voboda

@voboda.com

I learn about all kinds of cryptography, and try to use it to make the world a little better. You can see a few explorations at voboda.com

With #localfirst apps and SPAs, DNS hijacks are fatal. All end-user data, even encrypted, is revealed. Anyone else considered this? I'm doing some research, and designing some prototypes.

You use a bare Git repo with a `post-receive` shell script hook. I use GitHub Actions: remote YAML, swiss-cheese key management, OIDC trust glue, job orchestration, delimiter-delimited metadata, opaque internal headers, microservice spaghetti, bug bounties, and CVEs to match. We are not the same.

Filippo Valsorda@filippo.abyssdomain.expert · 3mo ago

… are fucking kidding me. A github.com cross-account RCE due to the most pedestrian of injection attacks along the obvious exposed surface… and they actually have a globally shared “git” UNIX user!! This is not what taking the role of supply chain stewards seriously looks like.

It struck me that pet names could actually work with the Reticulum network stack more than with IP, because you actually take your Reticulum address with you when you move in the network. You can't do that with IP addresses, hence the need for DNS.

If I had to identify a list of skills in high impact engineers, it would include: - ecological awe - intellectual humility - respect for the complexity of unfamiliar problems - cross functional communication - resilience engineering - marketing and sales (“Technical skills” aren’t in my top ten)

"Crypto was a community that had been building for almost a decade. Economic design was what they did. And nobody had addressed the economic design problem that made their conference weeks full of over-hyped but mostly empty events?" Here is my attempt. blog.voboda.com/density-index/

The Density Index

My first Ethereum conference was 20,000 people. The Amsterdam tourist district was a drunken, crypto merch explosion. I wondered how many were setting themse...

blog.voboda.com

Given today's LiteLLM supply chain attack, what are people's preferred development environment sandboxes on MacOS these days? I think it's time I started running my development environments somewhere where rogue code can't steal all my ~/... credential files

We cannot let them get away with this. And the solution is not to chop of a head of this hydra and call it a day - but to fundamentally change how we do things.

I'm glad this is coming to the forefront. I was deeply inspired by Nikolai Mushgian's attitude to this ( see nikolai.fyi and look at dmap, dpack and minicash's doc ) I even made a little game about this philosophy for Devcon SEA: immutalists.infinite.build

github.com

ligi@ligi.de · 8mo ago

Just called pledge on trustlessness.eth.limo A bit late as it came out in a very busy time of my life due to @devcon.org - but now finally found some time finally process the manifesto and sign. Signed it as ligi.ethereum.eth Thanks to Marissa Posner, Yoav Weiss, @vitalik.ca for the initiative!