Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Danny Grove

@groved@mastodon.social
mastodon 4.7.0-beta.1
  • Open on mastodon.social

Co-Founder @ hashbang.sh
Owner @ drgrovellc.com
Lead Infrastructure Engineer @ manifestcyber.com
[StageX] Maintainer
#security #ReproducibleBuilds #infrastructure #privacy #OpenSource
Thoughts are my own

0 Followers
0 Following
7 Posts
Joined October 13, 2022
OpenPGP:
openpgp4fpr:c92fe5a3fbd58dd3ec5aa26bb10116b8193f2dbd
Homepage:
https://dannygrove.com
Matrix:
https://matrix.to/#/@dgrove:matrix.org
Community:
https://hashbang.sh

Posts

Open post
groved
Danny Grove @groved@mastodon.social · Apr 18, 2026
Danny Grove
@groved@mastodon.social

Co-Founder @ hashbang.sh Owner @ drgrovellc.com Lead Infrastructure Engineer @ manifestcyber.com [StageX] Maintainer #security #ReproducibleBuilds #infrastructure #privacy #OpenSource Thoughts are my own

mastodon.social
Replying to @groved@mastodon.social
@slink@fosstodon.org @meejah@mastodon.social @0xKaishakunin@mastodon.social here is a link to our signatures repository that doubles as a lookaside endpoint and provides additional details on the various processes. https://codeberg.org/stagex/signatures
2
0
1
0
Open post
groved
Danny Grove @groved@mastodon.social · Apr 18, 2026
Danny Grove
@groved@mastodon.social

Co-Founder @ hashbang.sh Owner @ drgrovellc.com Lead Infrastructure Engineer @ manifestcyber.com [StageX] Maintainer #security #ReproducibleBuilds #infrastructure #privacy #OpenSource Thoughts are my own

mastodon.social
Replying to @slink@fosstodon.org
@slink@fosstodon.org @meejah@mastodon.social @0xKaishakunin@mastodon.social Here's our maintenance guide, https://codeberg.org/stagex/stagex/src/branch/main/MAINTENANCE.md Separately we get a few advantages from using OCI as our artifact/delivery method. This allows us to take advantage of atomic signature format and containers-policy.json. we can separately extend that in a k8s environment with something like kyverno for more complex policies. We're also working on support to separately manage this within a cli we're building but that's not fully fleshed out yet.
2
1
0
0
Open post
groved
Danny Grove @groved@mastodon.social · Apr 18, 2026
Danny Grove
@groved@mastodon.social

Co-Founder @ hashbang.sh Owner @ drgrovellc.com Lead Infrastructure Engineer @ manifestcyber.com [StageX] Maintainer #security #ReproducibleBuilds #infrastructure #privacy #OpenSource Thoughts are my own

mastodon.social
Replying to @groved@mastodon.social
@slink@fosstodon.org @Di4na@hachyderm.io @hipsterelectron@circumstances.run You can separately use PKCS11 and ship around public x509 public keys. Which still leaves you with a similar problem to GPG and single token key signing. Similar to what I described in a separate thread off this post, your problem will still lie in trust or needing to do some sort of quorum and split (or multi-sign) approach to prevent single point of trust.
0
0
0
0
Open post
groved
Danny Grove @groved@mastodon.social · Apr 18, 2026
Danny Grove
@groved@mastodon.social

Co-Founder @ hashbang.sh Owner @ drgrovellc.com Lead Infrastructure Engineer @ manifestcyber.com [StageX] Maintainer #security #ReproducibleBuilds #infrastructure #privacy #OpenSource Thoughts are my own

mastodon.social
Replying to @groved@mastodon.social
@meejah@mastodon.social @slink@fosstodon.org @0xKaishakunin@mastodon.social With a combination of reproducible builds, hardware backed individual keys and threshold signing policies you can then have better guarantees around this source code == this binary
1
1
1
0
Open post
groved
Danny Grove @groved@mastodon.social · Apr 18, 2026
Danny Grove
@groved@mastodon.social

Co-Founder @ hashbang.sh Owner @ drgrovellc.com Lead Infrastructure Engineer @ manifestcyber.com [StageX] Maintainer #security #ReproducibleBuilds #infrastructure #privacy #OpenSource Thoughts are my own

mastodon.social
Replying to @groved@mastodon.social
@meejah@mastodon.social @slink@fosstodon.org @0xKaishakunin@mastodon.social Separately you then run into the signing problem. And trust around that. Any hot or warm key is always going to have a chance of compromise and beyond that if any single person has direct access to a full copy of the signing key you run the risk of a bad actor signing a bad version. OpenPGP has been the defacto signer for a long time and I don't think that is going to reasonably change anytime soon. This is a problem we've been thinking a lot about with StageX.
1
2
1
0
Open post
groved
Danny Grove @groved@mastodon.social · Apr 18, 2026
Danny Grove
@groved@mastodon.social

Co-Founder @ hashbang.sh Owner @ drgrovellc.com Lead Infrastructure Engineer @ manifestcyber.com [StageX] Maintainer #security #ReproducibleBuilds #infrastructure #privacy #OpenSource Thoughts are my own

mastodon.social
Replying to @meejah@mastodon.social
@meejah@mastodon.social @slink@fosstodon.org @0xKaishakunin@mastodon.social Reproducible builds only go so far though. Unless you're runners linux distro, build toolchain and deps are full-source bootstrapped and reproducible, you don't fully know that you're not compromised. @meejah@mastodon.social is correct thought, this is an orthogonal thing. If you have multiple runners building the code separately and hermetically and they come back reproducible, you do have a much better guarantee about the software.
1
1
1
0
Open post
groved
Danny Grove @groved@mastodon.social · Apr 18, 2026
Danny Grove
@groved@mastodon.social

Co-Founder @ hashbang.sh Owner @ drgrovellc.com Lead Infrastructure Engineer @ manifestcyber.com [StageX] Maintainer #security #ReproducibleBuilds #infrastructure #privacy #OpenSource Thoughts are my own

mastodon.social
Replying to @slink@fosstodon.org
@slink@fosstodon.org @Di4na@hachyderm.io @hipsterelectron@circumstances.run As a note, you _can_ use your own cosign keys (on hardware you control) but it does put a _massive_ burden on you to run a significant amount of infrastructure to do so.
0
1
0
0

Remote instance

mastodon.social
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 08:32:18 UTC