Yesterday Milo was back at North Downs Specialist Referrals (NDSR) for a scan and the Epirubicin chemotherapy that comes at the end of this cycle of the CEOP protocol.

Milo enjoying an apple from the garden

The scan was very encouraging, showing that his lymph nodes were back to their usual size, so once again the oncologist thinks he’s in remission. His cancer has responded to treatment again, which is good. Also good was that with a slightly reduced dose of Vincristine last week his neutrophils were at an OK level for us to proceed with chemo.

Insurance

Milo’s premium has gone up a fair bit, but maybe that’s the normal course of things as he gets older. ManyPets have been turning claims around pretty quickly, with 60% being settled in a day or two, and the remainder coming through in 2-3 weeks. I’ve been adding the most recent NDSR report into the (newly added) history section each time, which hopefully is making things easier at their end (though why that’s necessary when they have all the history in their system can remain one of those mysteries of modern business processes).

Past parts:

1. diagnosis and initial treatment

2. first setback

3. back on track

4. second setback

5. easing the pace

6. counting the cost

7. fat boy

8. done CHOPping for now

9. scans

10. relapse

11. remission

12. complications

13. more H

14. three

15. scans (again)

16. relapse redux


September 2024

01Oct24

Pupdate

The bad/sad news at the start of the month is that Milo’s back on chemotherapy; though it seems to be going well, and we’re already almost at the end of the first cycle.

Max and Milo on a park bench

Apart from that the boys enjoyed some long walks before the weather turned.

Navy Reunion

It’s been 35 years since a bunch of us walked through the gates of Britannia Royal Naval College (BRNC) in Dartmouth. This is also likely to be the last time that some of us are still serving – those who’ve done well are now Admirals, and everybody’s on the cusp of hitting retirement age.

We were able to do things in a certain amount of style in the historic dockyard at Portsmouth – I guess those Admirals have some pull when they ask for things, and the weather was kind, allowing for a BBQ.

It was fantastic to catch up with old friends, some of whom I’ve stayed in touch with over the years, and others who I haven’t seen since our passing out ball at Dartmouth.

Vienna

I’ve been doing a lot of stuff with projects run by the Open Source Security Foundation (OpenSSF) over the past couple of years (e.g. Supply Chain Security Trifecta[1]), so when their SOSS Community Day Europe was announced it seemed like a good opportunity to meet folk in person who I’ve been collaborating with online. Sadly the industry wide turbulence of layoffs put a dent in that plan, but I went anyway and got to meet a bunch of interesting folk (and do a lightning talk on ‘Rules of Engagement for Forking a Dependency‘)

The view from my Vienna hotel window

I’ve been to Vienna a couple of time in my time at DXC, which took me into the centre of the city for customer meetings, and the industrial park where the DXC offices are; so this trip took me to a new bit I’d not seen before, and the trains were thankfully very quick and efficient in getting me there and back.

Dillions

One of the treats I had planned for Rachel’s 50th last month was a trip to Dillions, a local vineyard that we first came across when their Bacchus appeared at one of our favourite restaurants. We also ended up getting their ’22 Bacchus as the white wine choice for our party last month (which went down very well). Sadly the tour had to be cancelled so that the vines could be sprayed, but thankfully they were able to re-arrange it for what turned out to be a beautiful day in the middle of the month.

Promotional picture from the Dillions website

David the owner was a wonderful host, though ’24 hasn’t been a good year for growing grapes; so our tour of the vines was something of a tale of woe – mildew, ‘hens and chicks‘ and just generally poor yield. After the vines we got to the fun bit – tasting (almost) all the wines he’s released commercially. We came away with a case of the ’22 Rosé, as it’s lovely (even though I’m not usually a Rosé fan).

If you want to hear about winemaking from a passionate expert (who’s making some of the best wine in the country) I can highly recommend a tour once they restart next year.

The Langham Eastbourne

We’d have very happily returned to Horsted Place after such a nice anniversary trip last year, but they were booked solid :( So… The Langham was what eventually got pulled out of the sorting hat, partly because of their dinner inclusive rate, but mostly because of so many positive reviews.

I’m not sure exactly what I expected, but it managed to exceed in many ways. The room was lovely, with a nice sea view. Dinner was delightful, and right up there quality wise with some of the top restaurants we’ve visited. The Sussex cheese selection was one highlight, but the star of the show was the royale cut smoked salmon in Rachel’s starter – I almost regretted my choice of beef tartare. Breakfast was delicious, and it was nice to sit in the seaside conservatory in daylight. Yes, it’s Eastbourne, so we were the youngest guests by about two decades; but that didn’t make any difference.

I was particularly impressed by their online check-in/check-out process, which meant we were swiftly on our way after breakfast for a meandering drive home along the coast.

Computer Sheds

The Retro Computer Meetup had a jaunt to York to visit Jim Austin’s Computer Collection aka ‘The Computer Sheds‘. Jim and his merry band of volunteers have amassed an impressive hoard of kit and ephemera in the former pig farm ‘sheds’. They’re open for pre booked tours every other Saturday, with Jim providing an intro, and volunteers on hand to give guided tours. We were shown around by Pete, who’d worked with Jim at the University of York. It was particularly poignant for me to see examples of Silicon Graphics Indigo machines (and Cobalt ‘servers’) that I’d been telling a colleague about just days earlier. It’s possible that some of the machines in the sheds are the ones I actually used during my time at York.

Silicon Graphics Indigo workstations
A row of Silicon Graphics Origin 2000s
One Origin 2000 was in a shipping crate addressed to the University of York

One of the most memorable exhibits is thought to be the first prototype of the Sun 1 Workstation:

Cadlinc branded workstation

I chatted a little to Jim about Transputer stuff, whilst my meetup friends explored various artifacts connected to their earlier days of computing. It was a lot of time on trains to get there and back, but totally worth it.

HP Laptop Repairs

I got my son a Victus gaming laptop back in June, and he’s generally been very happy with it. Until the day it suddenly powered down.

Since I’d had a snag with the keyboard on my HP Omen laptop I knew the drill for getting it returned for repair, and it was soon on its way.

A few days later it was back, with a new motherboard (and trackpad). It lasted 7h before failing again.

Another repair, another new motherboard, and this time it lasted 45m. At this stage I’m pretty dubious about their testing, as it booted up into a CMOS parity error :/

Organising the next return was more of a palaver, and took three calls, which just seemed to be delaying the inevitable. We’re still waiting for it to get back, but neither of us is particularly optimistic.

Solar Diary

There were some nice days in the middle of the month, but generation was well down on last year.

306kWh generated during September

Note

[1] Of you’re interested in more on this I’m doing a talk at AllDayDevOps.


Grace Hopper

12Sep24

It’s wonderful that this lecture by Grace Hopper at the NSA in 1982 has made its way out into the world.

It’s SO prescient on a variety of topics like distributed computing, language standards, service ownership and the leadership vacuum. She could see it all – 42 years ago.

If you work in IT today, in any capacity, it’s worth 1h30 of your time (and maybe set aside a little more to reflect on what she had to say).


HelixML have announced their Helix platform for Generative AI is production ready at version 1.0. Described as a ‘Private GenAI Stack’ the platform provides an interface layer and applications that can be connected to a variety of large language models (LLMs). It can be used to prototype applications, starting with just a laptop; with all components version controlled to ease subsequent deployment and scaling of apps that prove useful. There’s also heavy emphasis on evaluations (evals) as the substitute for tests in the non deterministic domain of LLMs.

Continue reading the full story at InfoQ.


Two more months have rolled by since the last scan and Milo has enjoyed a nice summer of long walks and no vet visits (apart from his routine vaccinations).

Sadly the most recent scan picked up some inflammation of the lymph nodes, which suggests that the cancer is back. But once again we’ve caught it early, so there’s no sign of alimentary issues and any corresponding illness. It’s weird having a dog who’s ill but not unwell.

Milo sporting the bandage covering the Vincristine injection site.

So… back to chemo, and a slightly different protocol this time as he can’t have any more Doxorubicin (the H in CHOP). This time it’s going to be CEOP, which uses Epirubicin rather than Doxorubicin; but that comes at the end of the cycle, so we start off as before.

Past parts:

1. diagnosis and initial treatment

2. first setback

3. back on track

4. second setback

5. easing the pace

6. counting the cost

7. fat boy

8. done CHOPping for now

9. scans

10. relapse

11. remission

12. complications

13. more H

14. three

15. scans (again)


August 2024

03Sep24

Pupdate

The holidays brought the chance for longer lunchtime walks :)

Milo (jumping) and Max waiting for a biscuit

Zig

A bunch of smart (network) engineers kept mentioning Zig to me, so I took the opportunity to try it out. It’s supposed to be a replacement for C, and I was impressed by the bitwise switch statements in the fizz-buzz sample. If I was writing a device driver this feels like the language I’d want to use.

Even better, the Zig tool chain can cross compile C code. This seemed like the answer to my prayers for easily creating a range of binaries for the C implementation of NoPorts – until I discovered the binaries only worked superficially. I guess I’m now waiting for Zig 1.0.0 and a complete implementation of compiler-rt.

Warship

There’s a reunion planned in mid September to mark 35 years since a bunch of us joined Britannia Royal Naval College (BRNC) in Dartmouth. It’s sent me on a bit of a Navy nostalgia trip, which has got me watching episodes of Warship during my morning workouts. As it was made from 1973-77 I was far too young for an adult themed show, and I don’t even recall ever seeing any repeats of it back in the day. It holds up really well though. There are some scenes and episodes where it seems like my former colleagues were cosplaying what they’d seen on TV. And numerous comments (sometimes dismissed with ‘maybe before your time’) now suddenly make sense. Perhaps most (sadly) striking is that the challenges faced in the 70s that set the frame for some episodes are still relevant today.

Birthdays

The big event of the summer was Rachel’s 50th birthday, which we marked with a variety of activities culminating in a big party for friends at a local restaurant. Everything was great fun, and I’m particularly glad we got to see ABBA Revival at Trading Boundaries, which was an excellent evening out (and worth the early start and late arrival for OSHcamp…)

The ABBA Revival set at Trading Boundaries before the musicians took to the stage

Weirdly, my car was registered on Rachel’s 25th birthday, meaning it hit its quarter century at the same time as her half.

OSHcamp

It was great to return to the Open Source Hardware camp (OSHcamp) as part of Wuthering Bytes in Hebden Bridge. Even better to see one of my favourite communities thriving and growing, with a bigger venue allowing for more attendees with a good bunch of new younger faces :)

I enjoyed the talks on Saturday, and had the chance to present myself on ‘Showing that you care about security for your open source (hardware) project‘.

My intro slide captured by @[email protected]

Whilst Sunday brought the much greater challenge of assembling Ken Boak’s ‘TICK‘ bit serial computer.

New things

Windows

When we moved into our new build house in 2002 it was frustrating that the windows were so bad – poorly fitting wood framed units. We were told that wood was mandatory because of building in a conservation area, which was madness – chopping down more trees, and with gales blowing into some rooms that obviously impacted our energy use for heating. Thankfully there’s no such silliness for replacement windows, and we are perhaps in the late majority on the street to get uPVC units.

At this stage it’s hard to notice any difference (other than the lack of rotten window sills outside), but hopefully they’ll make a real difference once winter comes. I’ll be keeping a close eye on our gas usage.

Hot tub

I wasn’t a fan of getting an inflatable hot tub – mainly due to the energy use. But when an mSpa Alpine D-AL04 showed up in the summer of 2020 I grudgingly got into enjoying it whenever the weather allowed. Things changed once the solar was installed, as the tub could be run from a timer that would use electricity that would otherwise be exported, which really changed the effective cost.

Each year as it’s gone away I’ve wondered if it would survive for another season, and it lasted longer than I expected. But after some time off during our Lakes Trip the pump wouldn’t run for more than about 15m without stopping with an E1 error. I tried stripping it down and cleaning it out, but actually everything was pretty clean.

Lay-Z-Spa Barbados hot tub

Deciding that it wasn’t worth buying a new pump that might fix a now somewhat shabby old tub I thought the money would be better spent on a new one, so I grabbed a Lay-Z-Spa Barbados (which was half price in their summer sale). In many ways it’s a much better tub than the old mSpa. Energy efficiency is hugely improved by better insulation, the base is much more comfortable, and the chemical dispenser makes keeping the right chlorine level easy. My one niggle is that the lid fills up with rain water, though it’s much easier to clear than the old one. Also the WiFi/App is utter garbage – I can’t even get through the setup process.

Solar Diary

510.8kWh generated in August

It’s been another year since getting the panels installed, with a total of 8665 kWh generated (4271 this year, a little down on the previous year).

Ethernet data logger

I was never happy that the WiFi data logger couldn’t connect to my devices SSID, so I got a ShineLan-X ethernet data logger, and a managed switch to run a VLAN to it (because there’s no way I’m putting something that connects back to China onto my regular LAN). It’s great when it works, but there seems to be a race condition where sometimes the logger comes online before the inverter is ready.


Disclaimer

This isn’t tax or investment advice – if you need those things speak to a professional.

This is simply a story of a scary thing that happened, and (thankfully) worked out in the end.

TL;DR

If you’re in the process of re-certifying your tax status, E*TRADE take this as ‘not presently certified’ (even if your past certification hasn’t expired), and reach into your account and grab 24% of any trade proceeds as Backup Withholding Tax. Ouch.

My money was returned after the re-certification completed, about a week later.

What happened…

I needed to sell some US stocks to get cash for another investment. I’ve had an E*TRADE account for over 15y (since Credit Suisse created one for me to hold their restricted stock unit [RSU] grants), and so that’s where the stocks were.

When I signed in I was asked to re-certify my tax status as a non US person, which results in a W-8BEN being generated for the US Internal Revenue Service (IRS). Keen to ensure that I’m on top of such matters I did this before my trade, which was probably mistake #1. If I’d just skipped then the following events might have gone very differently, as my existing W-8BEN status was valid until 31 Dec (they last for 3 years).

Things have changed

There were a couple of aspects to the re-certification process that I don’t recall from previous occasions:

  1. I was asked why I had a US phone number on my account. This seems to be angled towards ‘if you have a US number then you must actually be a US person pretending to be a foreigner’, which is kind of ridiculous in a world of virtual telephony. I’ve had a US Google Voice number since 2010, and I often use it as my contact for US companies because they’re not always great at dealing with foreign contact details.
  2. I had to upload a bank statement with my UK address on it.

Make sure to keep evidence

After doing the re-certification I didn’t bother to download the file it offered me, thinking that I could get that in my account later. Mistake #2 – I now had no evidence of completing the re-certification process.

Back to the business at hand

I did my trade, but wasn’t able to move my money straight away. The US details for my Wise multi currency account had changed, so I had to initiate the process of adding a new account for withdrawals. It took a few (business) days for the the verification transactions to show up.

We’ve taken your money

I woke up on Saturday morning to an email ‘Backup Withholding Report’ telling me that a sizable chunk had been debited from my account (at a couple of minutes after Friday midnight).

They’d taken 24%.

  • Not 24% of my dividends – there hadn’t been any, that would have been $0.
  • Not 24% of my capital gains – that would have been a few $s, but fairly trivial.
  • 24% of my capital.

But, it was the weekend, so I had to wait for Monday (US time) to come around.

Meanwhile a trawl of the web didn’t turn up much solid information. This Reddit thread gave some glimmers of hope, but also raised the specter of the IRS holding my money for months-years, and lots of form filling to get it back.

The whole thing felt a bit like asset seizure, where my money was being accused of a (tax) crime, and would be held until I could prove its innocence.

I call support

Rob was very calm and helpful. He put me on hold to speak to the ‘tax and retirement’ team and came back to say that everything would be automatically refunded once my W8-BEN re-certification was complete. I asked why that was taking so long (as it used to be essentially instant) and he said that it was taking a few days to validate the uploaded docs.

Meanwhile…

I got a letter from E*TRADE ‘IMPORTANT: ACTION REQUIRED FOR YOUR TAX STATUS’ saying that my W-8 would expire on 31 Dec 2024, and if I didn’t re-certify:

your account may be subject to U.S. backup tax withholding of 24% on proceeds, dividends, and interest received in your account.

Oh, the irony :/

Also every time I signed into E*TRADE it was still nagging me to re-certify. It’s like I’d never completed the form (and there was no evidence that I had visible to me in my account).

Worked out in the end

About 6 days after the trade I got a notification that W-8BEN certification was complete. It was another couple of days before I got the ‘Withholding Reversal Report’ and the cash was back in my account and available for withdrawal.

Luckily I wasn’t in a huge hurry, and the various setbacks didn’t cause any particular problems (other than the worry and stress).

Could E*TRADE have done better?

I think so. At no point was I actually outside of W8 certification, so in my opinion they should never have taken anything from my account. It feels like a systems/process problem on their side that this happened at all.

Even if me starting the re-certification meant that they had to take money from my account, there could have been a much better explanation of why that was happening and what to expect. That would have saved me a bunch of worry. It would have saved them a support call.

It’s also telling of poor systems/process that the re-certification nag screens kept popping up even though I’d filled out the form.

What I’ll be doing differently if there’s a next time

  • Don’t mix up admin work with trading. If I’d waited until the money was safely out of my account before starting re-certification I’d have seen a nag screen on each login, but no real ill effects.
  • When offered the chance to download evidence take it. Don’t assume that you’ll be able to get to it later.

If Google’s brought you here

I’m sorry. It’s stressful. I hope things get straightened out. And I hope this might alleviate some of the panic. But do call support, your precise circumstances might be different; and also E*TRADE needs to feel some impact for how clumsily they seem to be handling this. Good luck…


Security researchers at the CISPA Helmholtz Center for Information Security have discovered a vulnerability they’ve called ‘GhostWrite’ that’s caused by a hardware bug in T-Head’s XuanTie C910 and C920 RISC-V CPUs. Vector extensions that are supposed to provide translation of virtual memory addresses to physical addresses don’t work, meaning that an attacker can gain access to the contents of memory and any attached devices. The bug was found using RISCVuzz ‘Differential Hardware Fuzzing’ tool, which the researchers describe in a paper (pdf). They also discovered ‘Halt and Catch Fire’ bugs in T-Head C906 and C908 CPUs that could be exploited for denial of service attacks.

Continue reading the full story at InfoQ.


July 2024

01Aug24

Pupdate

July (finally) brought some decent weather, at least for a bit, including our trip to the Lake District (more on that later).

Max and Milo paddling in Lake Windermere

Milo also had his first post chemo scan, which looked good (and got its own post).

Berlin part 2

After getting stranded in Berlin at the end of last month it was good to have a return trip for Fluttercon that was less eventful (at least on the travel front).

The conference was great, and it was fab to hang out with some of the leaders of the Flutter community, which remains one of the most friendly and vibrant I’ve come across. I particularly enjoyed the package maintainers summit, which was an ‘unconference’ within the conference where we got to discuss with Google product managers how to improve the pub.dev package ecosystem.

With two trips to Berlin in two weeks I took the opportunity to look up some of the folk I know who have moved there over the past few years, and it was interesting to get their insights from within what’s become one of the leading tech hubs in Europe.

No easyJet compensation :(

To further explain what happened on the day; earlier in the day intense thunderstorms over Berlin Brandenburg (BER) meant that our ground crew we not able to safely work, and as a result the airport authorities deemed it necessary to suspend all ground operations until the weather improved. The delays knocked on to the rest of the flights for that day. Unfortunately, This caused your flight to miss the curfew in Berlin Brandenburg (BER) and we had no option but to cancel your flight. We do take reasonable measures to avoid delays and cancellations to our flights by having replacement crews and spare aircraft available in our network. In the circumstances, these options were not possible as the cancellation to your flight was a direct result of adverse weather conditions.

I’m starting to wonder what the circumstances are when you do get compensation?[1]

Lake District (again)

After the last few years staying at Keepers Cottage it was time for a change. $daughter0 wasn’t joining us, as she was just getting started on her industry placement, and the in-laws weren’t up for it this year[2]. But Graythwaite has been so good that we decided to return to the smaller Dove Cottage.

It proved to be an ideal location for walks with the dogs, as we could do various circuits of the estate without ever touching a road. The car only left the drive three times over the whole week.

Great Internet connection

One pleasant surprise was a fibre based Internet connection. Past trips had got very indifferent ADSL, but having 150Mbps was hugely better than 2Mbps. The WiFi didn’t reach to the far end of the cottage (from the access point in the lounge), but that was fixed by deploying a travel router in the midway corridor.

Maps

I previously described the OS Maps app as ‘really good’, but sadly they’ve been tinkering with it, and the app user experience has declined badly. Dangerously bad. Waiting minutes for a map to appear when you’re planning a trip is super annoying. The same white screen with no map (as your battery runs down) whilst you’re outside trying to find your way is totally unacceptable.

It was also perplexing that the shiny new West Windermere Way doesn’t yet appear on the online map, making it invisible to those who don’t already know it’s there[3].

New sofa

The brown leather corner unit we’ve had since ’08 was beyond tired, with multiple holes in various places. But finding a replacement has proven trickier than expected. Fashions change, and it was really hard to get something that suited the aesthetic we wanted.

New sofa just after the delivery chaps put it together

The ‘Contempo’ in Pecan Brown felt like a least worst choice, but now it’s in place we’re pretty happy with it. It’s comfortable, the lighter colour lifts the room, and although we’ve lost a seat versus the previous configuration it’s got just as much space. The only thing we hadn’t considered is the higher back is harder for the dogs to get to, and more precarious once they’re up there (and an even more crazy leap if they choose to jump off).

Nc’nean

I first heard of Nc’nean when I received an offer to buy a couple of Batch 1 bottles, and I was impressed with their approach to building a modern whisky brand. I’d become a small time investor via the Seedrs EIS 100 fund, and the ‘Ainnir‘ maiden bottling was being offered to everybody who’d bought shares[4].

Nc’nean Ainnir – probably the prettiest whisky bottle I’ve seen

When I saw that there was a Nc’nean tasting coming up at the Scotch Malt Whisky Society (SMWS) it seemed like a good excuse to get some friends together, and they invited more friends, and in no time we had a huge group taking most of the tickets. Master distiller Matt took us through four different bottlings (including one that’s never been sold in the UK), and they were all excellent. His explanations for how they’re making such good whisky when the distillery is so young provided a great set of counterpoints to much received wisdom about whisky and what makes it taste nice.

I’ll be keeping an eye out for future releases, and my fingers are crossed for an SMWS bottling some time soon. Though for what it’s worth my favourite bottle on the night was their flagship ‘Organic Single Malt‘, which is widely available (e.g. from Amazon [affiliate link]).

ABS Sensor Replacement

On the way to drop off the dogs at kennels for EMFcamp (back in May) the ABS light came on in the XC60. My initial hope was a transitory fault, but it didn’t clear itself up. On the other hand, the car was driving just fine. Until the day I needed to take Milo to the vets for a scan, when it seemed to go into some kind of ultra-limp mode. It wasn’t safe to drive to the end of the street, never mind to the garage for a fix.

I’d already had a look at the fault codes with a reader, which pointed to the front drivers side ABS sensor. Sadly my initial attempt at removal failed completely. Though I was being too cautious, as I didn’t want to break the existing sensor (even though it had failed).

With a new sensor in hand (from eBay), and some YouTube guidance on removing stuck sensors I had a second try, and thankfully the fault is now cleared and the car is back in use (just in time for multiple runs to the tip with segments of the old sofa). The trick was to not be too bothered about breaking off the top of the sensor, as that clears the way to drill a hole then put a screw in, then the whole lot can be pulled out with a pry bar.

Solar Diary

This July was a slight improvement over last year. I also got the chance to clean off some of the panels that were looking a bit grubby.

592.8 kWh generated in July

The electricity generated for the month almost exactly matched what we used. Though there was still about 50% imported from the grid (and a similar chunk exported) as our usage doesn’t conveniently align with when the sun’s shining.

Notes

[1] Whilst I was waiting for my claim to be processed the news broke that the supreme court didn’t consider crew illness to be an ‘extraordinary circumstance’ that would absolve a carrier (in this case BA) from paying out.
[2] A decision that can now be filed as ‘just as well’ since my father in law had a stroke earlier in the month, and was in no shape to be driving the length of the country. Thankfully he seems to be improving as well as can be expected.
[3] Adding to the trouble is the top Google result for ‘West Windermere Way’ is the now outdated project page, which gives the impression that it’s still a work in progress.
[4] I suspect that I’ll see a much better return on the unopened bottle I’ve kept than I’ll ever get from my tiny shareholding. But I’m also glad I opened one, as it’s amazing whisky, especially considering it was bottled at the minimum 3y old.


What?

Let’s get the terminology cleared up. This post is about:

  1. Software Bill of Materials (SBOM) – the idea that you write down what’s inside the software you’re shipping (in a standarised form) so that people can figure out what vulnerabilities might be in there and make risk decisions based on that insight.
  2. Supply-chain Levels for Software Artifacts (SLSA) “salsa” – creating attestations from the build process to show that things haven’t been tampered with.
  3. Open Source Security Foundation (OpenSSF) Scorecards – a set of checks with accompanying badges and visualisation to show that a range of security practices are being adhered to (showing that you care about security).

None of these things stands alone, they’re all interlinked; and they certainly complement each other – a tripod is more stable than a pole.

SBOM

My earliest memories of the topic of supply chain security come from conversations with Josh Corman a little while after he founded I am the cavalry in 2013. He was taking a sabbatical from Sonotype to work on putting a bill through congress that would mandate SBOMs for stuff bought by the US Federal Government. There were two ideas at the core of this:

  1. Nobody would want to sell software with known vulnerabilities to Uncle Sam (because procurement officials would push hard on pricing for stuff with such defects).
  2. US government is one of the largest buyers, so if they’re getting SBOMs then for most products the work is done already and everybody else can benefit.

This eventually (in 2021) turned into Executive Order 14028 “Improving the Nation’s Cybersecurity“, and now lies at the heart of work being done by the Cybersecurity & Infrastructure Security Agency (CISA)[1].

Easy level – modern languages

Most modern languages use a package manager that creates a lock file, describing (in detail) the dependencies used by a piece of software. It’s relatively trivial to transpose the contents of that lock file into an SBOM expressed as SPDX or CycloneDX using tools like Syft. This is exactly what I’ve done for a bunch of Dart and Python stuff at Atsign, and I’ve little doubt I’ll be able to follow the same process for Java, Go, Rust and a bunch of other things we use.

Boss level – C

Things aren’t so straightforward with C (or C++). There’s no widely used package manager[2], so there’s no lock file to generate an SBOM from. I’ve been kicking the tyres on a few things that try to integrate with CMake; and logically the compiler and linker should know exactly what’s going in, though maybe not with the correct metadata to generate a good SBOM.

This is of course problematic. C/C++ is the centre of mass for software deployed in production. It’s also ground zero for most vulnerabilities, caused by a lack of memory safety.

SLSA

If SBOM is about the ingredients that go into a piece of software, SLSA is about making sure nobody sneaks anything else in there. The v1.0 spec defines three levels:

Track/LevelRequirementsFocus
Build L1Provenance showing how the package was builtMistakes, documentation
Build L2Signed provenance, generated by a hosted build platformTampering after the build
Build L3Hardened build platformTampering during the build

I initially envisaged an implementation process that would start by achieving L1 and progressively step up, but since we were already using GitHub Actions for Continuous Delivery it was pretty straightforward to jump straight to Build L3 (as GitHub provide the hardened build platform). All that’s needed is a little extra effort to get the provenance attestations out, which can be done with the slsa-github-generator action. This takes a bunch of file SHAs from the build process and mangles them into the multiple.intoto.jsonl file that carries provenance details that can then be verified[3].

Scorecard

Sticking with the ingredients/cooking analogy, Scorecard is the kitchen hygiene rating – a measurable way to show that diligent software practices are being used throughout the process.

I’ve written about ‘Implementing OSSF Scorecards Across a GitHub Organisation‘ previously (and spoken at a few conferences on the topic).

Much of the toil generated by getting a good score comes from dependency management, which of course relates to SBOMs. And there’s points on offer for signed releases, which can be measured (amongst other ways) by the presence of a SLSA attestation; so it’s in the Scorecard that the pieces of the supply chain security puzzle really come together to present a coherent picture to people who care about that software.

In some talks I’ve described Scorecard as a way to ‘show that you care about security’, and the various tables and charts that can be generated from a scorecard provide a very visual way to do that.

Bringing it all together

The SBOM can be signed in the SLSA attestation, which contributes to the Scorecard. That’s exactly what I’ve been pulling together for some of the key Atsign repos, and as it’s all open source[4] you can see for yourself how it’s done (and copy/paste into your own work as you see fit).

Notes

[1] Where it’s great to see friends like Allan Friedman keep going with the good work.
[2] People in the know have pointed me at Conan, but it’s early days in figuring out how that might help.
[3] It’s worth noting that GitHub’s Artifact Attestations achieves a similar outcome, and can be used in addition to the SLSA generator. Arguably Artifact Attestations provides much easier verification.
[4] Our OpenSSF Scorecards summary page provides a good entry point.