Filippo Valsorda @filippo.abyssdomain.expert

15.2K posts

Filippo Valsorda @filippo.abyssdomain.expert banner
Filippo Valsorda @filippo.abyssdomain.expert

Filippo Valsorda @filippo.abyssdomain.expert

@FiloSottile

Cryptogopher / Go crypto maintainer / @kateconger-knower / RC F'13, F2'17 / #BlackLivesMatter / he+him https://t.co/ZE4RtJ1xqD / https://t.co/qfth7zr00W / https://t.co/j1grpEm8uR

@[email protected] Katılım Haziran 2009
1 Takip Edilen45.6K Takipçiler
David Justo
David Justo@davidjustodavid·
@FiloSottile @tef_ebooks Trying to understand the GitHub sponsors part of this response. Are you saying GitHub sponsors is not an appropriate way for companies to sponsor OSS maintainers? Genuinely curious of what you meant :-)
English
1
0
0
171
Filippo Valsorda @filippo.abyssdomain.expert
@tef_ebooks Are you sure corporations don't want to pay for support? My experience is that they are desperate to find a professional counterpart that will sell them support, take their money, and take the job seriously. Most maintainers post GitHub Sponsors links though.
English
3
0
0
198
tef
tef@tef_ebooks·
either way, i'm still not exactly sure how "not being a hobby" meaningfully mitigates attacks built on abuse of trust i'm sure we could turn every side project into a side hustle, give or take crowd funding, but it's not like corporations want to pay for support, so
English
2
4
225
6.4K
Gergely Orosz
Gergely Orosz@GergelyOrosz·
@FiloSottile @patio11 Whatever the decision: either it will encourage similar activities (if it's a light sentence - sending the message this is fine) or discourages such activities (if a harsh sentence). Down to the justice system how it deals with it.
English
1
0
2
782
Filippo Valsorda @filippo.abyssdomain.expert
@GergelyOrosz @patio11 This is a sentencing memorandum. The argument is not that it's legal (the verdict already said it's not!) but about how bad it is. Without expressing an opinion on the specifics, I do think it's reasonable to say that creating a whole single-purpose fraud enterprise is worse.
English
1
0
6
331
Gergely Orosz
Gergely Orosz@GergelyOrosz·
@patio11 Did the defense tean really write this? Since when is using customer funds to fund another entity - while telling customers you are not doing this! - and eg use it for your personal gain (eg buy property for you/family), lawful? If this reasoning files, expect more of this.
Gergely Orosz tweet media
English
5
0
6
2.6K
Juliano Rizzo
Juliano Rizzo@julianor·
@FiloSottile 🤷‍♂️ Honestly, I have great respect for your work 💯. My initial comment, beginning with 'spoiler' (📽️🎞️) was more about stirring the pot, a blend of fiction reference and provocation to spark dialogue, not a hard stance on the matter. I assumed using the word 'senile' was enough
English
1
0
1
557
Filippo Valsorda @filippo.abyssdomain.expert
@julianor I'm not sure how to answer that... am I supposed to try to get more Twitter likes? Anyway, are you saying the next exploit chain will involve vulnerabilities in the PQC code, or simply that there will be one? Because the latter, I mean, sure?
English
1
0
4
375
Juliano Rizzo
Juliano Rizzo@julianor·
@FiloSottile I'm intrigued by the number of FAVs my tweet got from infosec veterans. It raises the question: are we simply senile, or 'The old wolf knows more because he is old than because he is a wolf' ?
English
1
0
3
403
Filippo Valsorda @filippo.abyssdomain.expert
@julianor The PQC algorithm implementation is. The changes announced today do far more than integrate PQC, iMessage was far behind on protocol crypto, but then the benefit is not just defending "against adversaries wielding imaginary computers".
English
5
0
5
400
Alex Rad
Alex Rad@defendtheworld·
@FiloSottile @julianor I don’t agree with all of djbs views. However taken holistically — what made djb this way — it’s because NIST has a long history of poor choices. Can you link the rebuttal to djbs weakness claims
English
1
0
0
352
Filippo Valsorda @filippo.abyssdomain.expert retweetledi
GopherCon
GopherCon@GopherCon·
We believe everyone deserves a chance to be a part of the #GopherCon magic!🪄 If you're passionate about Go and would like to join us in July, but don't have the financial means to do so, consider our scholarship program. ⏰The submission deadline is Monday, February 5th, at 11:00 p.m. Central Standard Time, so don't delay and apply today! forms.gle/oKtkMXUJoJLiTc… #RoadToGopherCon #golang
GopherCon tweet media
English
2
16
39
14.8K
Filippo Valsorda @filippo.abyssdomain.expert
@goinggodotnet That's because you have "go 1.21" in your go.mod, so the toolchain will do its best to behave like Go 1.21 did. #L3" target="_blank" rel="nofollow noopener">github.com/ardanlabs/serv… The new backwards/forwards compatibility features take a moment to get familiar with, but are pretty nice.
English
1
0
5
564
William (Bill) Kennedy
William (Bill) Kennedy@goinggodotnet·
Spent time looking at the http mux changes and incorporating them into the service project for 1.22rc2. One thing I had to discover is needing to set this env var for the code path to follow the 122 changes. GODEBUG=httpmuxgo121=0 github.com/ardanlabs/serv…
English
3
1
18
3.1K
Filippo Valsorda @filippo.abyssdomain.expert retweetledi
Sovereign Tech Agency
Sovereign Tech Agency@sovtechagency·
We're commissioning ~€600,000 in work on critical structural improvements, security, maintenance, and documentation from @ApacheLog4j maintainers. Announcement: sovereigntechfund.de/news/log4j-inv… Milestones: #what-are-we-funding" target="_blank" rel="nofollow noopener">sovereigntechfund.de/tech/log4j#wha
Filippo Valsorda @filippo.abyssdomain.expert@FiloSottile

No one is paying the log4j2 maintainers!? There is a whole page on the responsibilities of a @TheASF "Project Management Committee"... AND NO ONE IS PAYING THEM? apache.org/dev/pmc.html Open Source needs to grow the hell up. Yesterday. twitter.com/yazicivo/statu…

English
0
6
17
11.1K
Filippo Valsorda @filippo.abyssdomain.expert retweetledi
GoLab
GoLab@golab_conf·
Special thanks to Filippo Valsorda for yesterday afternoon's talk on 'The job of a #GoLang maintainer.' We delved into what it means to become an independent professional open-source maintainer. @FiloSottile #GoLab2023 #MaintainerLife
GoLab tweet mediaGoLab tweet mediaGoLab tweet media
English
1
9
43
8.3K
Filippo Valsorda @filippo.abyssdomain.expert retweetledi
Teleport
Teleport@goteleport·
As an open-core company, it’s vital that we support other open-source projects and maintainers. We're proud to sponsor @FiloSottile & we appreciate all he’s done to advance the state of security in Go, TLS and SSH. 📰~ Subscribe to Cryptography Dispatches words.filippo.io
English
0
1
14
5.2K
Filippo Valsorda @filippo.abyssdomain.expert retweetledi
patrickogrady.xyz
patrickogrady.xyz@_patrickogrady·
At @avalabsofficial, we believe the sustainable maintenance and development of open source cryptographic protocols is critical to the broad adoption of blockchain technology. We are proud to support this necessary and impactful work through our ongoing sponsorship of @FiloSottile and his team. words.filippo.io/dispatches/par…
English
3
31
111
16K