn.net 3y ago

A Report from the 2022 Image-Based Linux Summit

Foxboron
1pts0
linderud.dev 3y ago

Pam Bypass: when null(is not)ok

Foxboron
3pts0
archlinux.org 4y ago

Debug Packages and Debuginfod

Foxboron
3pts0
systemd-by-example.com 4y ago

Systemd by Example

Foxboron
496pts69
github.com 4y ago

Show HN: Release 0.8 of sbctl, Secure Boot key manager

Foxboron
7pts0
www.qubes-os.org 4y ago

Reproducible builds for Debian: a big step forward

Foxboron
125pts55
linderud.dev 4y ago

Mkinitcpio v31 and UEFI Stubs

Foxboron
42pts12

Could be one or one thousand. Frankly, the exact number doesn't matter.

It does. Manually checking a couple of AUR packages is easy. Installing a thousand AUR packages is not something anyone should be doing.

I'm assuming people are using the AUR to install programs that are sufficiently complex and the idea one can trivially audit a complex program and all of its dependencies is foolish. The foolishness of that expectation scales with the number of complex programs installed.

Nobody is asking them to do that. The premise is that the `PKGBUILD` and auxillary files provided by the AUR should be checked.

The idea that users should "just check the source code every single time" has never been, nor will it ever be, a reasonable solution to supply chain attacks.

Again, nobody is asking anyone to do this.

Expecting users to manually review every single change, for every single AUR package they are using, every single time they do an update or installation is just unreasonable if you want to AUR to be useful at all for the general user.

How many AUR packages are you assuming people are installing?

The host key section makes me wonder about doing this with servers, but what are the security guarantees in places like the cloud with that? Are you relegated to a software TPM, and if so, what guarantees does a software TPM have?

For the cloud? You would probably have a software TPM so not super secure, but you would still prevent the keys from being extracted away from the server. And if you don't trust your hypervisor/cloud provider you probably have other issues?

In my head the security guarantees are more straightforward for physical servers where you have a fTPM or a dTPM.

My question after reading the README.md: what are the requirements from the OS? Can it be Windows, Linux, etc?

This only supports Linux.

This just reads like a LLM trying to come up with a conspiracy theory around systemd.

It somehow got hyper-fixated on "three" for no particular reason and seems like it decided to harpen down that fact without explaining anything around it?

Maintainers: You’re a primary maintainer or core team member of a public repo with 5,000+ GitHub stars or 1M+ monthly NPM downloads. You've made commits, releases, or PR reviews within the last 3 months.

Laughable.

This is a tiny, if even unimportant, fraction of the FOSS community that runs the modern tech stack.

The TPM has nothing remotely resembling per-user PCRs.

The system could extend one of the PCRs, or an NVPCR, with some unique user credential locked to the user directory. Then you can't recreate the PCR records in any immediate way.

But you can't just recreate a key under one of the hierarchies anyway. You still need to posses the keyfile.

Who exactly are you thinking of that needs a job but doesn't have one?

That is not your claim. Your claim is that they "are on the payroll of one of the big tech interests or a foundation funded by them". Which is simply not true.

You can easily find several maintainers of these projects doing this as their part-time hobby project, have cut a deal at work or simply don't work at place that funds Linux development.

I'm not going to call out individual I know the situation and/or their employment history.

Linux, clang, python, react, blink, v8, openssl... You know what I mean. I stand by what I said. Do you have a counterexample you think is clearly unfunded? They exist[1], but they're rare.

For Linux "all the major contributors and maintainers are on the payroll of one of the big tech interests or a foundation funded by them" is simply not true. It's trivial to prove this by just looking at the maintainers of the subsystems. Making this claim is nonsense to begin with.

Same is true for several major contributors to the Python compiler and subsequent libraries as well.

You will move the goalpost by trying to narrow down what "major contributor" means.

It's software subject to economic coercion owing to the lack of means of its maintainership. It's 100% fine for you to write and release software for free, but if a third party bets their own product on it they're subject to an attack where I hand you $7M to look the other way while I borrow your shell.

So without knowing anyone you are making a value judgement on the (probable?) lack of ethics? Excuse me?

but for almost any economically important project all the major contributors and maintainers are on the payroll of one of the big tech interests or a foundation funded by them.

"almost" is the load bearing word here, and/or a weasel word. Define what an "economically important project" is.

Also just to be clear: node is filled with povertyware and you should be extremely careful what you grab from npm.

Is "povertyware" what we call software written by people and released for free now?

What else could they do? The government represent the country. If their business model is not welcome there then they withdraw. It's very fair to say "if you insist on those rules I choose not to play".

They can just not threaten the population of Italy? They are a 2 billion dollar company that has apparently scheduled a meeting with the vice president of the US on short notice? This is going to be resolved politically.

Btw, I recently "threatened" Switzerland to withdraw my business from there because the cost of doing business there (complying with their VAT regulation) is higher than my revenue from there (maybe 1-2 licenses a year). The whole Switzerland will not be able to buy my software because of that. I didn't think of posting about it on Twitter though.

You have not given "free services" to 20% of the world wide web that you are now using as leverage.

They are a conglomerate and per Matthews words "an internet infrastructure provider". Why does the local revenue matter when they are serving a global market?

EDIT: And fwiw, "Why would you continue doing business in Italy?" is not what is being proposed. They are threatening to block 55 million people from ~20% of the world wide web.

So blocking Kiwifarms took.. months of activism and loud complaining. Heraled by Matthew as "this is an extraordinary decision for us to make and, given Cloudflare's role as an Internet infrastructure provider, a dangerous one that we are not comfortable with".

However a fine that amounts to ~0.7% of the annual revenue and they threaten to block an entire country?

The issue is that it also becomes easy to game. I've abused the fact that bots repost lobste.rs by timing my post submissions, I could have had this front-page post as I posted this to lobste.rs originally.

This makes the HN front-page less of an organic thing, and this is an implicit vote ring behavior few people have access to. It also makes people interested in lobste.rs for this behavior, which our community is not interested inn.

Fahrplan – 39C3 7 months ago

https://streaming.media.ccc.de/39c3

All talks will be live streamed, and right after the talk is done you have a rough cut available instantly under "re-live" you can watch until the final recording is available; https://streaming.media.ccc.de/39c3/relive

The final recording will appear under a day or two after the talk is held: https://media.ccc.de/c/39c3

EDIT: A different variant of the schedule with better filtering is available here: https://events.ccc.de/congress/2025/hub/en/schedule

I should note that some talks will not be recorded, and only available at the congress. These are clearly marked on the congress hub website, but not easily available on the fahrplan view.

See for example the many problems of NIST P-224/P-256/P-384 ECC curves

What are those problems exactly? The whitepaper from djb only makes vague claims about NSA being a malicious actor, but after ~20 years no known backdoors nor intentional weaknesses has been reliably proven?

This is why djb is in the Cypherpunks Hall of Fame! [1]

This is a list made by you 2 weeks ago?

EDIT: Okay lol. I actually browsed the list and found multiple dubious entries, along with Trump!

Hilarious list. 10/10.

Side note: What is that massive yellow CYBER sticker that seems to be on 80% of them? Feel like I’ve missed some kind of political movement.

I'm a little bit unsure about the origins of the sticker. But in the european hacker community the "CYBER" sticker is used for a bunch of things. Package tape, stickers and security lines.

There is one webshop selling them: https://cyber.equipment/