Johnny Gill

@swfiua
16 Followers
65 Following
45 Posts
Exploring Colin Rourke's The Geometry of the Universe. https://gotu.readthedocs.org
Join me and my "car" at the Rally & Ride for Road Safety, today at 5 pm at Queen's Park!
#BikeTO #ONpoli

@pleaseclap @BlauesLicht

I have said, and I've printed a sticker in case you don't hear me say it:

Defend Dangerous Computing

I don't know if I've ever said why.

VS Code + Github hold a monopoly on the software development process like hasn't been seen since before the days of GNU. (You can @ me about GNU later, that's not the point right now.) Developers have been lured to this end by very nice to use tools, that are "free." These tools are both owned by Microsoft who can integrate them together as tightly as anything. The average, I would guess, developer experience is completely tied up in VS Code and Github.

Many of us don't use either, we can get back to that point later.

Now that we're all settled in to the default MS workflow, let's introduce a couple more technologies that seem obvious for security: Trusted Computing, SBOM and Software Identification.

There is a movement to secure the open source supply chain. I'm intimately familiar, and have been working in that space for a few years now. There are others more involved and smarter than me, look them up. A large open source software ecosystem has a broad attack surface, and this is making some people nervous. With something greater than 80% of enterprise software comprising of open source components, there are those in the security community who are nervous about the potential for malicious code to be introduced somewhere within this vast, porous field. In order to answer to this threat, new elements of control are being explored. Most of these seem benign on their own.

Having a bill of materials for a piece of software is fine. Having a reasonable assurance that the software you are running is the software that you think you are running is fine. Signing packages, libraries, SBOMs and various attestations is also fine, probably even good.

VS Code and Github are already starting work to make providing signed SBOM and attestations seamless for developers. Additional work being proposed by CISA aims to make it easier to identify software packages, and Microsoft will no doubt provide free, robust tools to make this simple for developers as well. No doubt, these tools will integrate seamlessly between Code and Github with little to no effort. We have an open source code ecosystem we can trust.

Did somebody say Trust? Let's add Trusted Computing. Without getting way into implementation specifics, Trusted Computing (and it's ilk) are designed to ensure that only the software that the hardware manufacturer deems "safe" may be run. Combined with secure software identification, SBOMs and trusted certificates, Trusted Computing we have an impenetrable fortress within which approved software may be safely run. Right?

"Safe" is not necessarily determined by the user of the system, but by the manufacturer, by regulators, by law. With a hegemony in place to ensure that software is identified, signed and approved, and hardware will only run approved software, this is looking pretty sweet for the monopolists - all with the blessing of regulators to give real teeth to any punishment for violation. CFAA gets even more powerful, no?

By willingly leaning into the VS Code + Github monopoly, developers are cutting a clear path to domination in exchange for "free", convenient tooling. These same folks might say of Alphabet or Meta, "If you're not paying, you're the product." Why would this be any different for corporate development tools?

This story gets even spookier when you add browser monopoly, cloud monopoly, what have you. If you don't like the word "monopoly", try "monoculture" and see if that makes you feel any better.

So, I say fuck safe (I work in cybersecurity, the irony is not lost on me), give me Dangerous Computing. Give me keen tools that I control that, yes, I might be able to cut myself on. Give me weapons, or get out of my why while I build my own.

DEFEND DANGEROUS COMPUTING

Also doing a workshop on the Geometry of the Universe.
I am going to be speaking about the Milky Way as seen through Gaia data at PyCon Dublin.

Debunking the NRA's 9 favorite gun myths.

I tackle every single major propaganda claim and shut it down with facts. Including:
•Gun laws don't work because criminals don't obey laws
•Guns don't kill people, only people kill people
•Cars kill people, are we banning cars too?
•Women need guns for self defense
•It's a mental health crisis
•What about Chicago?

Read & share!
https://www.qasimrashid.com/p/debunking-the-nras-9-favorite-gun?r=fyvxf&utm_campaign=post&utm_medium=web&triedRedirect=true

Debunking the NRA's 9 Favorite Gun Myths

As four more innocent people are massacred in the 385th mass shooting of 2024, we are beyond the point of needing critical federal gun safety legislation

Let's Address This with Qasim Rashid

In France car parks with space for 80 cars or more are now required by law to be covered with solar panels.

- Parks between 80-400 spaces have 5 years to comply
- Parks with spaces of 400+ have 3 years to comply

This should be required everywhere!

#ClimateCrisis #Electrification

Turns out the Canadian government has been funneling support to a #Gaza neighborhood called Tel al-Sultan, including a big well and water distribution system called the “Canada Well”. Didn’t know that. Anyhow, Israeli troops planted explosives and blew it up. https://vancouver.citynews.ca/2024/08/15/canada-demands-investigation-water-well-destroyed-israeli-troops-gaza/
Canada demands investigation into water well destroyed by Israeli troops in Gaza

The Canadian government is still calling for an investigation into Israel's destruction nearly a month ago of a large water facility in an area of the Gaza Strip where Ottawa is known for supporting Palestinians.

CityNews Vancouver

It should be noted that what we are seeing with JWST is no surprise to those who believe in the Perfect Copernican Principle, that there are no special times or places, the universe has looked how it does now for a very long time.

https://phys.org/news/2024-08-jwst-imagery-earliest-galaxies-due.html

JWST imagery shows light from one of the earliest galaxies is due to continuing bursts from star formations

An international team of astronomers and astrophysicists studying data and imagery received from the James Webb Space Telescope (JWST) has found that light emitted from one of the earliest galaxies identified thus far, is due to continuing bursts from star formations.

Phys.org

This image comes to you thanks to ESA's Gaia, astropy and matplotlib.

A visualisation of The Milky Way's rotation curve.

Spyware turned this Kansas high school into a 'red zone' of dystopian surveillance • Kansas Reflector

What Gaggle is selling is an antidote for fear — for administrators, for parents, for students — in exchange for civil liberties, writes Max McCoy.

Kansas Reflector