mayakacz | 2 years ago | on: Tailscale Funnel now available in beta
mayakacz's comments
mayakacz | 3 years ago | on: CVE-2022-41924 – tailscaled can be used to remotely execute code on Windows
The Windows client caches the current version for a while, so may not yet have v1.32.3 available on your device. In that case, you can still pull the latest release from http://pkgs.tailscale.com/stable.
mayakacz | 6 years ago | on: Binary Authorization for Borg
You can more easily compare Grafeas and Kritis (OSS projects Google developed, which are similar to GCR Vulnerability Scanning and Binary Authorization for GKE), to in-toto. In fact, I gave a talk covering some of the options for this here: https://youtu.be/uDWXKKEO8NU?t=1314
Disclosure: I work at Google and helped write this whitepaper on Binary Authorization for Borg.
mayakacz | 6 years ago | on: Binary Authorization for Borg
In terms of the upstream introduction of a new vulnerability, Binary Authorization for Borg can only verify that the code was in fact merged. See the section on third party code, "When importing changes from third party or open source code, we verify that the change is appropriate (for example, the latest version)."
Disclosure: I work at Google and helped write this whitepaper on Binary Authorization for Borg.
mayakacz | 6 years ago | on: Binary Authorization for Borg
Binary Authorization for Borg performs verification for pieces that come out of Google's CI/CD pipeline. For third party code, see in the doc, "When importing changes from third party or open source code, we verify that the change is appropriate (for example, the latest version)."
Disclosure: I work at Google and helped write this whitepaper on Binary Authorization for Borg.
mayakacz | 6 years ago | on: Binary Authorization for Borg
Disclosure: I work at Google and helped write this whitepaper on Binary Authorization for Borg.
mayakacz | 6 years ago | on: Binary Authorization for Borg
Disclosure: I work at Google and helped write this whitepaper on Binary Authorization for Borg.
mayakacz | 8 years ago | on: Ask HN: Who hires mathematicians?
mayakacz | 9 years ago | on: Ask HN: Sites that you visit daily?
Feedly (fresh articles): Ars Risk Assessment, Bloomberg, The Atlantic Business, various friends' and food blogs
Pocket (older articles)
If I have more time: HN, r/crypto, sometimes Medium
To waste time: Sporcle, Instagram, Foodgawker
mayakacz | 10 years ago | on: Things to Know about Databases that Leverage Partially Homomorphic Encryption
Happy to answer any questions or chat about cool uses of PHE!
mayakacz | 10 years ago | on: A 1920s millionaire set off a race to have the most babies