• 0 Posts
  • 52 Comments
Joined 1 year ago
cake
Cake day: June 11th, 2023

help-circle
  • I worked for them ten years ago. I was excited to do something important for once. And it was better than competing with Amazon for book sales. I was really helping.

    I eventually left because I didn’t think we were being a great steward of donor money. And I didnt have the best relationship with my boss. Nice guy, but we didn’t clock.

    Back then they spent like half their money on donations and programs trying to get more editors. That included supporting projects in smaller languages and diversity on current projects. Mostly good stuff as far as I could tell.

    Where they invested their money for tech was where I disagreed. But even so, I’ve donated since then. They are supporting important work. Everyone makes mistakes.

    Ultimately, I dunno.









  • I dunno about stdx as a solution. It’s just not a big enough list.

    At work we build a big java thing and we:

    • Manually import all dependencies, including transitive dependencies.
    • Bless them by committing their hash to our repo. I think the cargo lock file does something similar.
    • Audit the dependencies by hand. Sometimes that’s reading them all and sometimes thats less. Honestly, it’s often less. A few times it’s being members of the upstream community.
    • Don’t allow running as root
    • Drop all permissions we don’t need with seccomp including reading a bunch of stuff
    • Sandbox each thread based on what’s on the stack. Untrusted code can do less stuff.

    It’s still not enough. But it helps.

    Maybe a web of trust for audited dependencies would help. This version of this repo under this hash. I could see stdx stuff being covered by the rust core folks and I’m sure some folks would pay for bigger webs. We pay employees to audit dependencies. Sharing that cost via a trusted third party or foundation or something feels eminently corporate. Maybe even possible.



  • I really thought the idea was, “You like mecha? You like kids piloting mecha? This is how it’d go down.” I loved it so much. Shinji’s a broken, abused shell child. He lives with a broken human who drowns her sorrows in drink. His father is just evil. He’d have to be to let his kid pilot the mecha.

    The only real father figure we ever see for shinji is a spy. Who gets killed. He’s in love with a girl that hates him. Because he’s broken. But he has no one else. Except those friends at school who I think they take away. Don’t remember. And that angel who he has to kill or something. Damn, it’s been like 25 years. I have no idea what happened. But in my memory it’s terrible. Wonderful stuff.