anton's avatar
anton
npub1h72r...k5rt
security engineer - working on privacy, security and freedom: https://caution.co, https://distrust.co, http://stagex.tools, http://git.distrust.co/public
anton's avatar
anton 1 month ago
this is a good moment to share two tools some may find useful right now: * AirgapOS: a minimal (and audited) OS for offline secrets management used by several well known orgs in crypto you would all know: git.distrust.co/public/airgap * Keyfork: tool for generating a BIP39 seed and sharding it - can also derive for different crypto algos (and supports dice and even tarot cards as a source of entropy). Comes packaged with AirgapOS, also audited: git.distrust.co/public/keyfork Both of these tools are built using StageX (stagex.tools), which is a full source bootstrapped and deterministic distro. For the truly paranoid, we also wrote an entire guide for offline key management: trove.distrust.co based on above tools with some opinionated steps.
anton's avatar
anton 1 month ago
having audited tons of high risk orgs, and being on calls with companies daily, i always find it shocking at the level of security maintained internally vs the level of security companies communicate externally. most companies still run their security programs in a negligent manner, and worse yet don’t actually care about security. the most important goal for them is to appear secure. expert security theatre, and this is part of what motivates me to bring new levels of transparency to how software systems are built
anton's avatar
anton 1 month ago
who here knows about TEEs. trying to see something
anton's avatar
anton 1 month ago
what’s new on nostr? heard some buzz about a nice new piece of software 🐝
anton's avatar
anton 5 months ago
Hiatus, shmiatus, back attitus.
anton's avatar
anton 5 months ago
It’s highly likely this has already happened and is being suppressed, but deepfakes will be used to circumvent account recovery mechanisms. Companies need to act now to implement stronger protection measures.
anton's avatar
anton 9 months ago
Aloha nostr, hope everyone is doing well.
anton's avatar
anton 1 year ago
Give AI agents access to everything. What could *possibly* go wrong?
anton's avatar
anton 1 year ago
I recently did a supply chain talk in Montreal at the InCyber conference and covered topics regarding bootstrapping compilers, deterministic builds, and stagex, a linux distribution which addresses a number of security risks current linux distributions do not. Hmu if you are interested in any of these topics! Always looking for feedback, new collaborators and use-cases.
anton's avatar
anton 1 year ago
Spotted an exchange that offers bitcoin at the airport in Zagreb, Croatia 🤩 lfg image
anton's avatar
anton 1 year ago
The Dasharo developer pub is hosting a talk about our linux distribution which focuses on compiler safety, determinism and minimalism. (https://codeberg.org/stagex/stagex): 🔧 Simplify reproducible builds with Lance R. Vick from Distrust at Dasharo Developers vPub. Discover [Stageˣ], a minimal Linux distro for zero-trust software supply chains: - Provable reproduction for all artifacts - Replace containerized pipelines - Consistent builds across hardware - Trust no one internally 🗓️ Date: Dec 12 🕙 Time: 22:00–22:10 (UTC) 🎟️ Register for free: Learn more: 👉 Come hang out!
anton's avatar
anton 2 years ago
What’s the status of subkeys / revocations on nostr? Was the idea killed? Doesn’t feel right to not have a way to revoke a compromised key or the ability to use subkeys signed by a master key. I imagine the conversation happened somewhere, just not sure where… anyone have a link?
anton's avatar
anton 2 years ago
I was just doing some testing on mobile nostr clients and it seems some don’t delete the npriv when the app is deleted. Please fix this if your client has this issue. @primal is one example.