Adrian Mouat
@adrianmouat
Technical community advocate at Chainguard. Bad guitarist. He/him.
I'll be at WeAreDevelopers in Berlin this week if anyone wants to say hi! Or listen to me talk about vulnpocalypses.
This week, Elad Meged found a critical exploit in the Gemini CLI. He wrote: "This is the type of exploit that turns CI/CD pipelines into supply-chain attack paths." novee.security/blog/google-...
State Of Open Con is coming to Edinburgh this Friday! There's a pretty amazing speaker lineup (and then there's me, but you can't have everything), so please do come join us. Free tickets are available for community, students and anyone in-between jobs. stateofopencon.com/edinburgh-so...
Bruce Schneier wrote (or paraphrased): If you think technology can solve your security problems, then you don’t understand the problems and you don’t understand the technology. His point was that security is a process, not a product. It lies in the interaction and intersection of systems.
A few weeks ago Sam Altman said: "We see a future where intelligence is a utility like electricity or water and people buy it from us on a meter and use it for whatever they want to use it for" www.businessinsider.com/sam-altman-a...
I'll be speaking at SOOCon 26 on the Road in Edinburgh on 5th June. I'll be joining Andy Martin and @lizrice.com for a fireside chat on "The Mythos Effect", and how things might never be quite the same again... Tickets: stateofopencon.com/edinburgh-soocon26
I'm happy to be back in the ambassador game, this time as part of @openuk.bsky.social. OpenUK has been doing a fantastic job championing open source software, hardware, data, AI, and open standards to help grow the UK's digital economy.
My hot take on why the "latest" tag is sometimes the best tag to use! #containers #kubernetes #devops
For those of us struggling with feeling devalued as programmers with the rise of AI, I present the following quote from Paul Graham: "In programming, as in many fields, the hard part isn't solving problems, but deciding what problems to solve."
Probably the most complex piece of self assembly furniture I've ever built was my kids toy kitchen.
Stockholm, I have entered your maw. I'm also talking at the cncf Meetup tonight if anyone is interested! community.cncf.io/events/detai...
@danlorenc recently wrote a blog on Gastown, which is Steve Yegge's attempt to build a "workspace manager" for coordinating AI agents. www.chainguard.dev/unchained/ga...
@chainguard.dev Assemble returns! Chainguard's flagship conference is coming to NYC. Come join us in March for talks & community events on the future of secure software (and especially secure container images). assemble.chainguard.dev/event/2991fc...
I'm sure some of you use the excellent @renovatebot.com to update dependencies in repos. But if you're calling Renovate from a GitHub action, you probably had to create a Personal Access Token (PAT). And PATs are a form of long-live token, my thoughts on which are summed up by this GIF.
Apparently Dijkstra wrote: "If in physics there's something you don't understand, you can always hide behind the uncharted depths of nature. You can always blame God. You didn't make it so complex yourself."
The most important one being "avoid long-lived credentials". Oh, and I love the 12-factor app manifesto, but please don't put secrets in env vars! See the comments for a link to the full presentation.
Evaluating risk and focusing on actual problems is key to security. Quantum risks are real, but does it matter when you leave long-lived tokens accessible? As Bruce Schneier said "More people are killed every year by pigs than by sharks, which shows you how good we are at evaluating risk."
"Any fool can write code that a computer can understand. Good programmers write code that humans can understand." I stumbled across this quote from Refactoring by Martin Fowler when looking at dannorth.net/blog/cupid-f... by @tastapod.com .
At a private event last week Bogomil Balkansky shared his thoughts on what he looks for when investing and advising companies. The quote that stuck with me was "Velocity is the primary determinate of success for a company".
When I've had to explain what containers are in the past, I've often used this quote from @bcantrill.bsky.social "Docker will do to apt what apt did to tar."
@puerco.mx kicking off Open Source SecurityCon by demonstrating how to prevent cats messing with your training data.
Continuing quote Friday, here's one from Werner Herzog when a journalist asks him about teaching his son "real things": ‘It’s much easier than that. Your son doesn’t need to know how to milk a cow. I’d allow him to dig a deep hole in the ground. Just let him dig a hole in the ground.’
On Wednesday, during the booth crawl, I will be taking part in the biggest event at KubeCon. Alongside the one-and-only (thankfully) @bretfisher.com , we will be hosting "The CVE Price is Right" at the Chainguard booth. Come along to win amazing prizes (Bret's broken juicer)!
The product page has even more business numbers you can twiddle with! https://www.chainguard.dev/containers
If you've visited the @chainguard.dev Images page recently you might have noticed there's a fun new calculator which estimates how much $$$ you could save by moving to our images and thereby eliminating CVE remediation tasks.
One of my favourite movie quotes: "You, me, or nobody is gonna hit as hard as life. But it ain't about how hard ya hit. It's about how hard you can get hit and keep moving forward. How much you can take and keep moving forward. That's how winning is done!"