Remote
Taffer 🇨🇦
🎃👻
@Taffer@mastodon.gamedev.place
My job? Computer Sisyphus and Meme Historian. I work on cryptography, FIPS, and open source. I like video games, books, and riding my bike. I use Arch, btw.
I work for Chainguard, but I definitely don't speak for them.
Sometimes you just have to sit back, relax, and let the train wreck itself.
572 Followers
233 Following
50 Posts
Joined October 06, 2022
Website/Blog:
Worktree (git repo):
Skelly - retro CRPG:
Friends don't let friends use passkeys.
They're not portable between "security devices".
Say you're moving from @1password@1password.social to @bitwarden@fosstodon.org because 1Password supports fascists who want to ethnically cleanse Europe.
Passkeys don't migrate, and going through all of your passwords, then logging into each site to delete the passkey is painful.
A nice long random password, plus TOTP/OTP/"Authenticator" codes are best.
#1Password #Drop1Password #Bitwarden #passkey #totp
Open post
Replying to
@cR0w@infosec.exchange Clearly they’re cowards and would never do it. If only they were true alphas!
4
0
0
0
Open post
Replying to
@cR0w@infosec.exchange Our FIPS test lab sent us a survey to find out how we felt about using AI for FIPS certifications. Standards validation is a great spot for confabulation and leaving out details.
4
2
0
0
Open post
Replying to
@i0null@infosec.exchange Wtf, that’s the same band that did Deeper Shade of Soul?!? 🤘
3
1
0
0
Open post
Replying to
@endorama@hachyderm.io @ben@mastodon.bentasker.co.uk My company (Chainguard.dev) is hiring, and here’s a list of companies doing remote. Hope it helps! https://taffer.ca/posts/2025/remote/
4
0
2
0
Open post
Replying to
@cR0w@infosec.exchange If it worked for that, AWS, GCP, and Azure would be bug free, and never have a vulnerability. Instead take a look at how great GitHub is these days.
3
0
1
0
Open post
Replying to
@trinityblair@mastodon.social @catsalad@infosec.exchange 🤣 until I zoomed I thought this was a photo of your office
2
1
0
0
Open post
Replying to
@brahms@chaos.social @cR0w@infosec.exchange @nyanbinary@infosec.exchange Brute-forcing long chains of vulns into reports that mark them all High or Critical? At insane expense that’s still being underwritten by VC money.
2
1
1
0
Open post
Replying to
@Bwee@meow.social @eniko@mastodon.gamedev.place Here’s a list of companies doing remote, hope it helps! https://taffer.ca/posts/2025/remote/
6
0
2
0
Open post
Replying to
@acelaya@mastodon.social @kboyd@phpc.social Here’s a list of companies doing remote, hope it’s helpful! https://taffer.ca/posts/2025/remote/
2
1
0
0
Open post
Replying to
@accidentalciso@infosec.exchange Here’s a list of companies doing remote, hopefully it’s helpful- https://taffer.ca/posts/2025/remote/
5
0
3
0
Open post
Open post
Replying to
@Amy@iosdev.space @kboyd@phpc.social Dunno if it’s helpful, but here’s a collection of companies doing remote: https://taffer.ca/posts/2025/remote/#the-top
1
0
0
0
Open post
Replying to
@FritzAdalis@infosec.exchange @cR0w@infosec.exchange @en3py@onlyarts.social I can’t use Thunderbird (or any IMAP client) for email at work because Security hasn’t done an eval. But we can enable every MCP in sight.
4
2
0
0
Open post
Replying to
@drwho@masto.hackers.town @catsalad@infosec.exchange Can’t remember if I’ve already sent this before, but here’s a list of companies doing remote: https://taffer.ca/posts/2025/remote/ Chainguard.dev is definitely hiring right now.
3
1
0
0
Open post
Replying to
@cR0w@infosec.exchange I assume harvest now, decrypt later is less plausible now that “AI” has absorbed 120% of the world’s hard drives…
1
1
0
0
Open post
Replying to
@FritzAdalis@infosec.exchange @cR0w@infosec.exchange @en3py@onlyarts.social I love it, that’s terrible
3
0
0
0
Open post
Replying to
@da_667@infosec.exchange @cR0w@infosec.exchange I know my company is hiring (Chainguard.dev, but ask about “AI” if you talk to them, or contact me) and here’s a hopefully helpful list of companies doing remote: https://taffer.ca/posts/2025/remote/
1
0
0
0
Open post
Replying to
@0xabad1dea They’re doing three, huge, stupid things at once: using Copilot for everything (MS said to), switching to host on Azure (MS again), and rewriting everything using React (top down edict, don’t know the source). It’s so ridiculously slow and unreliable now.
3
0
0
0
Open post
Replying to
@bagder@mastodon.social I voted for OpenSSL. When BlackBerry 10 devices shipped they had three different versions of OpenSSL in them (all with different vulnerabilities of course).
2
0
0
0
Open post
Replying to
@gimulnautti@mastodon.green @jwz@mastodon.social Is it still a mostly Mozilla project? Because they’ve gone AI brained.
2
2
0
0
Open post
Replying to
@kevingibson@mastodon.gamedev.place @aeva@mastodon.gamedev.place Welcome back! Here’s a list of companies doing remote, I hope it’s helpful! https://taffer.ca/posts/2025/remote/
2
0
0
0
Open post
Replying to
@LoganFive@beige.party @catsalad@infosec.exchange Late 80s guidance councillor told me to go into journalism.
1
0
0
0
Open post
Open post
Replying to
@rootwyrm @cR0w Here’s a list of companies doing remote, no idea which have fallen to slop though, sorry: https://taffer.ca/posts/2025/remote/
1
0
0
0
Open post
Replying to
@gavi@bagel.ing Actually, just searching Fedi for catte had more better results!
1
0
0
0
Open post
Replying to
@AeonCypher@lgbtqia.space @alice@lgbtqia.space Dunno if this is helpful, but it’s a big list of companies doing remote: https://taffer.ca/posts/2025/remote/ My company (Chainguard.dev) is hiring.
0
0
1
0
Open post
Replying to
@yaah @glassbottommeg Here’s a list of companies doing remote, hope it’s helpful! https://taffer.ca/posts/2025/remote/
0
0
0
0
Open post
Replying to
@ireneista @aeva Here’s a list of companies doing remote, hope it’s helpful! https://taffer.ca/posts/2025/remote/
0
2
0
0
Open post
Replying to
@jwcph@helvede.net @eniko@mastodon.gamedev.place Anyone who’s played D&D knows that 10% chance of failure happens MUCH more often that you’d like.
0
0
0
0
Open post
Replying to
@nixCraft@mastodon.social I use Linux because it’s the least awful option. I’ve also switched distros every year or so since switching: Mint, Kubuntu, OpenSUSE, now EndeavourOS (and Fedora at work).
0
0
0
0
Open post
Replying to
0
1
0
0
Open post
Replying to
@NanoRaptor@bitbang.social Current contribution might be the remote job list, it’s been shared by at least two people other than me: https://taffer.ca/posts/2025/remote/
0
0
0
0
Open post
Replying to
0
0
0
0
Open post
Replying to
@Viss@mastodon.social @cR0w@infosec.exchange @catsalad@infosec.exchange It’s like if an LLM could extrude “food” slop.
0
0
0
0
Open post
Replying to
@cR0w@infosec.exchange @catsalad@infosec.exchange LastPass seems pretty bad at security …
0
1
0
0
Open post
Replying to
@tacitus@mastodon.gamedev.place @aeva@mastodon.gamedev.place “SGML is too corporate! We need to take it to the XTREME!”
0
0
0
0
Open post
Replying to on phpc.social
@kboyd@phpc.social Looks like @worktree@mastodon.social is adding some cloud options, hopefully in the near future to take advantage of this nonsense.
0
1
0
0
Open post
Replying to
@TechieNotNetie@social.vivaldi.net @Vivaldi@social.vivaldi.net @cloudflare@noc.social How about Clownflare fixes their crap “verification”? This week it’s Vivaldi, next week it’s Firefox, repeat forever. WTF are they even “verifying”?
0
1
0
0
Open post
Replying to
@thezoq2@mastodon.social @eniko@mastodon.gamedev.place Here’s a list of companies doing remote, hope it’s helpful! https://taffer.ca/posts/2025/remote/
0
0
0
0
Open post
I'm glad @Waterfox@mastodon.social Private Search has tweaked their UI to show more results, this makes it much more worthwhile and useful!
Now if they could just stop emailing me a code when I have to log in (which seems very frequent). At least give me the option to use TOTP instead!
#waterfox #WaterfoxPrivateSearch #search #totp #security #authentication
0
0
1
0
