

How it started : 0
Max : 0
Now : 0
Iso27002 and provenance validation goes brrrrr


How it started : 0
Max : 0
Now : 0
Iso27002 and provenance validation goes brrrrr


You’re not alone.
The industry itself has become pointlessly layered like some origami hell. As a former OS security guy I can say it’s not in a good state with all the supply-chain risks.
At the same time, many ‘help’ articles are karma-farming ‘splogs’ of low quality and/or just slop that they’re not really useful. When something’s missing, it feels to our imposter syndrome like it’s a skills issue.
Simplify your life. Ditch and avoid anything with containers or bizarre architectures that feels too intricate. Decide what you need and run those on really reliable options. Auto patching is your friend (but choose a distro and package format where it’s atomic and rolls back easily).
You don’t need to come home only to work. This is supposed to be FUN for some of us. Don’t chase the Joneses, but just do what you want.
Once you’ve simplified, get in the habit of going outside. You’ll feel a lot better about it.


Still crutching on containers?
Most tracker brands for Android only ping from phones that have their app installed. Not all Android devices.
There are tags for both Apple and Android that connect to their respective networks; and phones of the right network passing by will spot and announce locations.
This year there are trackers which will connect to either distinct network, albeit you can only choose once and it can’t switch without a factory reset. Those brands will have an overwhelming market share AND not require a branded app for daily use and recovery.
Since there is no brand that has an overwhelming market share that means the chance to find a lost Android tracker is much smaller than the apple ones.
In the known universe, Android has 73% of the market. 73 is bigger than 27.
I have some, but I only trust them to find my keys within Bluetooth range.
I can confirm you can find the right tags even when outside of BT range.
The chipolo Loop
The chipolo Card (not card One or card Spot; Card)
The Rhino key device leverages/licenses chipolo tech, uses its tools, and therefore
The Rhinokey Card (this is getting repetitive)
The chipolo app:
We have one Loop we’re testing, and it works as expected, right outta her S24 or so, and with my S10. She shares me the loop right outta Find My. She installed no app. We did not pair it with an iPhone as hers is a work phone.
We intend to get more Loops, and Cards for the parents and ourselves. The boomers are all on iPhones so it will be fun science.
You like segregation?
They’ve only almost barely nearly shat out a usable Unix with hurd. Give them another few decades, my dude!


The core insight: OSS monetization was always about attention.
As an Open-source contributor and former owner of several projects, I’m embarrassed.
If you came into Open-source to become rich or famous, you’re a selfish fool. Code for the sake of the code.
0 is the goal. Well done !
Edit: Ha! Some masochist down-voted that.