Lance R. Vick

@lrvick
1.7K Followers
279 Following
1.1K Posts

FOSS || GTFO

* Security Engineer
* Cypherpunk
* Founder of #! (hashbang.sh), stagex.tools
* Co-founder of Distrust.co, Caution.co
* Church Of Cryptography Priest

#infosec #security #opensource #foss #sysadmin #cryptoanarchy #cypherpunk #embedded #puzzles #privacy #locksport #programming #linux #homelab

OpenPGPopenpgp4fpr:6B61ECD76088748C70590D55E90A401336C8AAA9
Matrix@lrvick:matrix.org
Resumehttps://lance.dev
Communityhttps://hashbang.sh

Anthropic just legally threatened Opencode to make them drop support: https://web.archive.org/web/20260221041617/https://github.com/anomalyco/opencode-anthropic-auth/pull/15#issuecomment-3930558874

Archive link because they deleted the repo after to comply with demands.

In short, Anthropic only wants you using their official walled-garden clients to access the models trained on our open source code.

They are not a lesser evil. They are just as evil as OpenAI.

Stop giving these assholes money. Rent or buy hardware to self-host with privacy and freedom. It is not that hard, I promise.

fix: Align Anthropic OAuth requests with Claude Code by deveworld · Pull Request #15 · anomalyco/opencode-anthropic-auth

Summary Normalize Anthropic OAuth requests to match Claude Code's headers, betas, metadata, tool casing, and model IDs. Remove tool_choice and inject metadata.user_id from ~/.claude.json to sa...

GitHub

AI automated security review company that views human code review as unnecessary, gets hit by supply chain attack that their automation failed to detect. Beautiful.

How many more of these are required before we can seriously talk about Web of Trust, commit signing, and decentralized crowd-sourced FOSS code review?

https://www.sysdig.com/blog/teampcp-expands-supply-chain-compromise-spreads-from-trivy-to-checkmarx-github-actions

TeamPCP expands: Supply chain compromise spreads from Trivy to Checkmarx GitHub Actions | Sysdig

The Sysdig Threat Reseaarch Team (TRT) reveals how TeamPCP’s supply chain attack spread from Trivy to Checkmarx, reusing stolen CI/CD credentials to compromise GitHub Actions and evade traditional detection.

Read more about our work on [Stageˣ] here: https://stagex.tools

All the pain of supply chain attacks is self inflicted. We actually can fix this.

Home | [Stageˣ]

A container-native, full-source bootstrapped, and reproducible toolchain to build all the things.

Security celebrities have been shitting on the PGP Web Of Trust as an idea we should abandon in favor of centralizing trust on corpos.

Meanwhile the internet is filling with AI bots using fake corpo accounts and no one can tell who is human anymore. Huh.

WoT has never mattered more, and it is time we anchor modern tooling back to the human roots that built the internet.

My fellow [Stageˣ] maintainer Kron, Zoë Finja Emilia makes a strong visual case.

https://kron.fi/en/posts/stagex-web-of-trust/

How do you trust a new Linux Distribution?

Who do you trust (… and how do you trust the new Linux Distribution StageX?) Do you trust your best friend from childhood? Do you trust your chosen Distribution for your Homelab? For your Workplace? Psychology says there are roughly two types of trust. Direct and Transitive trust. Direct trust is you trusting your best friend. Transitive trust is your best friend assuring you another person is also trustworthy and you listening to their word because you trust them.

Zoë's Blog

As the founder of the Stagex Linux distribution and a California resident, my official position on operating system age verification mandates is that I personally will not implement it, and I doubt anyone else will.

Our decentralized and multi-party cryptographic signing design means no single person or entity has the power to make changes to the distribution alone.

But please, California lawmakers, try to make me. I would get off on making you look like idiots in court.

That is all.

If anyone would like to tip me for my work, I accept DDR5 memory.

Veritasium just dropped a video on ethics of the FOSS movement, right to repair, digital sovereignty, and the idea that closed source software has absolutely no role in supply chain security.

In recent years my teammates and I have shifted our entire careers to FOSS supply chain security engineering in spite of constantly being told our work is a waste of time. We feel seen!

https://yewtu.be/watch?v=aoag03mSuXQ

Shameless plugs @ https://caution.co https://distrust.co and https://stagex.tools

I wonder if there were people that thought Stallman was a bad person for using a proprietary compiler to build the first version of GCC.

I exclusively write FOSS, but sometimes I don't understand the purity tests of the FOSS community.

As long as a PR author fully read the the code, and it was not largely copied from any other project, I don't care what kind of autocomplete magic was used.

FOSS is at too big of a disadvantage to be picky about useful contributions that respect the license.

When you work on OS development, you spend a -lot- of time waiting on compiling experiments. Wasted time.

So, finally broke down on a big workstation upgrade:

So I trained an LLM on myself, and it sounded like a complete idiot so I deleted it immediately.

I am starting to consider that it might be a me problem.