
maltfield
@maltfield@slrpnk.net
Founder of /c/eco_libre
- Comment on Replacement for Docker Content Trust (DCT) 14 hours ago:
You can pay for signed images from someone else
Can you tell me a bit more about this? Who are the major providers?
- Comment on Replacement for Docker Content Trust (DCT) 14 hours ago:
We do our pre-releases on CI runners for convenience. GitHub automatically kicks-off a build when we
git push.When it comes time to do a real release, we can just run the job locally on our build machines (this is easier thanks to docker). Because our builds are reproducible, we can just check that the hash matches on our local build and the one from the free GitHub CI runners. That way we don’t have to trust the infrastructure, but we can use it for free & easy iteration before our final release.
- Comment on Replacement for Docker Content Trust (DCT) 21 hours ago:
Yes, you have to trust someone.
My point is that cryptographic signatures can reduce that risk from having to trust tens of thousands of people to just one person.
That’s a hugely meaningful reduction of risk.
- Comment on Replacement for Docker Content Trust (DCT) 22 hours ago:
How could monitoring a firewall log protect you from a Publishing Infrastructure Compromise or MITM attack? It would just show the malicious image being downloaded from the expected source…
- Comment on Replacement for Docker Content Trust (DCT) 23 hours ago:
Because the hash comes from the same source as the image itself.
So if someone compromised the publishing infrastructure (or does a MITM attack), they can trivially maliciously modify the hash as easily as they can maliciously modify the image. It provides zero security to Publishing Infrastructure compromise.
A good historical example of this happening was when monero’s release infrastructure was comprimised once. And here’s a great list of historically relevant cases where this happened:
In the case of Monero, the users were able to verify that the cryptographic hash on the release was invalid, and it was fixed very fast. If the user can only check checksums, they have literally no way to detect if the publishing infrastructure or a MITM attack is taking place.
- Comment on Replacement for Docker Content Trust (DCT) 23 hours ago:
but how do you verify the sources of what you’re fetching?
Is it coming from an unsigned git repo? That seems equally vulnerable
- Comment on Replacement for Docker Content Trust (DCT) 23 hours ago:
Open-Source Software.
Can I install nix to run inside the free CI runners provided by GitHub, GitLab, and Codeberg?
- Submitted 1 day ago to selfhosted@lemmy.world | 18 comments