Post #2792053
2026-05-23 09:15 UTC
Killing long-lived developer API and GPG keys was a massive victory for the architecture of the Internet. But attackers didn't just give up; they shifted their focus to our build pipelines. My latest post examines this structural threat shift: https://josephhall.org/blog/squeezing-the-balloon/ 1/5
Replies (1)
-
@joebeone@techpolicy.social 2026-05-23 09:15
At the USENIX Security Enigma Track, Zach Steindler @steiza@a2mi.social detailed the massive effort to adopt Trusted Publishing. By swapping permanent passwords for ephemeral OIDC keys, we closed a major vulnerability window across registries. Watch his presentation: https://youtu.be/Vti6Av5NPuU 2/5