

G-GE-GET-GET F-GET FU-GET FUC-GET FUCK-GET FUCKE-GET FUCKED-ET FUCKED-T FUCKED-UCKED-CKED-KED-ED-D


G-GE-GET-GET F-GET FU-GET FUC-GET FUCK-GET FUCKE-GET FUCKED-ET FUCKED-T FUCKED-UCKED-CKED-KED-ED-D


I was curious and, yeah, it seems like docker hub not requiring signature means many popular publishers don’t bother to sign. But that’s not to say it can’t be done. For example: https://github.com/sigstore/cosign
Today,
cosignhas been tested and works against […] Docker Hub


Again we’re talking past each other. I’m sure those results are available and I’m aware docker doesn’t verify signatures automatically, but I’m asking how that necessarily makes docker insecure in spite of best practices being implemented. It’s about pinning yourself to trusted digests and having a verification process (like time) before updates. Why would you need authorship verification in that case? If there’s a good answer to that, I’d consider alternatives too. I’m just saying I don’t think it’s inherently insecure over this, and at face value It boils back down to the classic: don’t download untrusted software.


You’re making big claims on security here, like “cannot be done,” and each time you do I feel like we’re talking past each other a bit. I never claimed you can verify that the person who pushed the container had access to a private key file. I claimed you can verify the security of a container, specifically by auditing it and reviewing the publisher’s online presence. Best practices. Don’t upgrade right away, and pin digests to those which can be trusted.
When you pin a digest, you’re not going to get a container some malicious agent force pushed after the fact. You pinned the download to an immutable digest, so hot-swapping the container is out the window. What, as I understand, you’re concerned with is the scenario that a malicious actor (1) compromised the registry login beforehand, (2) you pinned the digest after hand, and (3) the attack is unnoticed by you and everyone else.
I’m trying to figure out under what conditions this would actually occur, and thus justifies the claim that docker pull is insecure. In a work setting, I only see this being an issue if the process to test/upgrade existing ones is already an insecure process. Can you help me understand why I should believe that, even with best practices in place, Dockers own insecurities are unacceptable? Docker is used everywhere and I’m reluctant to believe everyone just doesn’t care about an unmanageable attack vector.


You’re talking about authorship. Sure. But if you verify the container yourself as secure and pin the digest, what’s the issue?


What are you talking about, “yeah that’s the insecurity I’m talking about.”
I didn’t mention an insecurity and neither have you. Would you mind being a little more clear than “Docker pull is insecure?”
Frankly, I was expressing confidence in dockers security. It goes without saying though, any user can do insecure things like download from untrusted sources. That’s not dockers problem though, it’s the users.
Edit: I see now that you added “it’s the download that’s not verified.” Integrity is verified, so I assume you mean authorship (via signing)? I guess you’re saying that, if admin credentials are stolen from a container publisher and the thief force pushes malicious code into the registry under a pre-existing tag—then you would be exposed to that?
Even in that case, though, a digest cannot be overwritten. Tags can. So you’d just pin the digest to avoid this one attack vector?


You can verify the checksum to ensure the contents pulled are exactly the same as what was published. You can also use a private container registry.
How exactly would docker pull be any more insecure than something like pip install? Or, really anything… Let’s go with your preferred alternative, how are you going to get it on your machine in a more secure way than docker provides?
Docker uses TLS with registries, layers and manifests have cryptographic digests, checksums, and you can verify the publisher yourself. Push it into your own registry if you want, or just don’t use latest.


Docker is a security risk? … excuse me, what? Can’t you just, idunno, secure the environment that docker runs in? Use rootless images? Use immutable images?
And, are you asking for something that runs on bare metal? Couldn’t you just install the ISO that the dockerfile uses, then convert the dockerfile logic to an sh script?


Nothing is a special about the Cheeto Man. He is not a means to some end, as though his specialty is bringing about some change which nobody else could have. Cheeto Man is an end in himself. He’s the result of where we have been headed for a long time. Circumstances were right for a man like Cheeto Man, and now here he is. It’s like when the weather man tells you circumstances are just right for rain — that means it’s probably going to rain.


The unfortunate reality is that MAGA is only turning on Trump in the slightest possible manner because they see his potential fumble. It’s acknowledging writing on the wall, it’s not a push against their king.
They’re not attracted to winning, in the sense that they may come to reason and stand for what’s right… no. They’re just adverse to loosing, in the sense that they cling to whichever side seems more powerful to them.
Trump is just one bandaged ear away from having his tea-sac in their throats again.


Exactly. I wouldn’t put it past them to regard the scrubbing as an “ongoing federal investigation” — which the article clearly mentions can still be redacted.


There’s an obligation not to believe it. If the Grinch fucks up your Christmas 10 years in a row, then tells you he’s ready to turn a new leaf, you don’t respond by telling him where you put the tree this year. You instead wonder if this is the newest trick up his sleeve, trickery. When he later does a good deed, you now wonder if he’s playing the long con here. When fellows start to advocate for the Grinch having changed, you wonder if your fellows are either naïve or in on the trick. I don’t know at what point the Grinch deserves trust, but it’s probably proportional in some way to the amount of trust they proved themselves not to deserve.
Also, if you later discover that the Grinch turned a new leaf only after discovering that the police seized his computer, found support for a pedophile in chief, and plans to make it public… then you wonder if the whole thing is just Grinch trying to survive the blowout. Grinch has been very bad.


And why the fuck would companies get the refund? The costs of their import fees were passed onto consumers. Another fucking payday for the slime fucks while the actual population of human beings suffers?


If Trump and Epstein’s relationship were the 2015/16 October surprise, could have worked. Like the emails, the photos, the rumors of Trump’s coordination via his beauty pageants, … all of that.
I think part of the problem is that the damning evidence comes right after slightly less damning evidence in every case. It’s like walking his follows up a steady staircase until they’re all full on fascist and can no longer recognize themselves (nor care to).


People will get the deltas shipped in from global shops or try making it themselves with dangerous chemicals that need be properly removed afterward, don’t worry. The price between delta 8 and delta 9 is just too wide that a country built on market capitalism and class-based disenfranchisement won’t be able to resist. You’ll have a less safe blackmarket soon enough, but the good news is that drug dealers don’t check ID so it’s technically more accessible to kids now too. /s


We should all be considering just how successful his operation was, as well. It’s not like Epstein was a small figure head. Epstein effectively trafficked girls and networked them to high ranking public officials for decades. That ought be concerning for us all, knowing that our society was so vulnerable. Epstein built his pedophile pedestal in a way that reinforced the system’s security as it grew. It was so effective, in fact, that even in death his secrets remain mostly secret. That’s a failure on our part; we were vulnerable as a society and he capitalized on that vulnerability.


I think that’s largely true, but aren’t you skipping the idea of a chapter 13 (is it?). I thought there was a major difference between chapter 7 and 13, being that you aren’t required to pay anything back. You may still have to forfeit some assets, but you can also keep assets like a car so long as you can prove you’re making payments and you need it. Also consider, the people who can’t afford insurance and would thus take this option probably don’t have much in the first place. I’m not a lawyer though, what are your thoughts?


deleted by creator


But, isn’t there an alternative? You just go, accept the debt, and eventually file bankruptcy.
Sounds fucked up, but at the same time… what’s the number one reason for bankruptcy in the US? We’d just be doing so on our terms by that point.
These might be apples and oranges, but how does NextCloud compare to Seafile?