@dalias @cas @womble @eigen @mhoye
I think it's bad faith to assume the maintainer would give the employer *they happen* to work for editorial control.
@dalias @cas @womble @eigen @mhoye
I think it's bad faith to assume the maintainer would give the employer *they happen* to work for editorial control.
@dalias @cas @womble @eigen @mhoye
This presumes the FOSS maintainers have more loyalty to their employer than the community they serve for decades.
@dalias @cas @womble @eigen @mhoye
Yes, but you are making *pointed* claims about other FOSS contributors and projects.
@dalias @cas @womble @eigen @mhoye
And how do you discern the difference?
@dalias @cas @womble @eigen @mhoye
And if the employment contract stipulates they can work a percentage of their hours on FOSS, and the company has no say nor control in the development of the software?
@Gottox this has to be LLM hallucinations
There is a native way to use secure enclave with ssh on Mac these days.
It seems a bit more convoluted though.
https://gist.github.com/arianvp/5f59f1783e3eaf1a2d4cd8e952bb4acf
From @arianvp
@dalias
I generally agree but I struggle to see how distros should/are capable of solving it.
It's a social problem more so than a technical one.
From the @archlinux side; there is not.
But code review of individual package bumps is something few distros do.
@scy
US court is leaning towards that LLM generated code is fundamentally not copyrightable.
This is a different problem to the moral issues I have with this.
Apparently chardet got Claude to rewrite the entire codebase from LGPL to MIT?
https://github.com/chardet/chardet/releases/tag/7.0.0
That is one way to launder GPL code I guess?
What information on the CT log are you aiming at?
In amazing event of "unable to read the room", an AI CTO has joined the #lobsters IRC channel and instructed an AI agent to beg the channel for an invite to the site.
Amazing.
To quote @aks
> Men would rather outsource their social life to LLM's than go to therapy
@soatok @cadey
I mean, can you remember the command to sign and validate the signature from the top of your head?
I remember age, no issue. But ssh?
`ssh-keygen -Y sign -n file -o signature.sig file`? I think?
And to validate it's uhh
`ssh-keygen -Y verify` and then I have to check the man page?
Why is keygen doing this. What is `-Y`? What is `-n file` and why do you have to remember this across the sign and verify commands?
Score: 2/10
gpg is literally easier.
@cadey @soatok
Honestly, `openssh` could be that tool if they just cared about their UX :/
@soatok
I should have been more specific, sorry. It requires it's own server software.
@soatok
I'm aware of that work, but it has a custom tlog implementation and requires a server.
I think it should be simpler like `wkd`, and then try jam a tlog into this somehow.
@soatok
Yes, but a httpdir is simpler.
This is why I would prefer to generalize and move public key distribution to some `well-known` directory.
https://github.com/C2SP/C2SP/issues/192
I'm looking at figuring out a convenient abstraction over this in the form of:
```
keys | keys list | keys foxboron@example.org
keys get -t age foxboron@example.org
keys fetch foxboron@example.org
```
or something along these lines. Once you have the keys inside a dir and some "identifier" you could work on tooling on top of this.
F/OSS Hacker. Arch Linux Developer, Security Team, Reproducible Builds. General Linux stuff and supply chain issues.Writes in English and Norwegian from time to time.He/Him
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.