> Unfortunately, if you've used Google Takeout or other systems that can both downsample your photos and videos, as well as actually deleting _or changing_ metadata, deduplicating becomes a big wad of heuristics.
I thought takeout exported the original files? (alongside metadata entered into the application)
FWIW: That project was started as an internal tool with a playful acronym and then went from obscure to well-known enough to making renaming a somewhat regrettable concept rather quickly just due to momentum. I think we'd have named it differently if we were aiming for widespread usage :-)
We had no reason to worry about making it popular, the effort was staffed to improve developing Kubernetes itself.
Ok but the premise of physical harm in person comes from the parent comment, not mine:
"Most of those dependencies represents at least one human being who can be threatened with a crowbar and forced to ship an exploit, which can then infect vast numbers of production applications."
I suspect for a lot of projects reproducible builds are themselves a bit of a hurdle and not being verified in the rarer case that they already exist, but the point of reproducible + signed builds as indirect source-signing stands.
Those are interesting points / possible approaches, however is there any indication that this particular project enables any of that?
This seems focused on signing binaries / build artifacts.
IMHO it seems like if you have the threat model of "crowbared maintainer forced to insert backdoor" you probably don't trust sources let alone binaries and need to vet your dependency sources and then compile your own binaries from them.
Many open source dependencies will not have a jurisdictionally diverse review team, or any review team at all (single maintainer).
Those things don't have to be inherently slow and e.g. external IP don't need to block bring-up.
I've worked on KIND and on clusters on clouds (at Google, but on multiple clouds) and both can be very quick, if anything there's still low hanging fruit to make KIND faster that I'd expect a production service with more staffing to handle.
KIND is Kubernetes, typically on much weaker hardware :-)
Within a few minutes is a perfectly reasonable expectation even for "real"-er clusters, see e.g. under 4 minutes:
> Then there is the always present double standard. Why did Twitter allow “Hang Mike Pence” to trend last night? Where are the suspensions and permanent bans?
> Journalist Yashar Ali tweeted a screenshot of the topic trending, indicating that the phrase had been tweeted over 14,000 times. Ali noted that most people were "quot[ing] some of the insurrectionists" at the Capitol, rather than making direct threats against Pence. He wrote that the phrase "shouldn't be allowed to trend."
> “We blocked the phrase and other variations of it from trending. We want trends to promote healthy discussions on Twitter,” a company spokesperson told The Post. “There are Rules for trends — if we identify accounts that violate these rules, we’ll take enforcement action.”
I thought takeout exported the original files? (alongside metadata entered into the application)