Lance R. Vick

@lrvick
1.7K Followers
278 Following
1.1K Posts

FOSS || GTFO

* Security Engineer
* Cypherpunk
* Founder of #! (hashbang.sh), stagex.tools
* Co-founder of Distrust.co, Caution.co
* Church Of Cryptography Priest

#infosec #security #opensource #foss #sysadmin #cryptoanarchy #cypherpunk #embedded #puzzles #privacy #locksport #programming #linux #homelab

OpenPGPopenpgp4fpr:6B61ECD76088748C70590D55E90A401336C8AAA9
Matrix@lrvick:matrix.org
Resumehttps://lance.dev
Communityhttps://hashbang.sh

@nabeards Packages are just containerfiles so it is not hard to write them yourself in most cases: https://codeberg.org/stagex/stagex/src/branch/main/packages/core/curl/Containerfile

But file issues for things you want to see, or PRs if you get something building locally.

Need any help, drop into #stagex:matrix.org

stagex/packages/core/curl/Containerfile at main

stagex - A container-native, full-source bootstrapped, and reproducible toolchain to build all the things

Codeberg.org

Read more about our work on [Stageˣ] here: https://stagex.tools

All the pain of supply chain attacks is self inflicted. We actually can fix this.

Home | [Stageˣ]

A container-native, full-source bootstrapped, and reproducible toolchain to build all the things.

Security celebrities have been shitting on the PGP Web Of Trust as an idea we should abandon in favor of centralizing trust on corpos.

Meanwhile the internet is filling with AI bots using fake corpo accounts and no one can tell who is human anymore. Huh.

WoT has never mattered more, and it is time we anchor modern tooling back to the human roots that built the internet.

My fellow [Stageˣ] maintainer Kron, Zoë Finja Emilia makes a strong visual case.

https://kron.fi/en/posts/stagex-web-of-trust/

How do you trust a new Linux Distribution?

Who do you trust (… and how do you trust the new Linux Distribution StageX?) Do you trust your best friend from childhood? Do you trust your chosen Distribution for your Homelab? For your Workplace? Psychology says there are roughly two types of trust. Direct and Transitive trust. Direct trust is you trusting your best friend. Transitive trust is your best friend assuring you another person is also trustworthy and you listening to their word because you trust them.

Zoë's Blog

@arnoldnakamura I would agree with you, if Monero was built with stagex or something of equivalent controls to avoid trust in single parties within the distro.

Zcash sponsored us moving their wallet to be built with stagex, and hopefully soon their node. Sui has done the same.

A lot of us are big fans of Monero and would love to see it decentralize its supply chain trust as well.

As the founder of the Stagex Linux distribution and a California resident, my official position on operating system age verification mandates is that I personally will not implement it, and I doubt anyone else will.

Our decentralized and multi-party cryptographic signing design means no single person or entity has the power to make changes to the distribution alone.

But please, California lawmakers, try to make me. I would get off on making you look like idiots in court.

That is all.

@hko Imagine my pain having to buy 256G of ECC recently >.>
If anyone would like to tip me for my work, I accept DDR5 memory.

Veritasium just dropped a video on ethics of the FOSS movement, right to repair, digital sovereignty, and the idea that closed source software has absolutely no role in supply chain security.

In recent years my teammates and I have shifted our entire careers to FOSS supply chain security engineering in spite of constantly being told our work is a waste of time. We feel seen!

https://yewtu.be/watch?v=aoag03mSuXQ

Shameless plugs @ https://caution.co https://distrust.co and https://stagex.tools

I wonder if there were people that thought Stallman was a bad person for using a proprietary compiler to build the first version of GCC.

I exclusively write FOSS, but sometimes I don't understand the purity tests of the FOSS community.

As long as a PR author fully read the the code, and it was not largely copied from any other project, I don't care what kind of autocomplete magic was used.

FOSS is at too big of a disadvantage to be picky about useful contributions that respect the license.

@jab01701mid Also with that number of cores, a 110 load average is only like 26% utilization! lol.