Remote
Raito Bezarius
@raito@nixos.paris
#Lix developer, #NixOS developer, #Lean theorem prover user.
My interests revolve around formal verification, evolutions of the Nix model, firmware platform security, public policies and (geo)politics.
Alternatively, I enjoy Japanese animation and culture.
My DMs are open for anything and everything.
1121 Followers
857 Following
40 Posts
Joined October 29, 2022
Twitter:
GitHub:
Website FR:
Open post
Replying to
@dalias@hachyderm.io @womble@infosec.exchange @eigen@mattstodon.panar.ooo @mhoye@cosocial.ca Who is helped by creating "us vs. them" when the people you are shitting on are fellow FLOSS contributors? Is it possible to consider offering more sympathy and empathy to other contributors even if you disagree with them on many things as they offer you a similar courtesy by trying to engage with musl and support it? Should we return to a world where we fail basic solidarity?
4
1
0
0
Open post
Replying to
@yuka 6.12.85 has the fix: https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.85
4
1
0
0
Open post
Replying to
@filmroellchen @aks given that all the linux kernel is doing the same thing, not sure it makes a difference
6
8
0
0
Open post
Replying to
@zimoun @luj @civodul Arguably, as these ecosystems become more and more used, they also become a more interesting target for hostile actors with serious means (who can coerce people, etc.).
France is a pretty interesting case with the number of high profile kidnappings of cryptocurrency owners and I don't really know if the Ministry of Interior is doing well or not on that aspect to ensure that people can freely live.
3
0
0
0
Open post
Replying to
@civodul @luj @zimoun I skimmed through the paper but I did not find what I was interested in. How do you address the committer trust layer? I get that Guix authenticates Git checkouts and verifies signatures of committers.
How does Guix work towards coercion resistance against backdooring, suspicious behavioral attacks, compromised forge accounts/authoring systems, etc. ?
I suspect this is the point that has been the least addressed among all modern supply chain solutions.
3
5
0
0
Open post
Replying to
@robinheghan @lix_project you're right and it is, nonetheless, it's still worth having alternative cohesive spaces, even if contributing to nixpkgs takes place, it can take place in other channels as well (which are moderated). In addition, having an alternative to nixpkgs is a question of the community organizing to fork it.
10
5
0
0
Open post
Replying to
@fionafokus@mystical.garden at this current point, we have somewhat luxury problems with our rail network compared to equivalent systems (which does not exist really I think?)
3
0
0
0
Open post
Replying to
2
0
0
0
Open post
Open post
Open post
Replying to
@LGUG2Z@hachyderm.io Voted no, let me expand: I would like to see compelling ways to block usage by exploiting legislation and compliance and so on.
4
1
0
0
Open post
Open post
Replying to
1
8
0
0
Open post
Open post
Open post
Open post
Open post
Replying to
@corbin@defcon.social @stargirl@hachyderm.io Indeed, I commented here: https://discuss.python.org/t/python-packaging-strategy-discussion-part-1/22420/153?u=raitobezarius on our perspective.
5
0
1
0
Open post
Open post
Open post
Replying to
@bluca@fosstodon.org @staticnoisexyz@infosec.exchange if you want the rage: why is this not in the TPM2??? why??? i want my user records in tpm2 plz
0
2
0
0
Open post
Open post
Replying to
@louis @lix_project that's interesting feedback, I guess if we get there, we will probably consider owning the cap'n'proto library as well if needed
0
0
0
0
Open post
Replying to
@mevenlennonbertrand@lipn.info any links to PRs/issues, that's super interesting
0
4
0
0
Open post
Replying to
@CounterPillow@mastodon.social what do you mean? Like B4 didn't get an AI review feature or automatic backport are not decided by LLMs?
0
5
0
0
Open post
Replying to
@CounterPillow@mastodon.social I don't know if this is ignorance or something else, but again: https://lore.kernel.org/all/20250725175358.1989323-1-sashal@kernel.org/ what do you mean?
The kernel already contains many regressions caused by LLM, what are you on? Even security vulnerabilities were caused already by LLMs.
0
3
0
0
Open post
Replying to
@zkat@fedi.zkat.tech @lcamtuf@infosec.exchange also all these issues can be reasonably mitigated by a careful use of https://docs.rs/pathrs/latest/pathrs/ which possess the decade long lessons
0
0
0
0
Open post
Replying to
@CounterPillow@mastodon.social Thank you for not moving the goal post for what follows because I do not owe you my time.
(1) On security regressions: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=d4f9351243c17865a8cdbe6b3ccd09d0b13a7bcc is well known, AUTOSEL/rejection of CVEs based on LLM has been causing more of them. You can figure out more if you filter lore by stable backports.
1/?
0
0
0
0
Open post
Replying to
0
0
0
0
