so many nice football kits completely ruined by the most horrendous sponsors imaginable
fifa collapsing the second it even looks in the direction of private equity is just... beautiful, a+ story writing, my compliments to the chef
next time they ask for donations, take a moment and wonder whether they are spending that money on a law firm that specializes in avoiding unionization 🙃 cwa-union.org/news/release...
Wiki Workers United US/CWA Will File for NLRB Election After Wikimedia Foundation Declines Voluntary Recognition
Wiki Workers United U.S. (WWU-US-CWA) has released a statement after announcing today that it will file for a union election with the NLRB after the Wikimedia Foundation declined the union's request f...
cwa-union.org
wild that this is the last game of the World Cup, definitely no more games after this
excited to talk about the (mostly) boring vulns we have, with a slight digression about how LLMs have completely turned the way vulns are found upside down 🙃
If Go is memory-safe, where do its vulnerabilities come from? 🔒 Go Security Team Lead @roland.zone shares how the Go team identifies, responds to, and learns from vulnerabilities across the Go ecosystem. Discover what those lessons mean for building more secure Go software. 🎟️ gophercon.com
If Go is memory-safe, where do its vulnerabilities come from? 🔒 Go Security Team Lead @roland.zone shares how the Go team identifies, responds to, and learns from vulnerabilities across the Go ecosystem. Discover what those lessons mean for building more secure Go software. 🎟️ gophercon.com
i'm sorry, i have zero interesting in consuming a "companion podcast", i'd like to watch your slop tv show, derive my own opinions, and then immediately forget everything about it 30 minutes later
did something very silly, may have some at gophercon this year if you ever sent us a vulnerability report or contributed to Go crypto (or are just nice to me) thanks to @ljamesart.bsky.social who did the great art!
genuine question: why are the HTTPS page load numbers so much lower on Linux? is it really just people doing local development, or is there some other weird thing causing this? transparencyreport.google.com/https/overview
Google Transparency Report
transparencyreport.google.com
excited to see RFC 8738 actually being used! letsencrypt.org/2026/01/15/6...
6-day and IP Address Certificates are Generally Available
Short-lived and IP address certificates are now generally available from Let’s Encrypt. These certificates are valid for 160 hours, just over six days. In order to get a short-lived certificate subscr...
letsencrypt.org
i have opinions about the ffmpeg security thing but i'm not going to post them, for my own sanity (but i am posting about not posting about it)
I did a talk at the UK GopherCon last month about what my team does, and I only let my laptop fall asleep twice! www.youtube.com/watch?v=oLtq...
Go Security – Past, Present, and Future - Roland Shoemaker
YouTube video by GopherCon UK
youtube.com
Hi folks, it’s survey time! We’d love to learn more about how you use Go and what could be improved. Share your feedback via our annual developer survey at google.qualtrics.com/jfe/form/SV_.... It should take 10 - 20 minutes to complete, and will be open through September 30. Thank you! #golang
Go Developer Survey 2025
Share your feedback about developing software with Go.
google.qualtrics.com
I recently passed my 5 year anniversary at Google on the Go team (thanks to them for reminding me), which also means it's been about 10 years since I first joined the Let's Encrypt team. It's been amazing to see the projects grow over those years, and I couldn't be prouder to have worked on them.
explaining post tour criteriums to non-cycling people makes you sound fully insane
a man in a suit and tie with his arms in the air and the words it 's happening
ALT: a man in a suit and tie with his arms in the air and the words it 's happening
media.tenor.com
We announced the new native Go FIPS 140-3 mode today! FIPS 140, like it or not, is often a requirement, and I was increasingly sad about large deployments replacing the Go crypto packages with non-memory safe cgo bindings. Go is now one of the easiest and most secure ways to build under FIPS 140.