this is a good moment to share two tools some may find useful right now:
* AirgapOS: a minimal (and audited) OS for offline secrets management used by several well known orgs in crypto you would all know: git.distrust.co/public/airgap
* Keyfork: tool for generating a BIP39 seed and sharding it - can also derive for different crypto algos (and supports dice and even tarot cards as a source of entropy). Comes packaged with AirgapOS, also audited: git.distrust.co/public/keyfork
Both of these tools are built using StageX (stagex.tools), which is a full source bootstrapped and deterministic distro.
For the truly paranoid, we also wrote an entire guide for offline key management: trove.distrust.co based on above tools with some opinionated steps.
anton
npub1h72r...k5rt
security engineer - working on privacy, security and freedom: https://caution.co, https://distrust.co, http://stagex.tools, http://git.distrust.co/public
having audited tons of high risk orgs, and being on calls with companies daily, i always find it shocking at the level of security maintained internally vs the level of security companies communicate externally. most companies still run their security programs in a negligent manner, and worse yet don’t actually care about security. the most important goal for them is to appear secure. expert security theatre, and this is part of what motivates me to bring new levels of transparency to how software systems are built
who here knows about TEEs. trying to see something
what’s new on nostr? heard some buzz about a nice new piece of software 🐝
Hiatus, shmiatus, back attitus.
It’s highly likely this has already happened and is being suppressed, but deepfakes will be used to circumvent account recovery mechanisms. Companies need to act now to implement stronger protection measures.
Aloha nostr, hope everyone is doing well.
gm nostr crew
Give AI agents access to everything. What could *possibly* go wrong?
I recently did a supply chain talk in Montreal at the InCyber conference and covered topics regarding bootstrapping compilers, deterministic builds, and stagex, a linux distribution which addresses a number of security risks current linux distributions do not.
Hmu if you are interested in any of these topics! Always looking for feedback, new collaborators and use-cases.

Anton Livaja
Expanding (Dis)Trust - talk about compiler safety, determinism and StageX
This talk which was held in Montreal at the InCyber conference taking place Oct 29-30 2024, covers topics regarding bootstrapping compilers, determ...
Spotted an exchange that offers bitcoin at the airport in Zagreb, Croatia 🤩 lfg 

The Dasharo developer pub is hosting a talk about our linux distribution which focuses on compiler safety, determinism and minimalism. (https://codeberg.org/stagex/stagex):
🔧 Simplify reproducible builds with Lance R. Vick from Distrust at Dasharo Developers vPub.
Discover [Stageˣ], a minimal Linux distro for zero-trust software supply chains:
- Provable reproduction for all artifacts
- Replace containerized pipelines
- Consistent builds across hardware
- Trust no one internally
🗓️ Date: Dec 12
🕙 Time: 22:00–22:10 (UTC)
🎟️ Register for free:
Learn more: 👉
Come hang out!

Attendize.com
Dasharo User Group #8
Dasharo User Group (DUG) #8 and Dasharo Developers vPub 0xD When? December 12th 2024 5PM UTC (plus 01:00 Warsaw Time)...

[Stageˣ] Linux distribution
A container-native, full-source bootstrapped, and reproducible toolchain to build all the things.
Dobro jutro
What’s the status of subkeys / revocations on nostr? Was the idea killed? Doesn’t feel right to not have a way to revoke a compromised key or the ability to use subkeys signed by a master key. I imagine the conversation happened somewhere, just not sure where… anyone have a link?
I was just doing some testing on mobile nostr clients and it seems some don’t delete the npriv when the app is deleted. Please fix this if your client has this issue. @primal is one example.