Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

At first I thought this might be promising, given

without burden on upstream maintainers

Then I see

This is not an officially supported Google product

on https://github.com/google/oss-rebuild

And then I also see

oss-rebuild uses a public Cloud KMS key to validate attestation signatures. Anonymous authentication is not supported so an ADC credential must be present.

    $ gcloud init
    $ gcloud auth application-default login
I would not use this with a dependency on Google Cloud, or the gcloud command line tool.

Mainly because Google has horrible customer support.

It would be more interesting if they came up with something hosted on third party infrastructure. Last I heard, Google Cloud is run by Oracle executives

---

e.g. in particular the Unisuper incident led me to believe that a lot of operational stuff is being outsourced, and is of poor quality

UniSuper members go a week with no account access after Google Cloud misconfig

https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...

Google accidentally deleted a $125 billion pension fund's account

https://qz.com/google-cloud-pension-fund-unisuper-1851472990

I would not say this is unrelated, because operations in the underlying cloud can be a weak link in security

Although I'd certainly be interested in an argument otherwise



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: