jkingdon2000.blogspot.com
Jim Kingdon on Programming: November 2013
http://jkingdon2000.blogspot.com/2013_11_01_archive.html
Jim Kingdon on Programming. Saturday, November 23, 2013. Securing package distribution with TUF. If you are a little bit familiar with this stuff, you are probably saying "signed packages", as found in for example Fedora. And that indeed is what I'm getting at, specifically TUF. The Update Framework). TUF aims to be usable by any package repository, but the most effort to date has been to using it for PyPI. As part of Square. TUF is fairly easy to work with. The public keys and signatures and such ar...
titanous.com
Docker Image Insecurity · Jonathan Rudenberg
https://titanous.com/posts/docker-insecurity
Is a cofounder of Flynn. And an architect of the Tent Protocol. December 23, 2014. Recently while downloading an official container image with Docker I saw this line:. Ubuntu:14.04: The image you are pulling has been verified. I assumed this referenced Docker’s heavily promoted. Images are downloaded from an HTTPS server and go through an insecure streaming processing pipeline in the Docker daemon:. Decompress] - [tarsum] - [unpack]. This pipeline is performant but completely insecure. Untrusted inpu...
raesene.github.io
Software Library Repositories and Security
https://raesene.github.io/blog/2015/03/01/software-library-repositories-and-security
Security Geek, Penetration Testing, Docker, Ruby, Hillwalking. Software Library Repositories and Security. March 1st, 2015. Last week I did a presentation for the Securi-Tay Conference. The title of the talk was Security and ‘modern’ software development , and the main theme of the talk was looking at library repositories like Rubygems. And how an attacker could try and place malicous content into those locations. Which lasted for a while before it was noted. Are trying to improve the situation, progress...
relaxdiego.com
Notes from CoreOS Fest 2015
http://www.relaxdiego.com/2015/05/coreosfest-notes.html
Notes from CoreOS Fest 2015. 07 May 2015 : 15 minute. I went to the first CoreOS Fest this week and the following photo, of which I am clearly the main subject, proves it! Source: https:/ twitter.com/bradfitz/status/595726778422931456. Now that that’s out of the way, here are my notes from that event. Container all the things! My favorite explanation of containers comes from a Reddit comment. Which I include below for your convenience. Go ahead, it’s a fun read. He’s standing near me and I don’t like it!
jkingdon2000.blogspot.com
Jim Kingdon on Programming: Securing package distribution with TUF
http://jkingdon2000.blogspot.com/2013/11/securing-package-distribution-with-tuf.html
Jim Kingdon on Programming. Saturday, November 23, 2013. Securing package distribution with TUF. If you are a little bit familiar with this stuff, you are probably saying "signed packages", as found in for example Fedora. And that indeed is what I'm getting at, specifically TUF. The Update Framework). TUF aims to be usable by any package repository, but the most effort to date has been to using it for PyPI. As part of Square. TUF is fairly easy to work with. The public keys and signatures and such ar...
SOCIAL ENGAGEMENT