Sign in

Martin Baschpel

@bilbothebird.bsky.social
6 followers 17 following 16 posts

There is no pink oliphaunt.

PostsRepliesMedia
Reposted by Martin Baschpel
Charlie Chapman @charliemchapman.com · 20/07/2026
Watching The Odyssey the only way Nolan truly intended
51154380
Martin Baschpel @bilbothebird.bsky.social · 03/07/2026
Funny you would say "Credit cards no longer have embossed numbers", because that seems to be strictly non-true for Visa&Mastercard here in Austria and Germany. My 2026 issued Mastercard plastic piece still has embossed numbers as have all credit cards I see around here. Not that I _ever_ needed it.
100
Martin Baschpel @bilbothebird.bsky.social · 02/06/2026
It is deeply unclear to me why MS would need to maintain their own port of these tools, when they have been ported as open source all these years anyway ... available e.g. at community.chocolatey.org/packages/gnu...
community.chocolatey.org
000
Martin Baschpel @bilbothebird.bsky.social · 15/04/2026
Reminding people - all of us - that these machines do not, at all, currently work like we would expect "intelligence" or reasoning to work, is not missing the point. Dismissing these things as useless because of that would be missing the point. They're useful and amazing, but intelligent: not.
020
Martin Baschpel @bilbothebird.bsky.social · 26/02/2026
I think the fear/assumption here is that it's only about the "me" that's been set off pondering, rather than about the feelings of the other person - but I guess there's only one way to know, and that is by talking about it. 👀
010
Martin Baschpel @bilbothebird.bsky.social · 19/01/2026
It's gonna be that kind of week .... xkcd.com/979/ && xkcd.com/386/ == 😵
xkcd.com
Wisdom of the Ancients
000
Martin Baschpel @bilbothebird.bsky.social · 15/12/2025
I only saw Across The Spider-Verse in a Theater, but oh my, one of the most must-see-in-an-actual-cinema movies of the last 20 years. Absolutely immersive.
000
Martin Baschpel @bilbothebird.bsky.social · 23/10/2025
www.kickstarter.com/projects/mee...
000
Martin Baschpel @bilbothebird.bsky.social · 13/10/2025
The Great Software Quality Collapse: How We Normalized Catastrophe open.substack.com/pub/techtren...
open.substack.com
The Great Software Quality Collapse: How We Normalized Catastrophe
The Apple Calculator leaked 32GB of RAM.
011
Martin Baschpel @bilbothebird.bsky.social · 16/09/2025
Maybe it's actually a good way? Sure it's a bad way to sell AI, and misleading of how much better it can already be. But I think it serves as a reminder of the subtle stupidity behind even the most advanced models. :-)
000
Martin Baschpel @bilbothebird.bsky.social · 28/05/2025
From FOSS to Flop, and How to Go Commercial Without Alienating Your Users blog.inedo.com/inedo/from-f... ... I guess I have Some Thoughts about that blog post, but overall a nice read. #foss #dev
blog.inedo.com
From FOSS to Flop, and How to Go Commercial Without Alienating Your Users
Moq, FluentAssertions, MassTransit, AutoMapper, MediatR – if those NuGet package names sound familiar, it might be from all the recent controversy. The authors of these free, open-source .NET librarie...
000
Martin Baschpel @bilbothebird.bsky.social · 02/05/2025
With Authenticode, what is the point of having hardware based HSM/FIPS protection for the private key when the Ability-To-Sign is only protected by Cloud credentials or API keys? I really don't get it yet. #authenticode #codesigning #softwaresecurity security.stackexchange.com/questions/28...
security.stackexchange.com
When Code Signing, what is the point of enhanced security specifically for the private key itself?
TL;DR What is the point of having hardware based HSM/FIPS based protection for the private key when the ability to sign is "only" protected by credentials / API keys? Background In the pa...
000
Reposted by Martin Baschpel
Kevlin Henney @kevlin.bsky.social · 28/04/2025
My keynote, "Fun for Now", from @devoxxgreece.bsky.social a couple of weeks back www.youtube.com/watch?v=dt9Y...
youtube.com
Devoxx Greece 2025 - Fun for Now ( opening keynote by Kevlin Henney )
YouTube video by Devoxx
174
Reposted by Martin Baschpel
Kevin Jones @vcsjones.dev · 28/04/2025
The specific text "Signatures using elliptical curve cryptography (ECC), such as ECDSA, aren't supported in Windows and newer Windows security features." seems pretty clear to me, "It's not supported".
011
Martin Baschpel @bilbothebird.bsky.social · 28/04/2025
... * Digicert claims (docs.digicert.com/en/certcentr...) that we could use ECC P-256-bit key size. * Yubico timings (support.yubico.com/hc/en-us/art...) indicate that ECDSA-P256-SHA256 could be more than facto 10 faster than RSA-4096. (Factor 6 for RSA-3072)
docs.digicert.com
Order a Code Signing certificate
000
Martin Baschpel @bilbothebird.bsky.social · 28/04/2025
The reason I wanted to try ECC: * Signing all binaries of our CI release builds is dead-slow with RSA 4096 (850 msec per File on our YubiHSM2), and ...
docs.digicert.com
Order a Code Signing certificate
100
Martin Baschpel @bilbothebird.bsky.social · 28/04/2025
In my case we would have liked to try an ECC only private key for our OV certificate, so the Root certificates would still be RSA. Seeing ECC unsupported on the Root however is not exactly encouraging.
100
Martin Baschpel @bilbothebird.bsky.social · 28/04/2025
Interesting. Even though the docs you have linked to are specifically for the "Trusted Root", which, as far as I can grasp, I don't have any influence over anyway with Authenticode, since that's provided by (e.g.) Digicert.
200
Martin Baschpel @bilbothebird.bsky.social · 28/04/2025
@vcsjones.dev - You wrote a great article about ["Authenticode and ECC"](vcsjones.dev/authenticode...) ... 9 years ago. We're currently looking into using ECDSA only signing for Authenticode. Know whether the conclusion from back then (lacking consistent tool support) has changed in 2025?
vcsjones.dev
Authenticode and ECC
While HTTPS / TLS have been making great strides in adopting new cryptographicprimitives, such as CHACHA, x25519, and ECC, another place has remainedrelative...
111