GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Lance R. Vick (lrvick@mastodon.social)

  1. Embed this notice
    Lance R. Vick (lrvick@mastodon.social)'s status on Monday, 31-Mar-2025 07:40:51 JST Lance R. Vick Lance R. Vick

    Saw a Tesla with an american flag license plate border and a plate that read "LYVFREE".

    While I don't actually condone such actions, it was in that moment I truly understood where people get the urge to set a Tesla or two on fire.

    Teslas have become the urban equivalent of big pickup trucks with truck nuts and flags flying off the back.

    In conversation about 2 months ago from mastodon.social permalink
  2. Embed this notice
    Lance R. Vick (lrvick@mastodon.social)'s status on Saturday, 16-Nov-2024 19:29:27 JST Lance R. Vick Lance R. Vick

    Saying "Don't use PGP, use SigStore or Age!" is the same class of dumb as saying "Don't use web standards, use Flash or Java embeds!".

    Before advocating everyone abandon standards and use whatever tools have the better UX or defaults for your use case blindly, maybe take the time to actually understand the problems the standards are trying to solve for, and if any improvements or better implementations are in progress.

    In conversation about 6 months ago from mastodon.social permalink
  3. Embed this notice
    Lance R. Vick (lrvick@mastodon.social)'s status on Friday, 27-Sep-2024 05:48:23 JST Lance R. Vick Lance R. Vick
    • Matthew Lyon

    @mattly I think trying to force authors of software to sign their software or improve their security posture beyond what they want to is a dead end.

    Plus, who is to say a developer like you is even still alive to be forced to change? Or that your account was not taken over by a blackhat years ago?

    We need to stop trusting authors and start requiring/funding actual signed reviews of the code we effectively copy/paste from randos on the internet.

    In conversation about 8 months ago from mastodon.social permalink
  4. Embed this notice
    Lance R. Vick (lrvick@mastodon.social)'s status on Friday, 27-Sep-2024 05:48:22 JST Lance R. Vick Lance R. Vick
    in reply to
    • Matthew Lyon

    @mattly I did talk to the GitHub team about this stuff, for -hours-, however they are convinced even offering code-signing or signed code reviews as -optional- would make people feel pressured to do such things, and contribute less code, so thus they will never do it.

    Instead, they force 2FA on developers and make them want to contribute less code anyway, a change that does not actually solve the problem.

    Microsoft/Github have lost the plot. Or they never had it.

    I recommend Codeberg.

    In conversation about 8 months ago from mastodon.social permalink
  5. Embed this notice
    Lance R. Vick (lrvick@mastodon.social)'s status on Thursday, 26-Sep-2024 23:46:04 JST Lance R. Vick Lance R. Vick
    • Matthew Lyon

    @mattly You can thank people like me for proving how easy supply chain attacks are for this change.

    I usually target inactive accounts of past contributors. Especially those that don't have 2FA and let their email domain names expire.

    That said, forced 2FA is the wrong solution. There should be a system for decentralized signed code review so people can sign review on any code, and set policies on how many signed reviews are required on code before it is trusted by their system.

    In conversation about 8 months ago from mastodon.social permalink
  6. Embed this notice
    Lance R. Vick (lrvick@mastodon.social)'s status on Wednesday, 13-Mar-2024 01:53:50 JST Lance R. Vick Lance R. Vick

    Hot take: If you are not confident enough with Linux to run it on your own daily driver workstation, you probably have no business securing or managing it in production.

    In conversation about a year ago from mastodon.social permalink
  7. Embed this notice
    Lance R. Vick (lrvick@mastodon.social)'s status on Wednesday, 13-Mar-2024 01:34:43 JST Lance R. Vick Lance R. Vick
    in reply to
    • Jennifer
    • Thomas Phinney, Font Detective

    @tphinney @Jennifer Exactly this, and they chose to introduce it months after I became a patient, having known from the outset that I do not have or want a Google or Apple device.

    I gave up my smartphone 3 years ago, and am a lot happier being disconnected when I am not at my desk. It would seem some don't consider this a valid lifestyle choice.

    This is the first time anyone has refused me services for not having a phone.

    In conversation about a year ago from mastodon.social permalink
  8. Embed this notice
    Lance R. Vick (lrvick@mastodon.social)'s status on Wednesday, 13-Mar-2024 01:33:02 JST Lance R. Vick Lance R. Vick
    • Ben Aveling
    • Jennifer

    @BenAveling @Jennifer There are no medical devices involved.

    They said they only willing to communicate, schedule, and exchange medical information with patients with their apple/google mobile app moving forward, even if it means terminating relationships with existing patients.

    I even offered to show up in person for every communication, and they refused.

    In conversation about a year ago from mastodon.social permalink
  9. Embed this notice
    Lance R. Vick (lrvick@mastodon.social)'s status on Tuesday, 12-Mar-2024 09:11:31 JST Lance R. Vick Lance R. Vick

    It's official. After 3 months of back and forth, a major medical provider has elected to drop me as a patient for not having a Google or Apple device.

    It is unclear if this is legal, but it is very clearly discriminatory and unethical.

    Any tech journalists or lawyers interested interested in this?

    I would like to do anything I can to ensure this never happens to anyone else.

    In conversation about a year ago from mastodon.social permalink
  10. Embed this notice
    Lance R. Vick (lrvick@mastodon.social)'s status on Monday, 15-Jan-2024 09:32:52 JST Lance R. Vick Lance R. Vick

    1. Buy expired NPM maintainer email domains.
    2. Re-create maintainer emails
    3. Take over packages
    4. Submit legitimate security patches that include package.json version bumps to malicious dependency you pushed
    5. Enjoy world domination.

    In conversation Monday, 15-Jan-2024 09:32:52 JST from mastodon.social permalink
  11. Embed this notice
    Lance R. Vick (lrvick@mastodon.social)'s status on Monday, 15-Jan-2024 09:32:51 JST Lance R. Vick Lance R. Vick
    in reply to

    I just noticed "foreach" on npm is controlled by a single maintainer.

    I also noticed they let their personal email domain expire, so I bought it before someone else did.

    I now control "foreach" on NPM, and the 36826 projects that depend on it.

    In conversation Monday, 15-Jan-2024 09:32:51 JST from mastodon.social permalink
  12. Embed this notice
    Lance R. Vick (lrvick@mastodon.social)'s status on Sunday, 31-Dec-2023 19:11:21 JST Lance R. Vick Lance R. Vick

    At #37c3 they have IRC, and Matrix for text and for voice they setup their own LTE/2G/3G/SIP/DECT network where you bring whatever phone-like device and pick a 4 digit phone number.

    Meanwhile in the USA for #defcon they just paid Discord money and told everyone to accept their privacy policy, and even the DC Privacy Village asks people to sign up for Slack and Google.

    People ask why I fly to CCC from the USA. It is because that is the closest place to find a thriving hacker culture.

    In conversation Sunday, 31-Dec-2023 19:11:21 JST from mastodon.social permalink

User actions

    Lance R. Vick

    Lance R. Vick

    FOSS || GTFO* Security Engineer* Cypherpunk* Founder of #! and Distrust* Church Of Cryptography Priest#infosec #security #opensource #foss #sysadmin #cryptoanarchy #cypherpunk #embedded #puzzles #privacy #locksport #programming #linux #homelab

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          227797
          Member since
          31 Dec 2023
          Notices
          12
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.