Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
DanielDent
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
Show HN: Use DNS caches as a side-channel to identify related network flows
(dnscookie.com)
1 points
by
DanielDent
8y ago
|
0 comments
32.
▲
by
DanielDent
8y ago
Until late last year that was their policy: https://blog.cloudflare.com/unmetered-mitigation/ Also they specifically refer to volumetric mitigation' as the thing which everyone gets. The harder to deal with attack
33.
▲
by
DanielDent
8y ago
Are there often significant issues that arise while Cloudflare is mitigating an attack? I've often wondered why people would conduct attacks if the attacks don't actually end up doing anything. The fact that somebody is protected
34.
▲
by
DanielDent
8y ago
One of the ways to get it working is to get more people using it... QUIC is implemented with a number of fallbacks to deal with broken networks, but at some point it's probably better to just let things break and force network operator
35.
▲
by
DanielDent
8y ago
I wrote my own take on this based on what I observed at their auction: https://www.danieldent.com/blog/ncix-able-auctions-bowra-gro...
36.
▲
NCIX, Able Auctions, and Bowra Group Data Breach
(danieldent.com)
3 points
by
DanielDent
8y ago
|
0 comments
37.
▲
by
DanielDent
8y ago
This seems like it might be a new "hello world" for devops-inclined people. I've authored a similar Docker image with less features: https://github.com/DanielDent/docker-nginx-ssl-proxy (Although lately
38.
▲
by
DanielDent
8y ago
Here are the three most significant problems from my perspective: (1) Cost - IP allocation isn't close to free, either in $ or in time/administrative overhead. (2) Technical Complexity - Using routing protocols like BGP is not cur
39.
▲
by
DanielDent
8y ago
Let's imagine a small business with two IPv6-capable ISPs & a router. They want to make effective use of their two links for load balancing & failover. There's not a chance that BGP is going to get set up or that their own
40.
▲
by
DanielDent
8y ago
Your response only furthers my point: if it doesn't show up on a marketing feature sheet, Gitlab doesn't seem to care to devote any resources to it. Adding new features is great, but making sure that the user experience around ex
41.
▲
by
DanielDent
8y ago
It really really would. And it's a very good thing that their product allows you to self-host, because I have zero-confidence in their ability to properly operate infrastructure. But the attention to detail/quality on the product
42.
▲
by
DanielDent
8y ago
Yes, client-side URL calculation and/or a whitelist of acceptable URLs would be a significant improvement. Thankfully command-line curl won't follow redirects unless you pass it a special flag, though if you do need it to follow r
43.
▲
by
DanielDent
8y ago
It's fairly standard for network clients to assume potential malicious control of the server they are connecting to. It helps reduce the blast radius of a compromised server. In the case where the server is operated by a third party (a
44.
▲
by
DanielDent
8y ago
B2's API design has security implications: https://www.danieldent.com/blog/restless-vulnerability-non-b...
45.
▲
The RESTLESS Vulnerability: Non-Browser Based Cross-Domain HTTP Request Attacks
(danieldent.com)
1 points
by
DanielDent
8y ago
|
0 comments
46.
▲
by
DanielDent
8y ago
Last I checked, DO still fails to allocate as little as a /64 to droplets. They provide a shared /64 out of which you are allowed to use 16 individual IP addresses. In IPv6 land, that can introduce a lot of pointless complexity. I
47.
▲
by
DanielDent
8y ago
Probably unrelated, but telus.net's SPF record appears to authorize RFC6598 ( https://tools.ietf.org/html/rfc6598 ) IP space: "v=spf1 ip4:199.185.220.0/24 ip4:198.161.157.0/24 ip4:198.161.156.0/2
48.
▲
by
DanielDent
9y ago
Florida has embraced open records laws, while other US jurisdictions have not - certainly not to the same extent. A significant portion of your observation can likely be attributed to reporting bias: it's easy/cheap for a journali
49.
▲
by
DanielDent
9y ago
It looks like RFC 7873 (May 2016) came up with a very different meaning for "DNS cookies" than I did in 2015. It's an unfortunate naming collision. My meaning: http://dnscookie.com/ RFC 7873 meaning: https:&
50.
▲
by
DanielDent
9y ago
On an iPhone 5S I have replaced both a cracked screen and an old battery. The replacement battery was ~$7 USD including shipping, while the replacement screen (all-in-one digitizer/glass/screen assembly) was ~$15.50 USD including
51.
▲
by
DanielDent
9y ago
The SkyTrain in Vancouver, Canada does not have drivers. It has been in service since it was built for the 1986 World Expo. Autonomous trains are not nearly as widespread as they could be, but this is not for technical reasons - it is for p
52.
▲
by
DanielDent
9y ago
LE "created" this issue in the sense that they were the first to formalize an implementable specification for automated verification of authorized domain name use. In comparison to the prior relatively unspecified approach to veri
53.
▲
by
DanielDent
9y ago
This spec may only be usable by provider issuing certificates they manage on behalf of their customers. It's possible the protocol is unusable on a shared IP address for customer-managed certificates. Even today, there are many hosting
54.
▲
by
DanielDent
9y ago
I think this issue can be described as a form of confused deputy problem. Is not the real solution to have the confused deputies stop acting in a confused manner? If this issue were confined to a handful of small hosting companies almost no
55.
▲
by
DanielDent
9y ago
Insurers are not charities. They price based on a risk model. A police department with frequent liability payouts can expect their premiums to be priced according to the risk they represent (assuming they are even able to find an insurer st
56.
▲
by
DanielDent
9y ago
Dark pools & other approaches which avoid sucking liquidity out of public order books are available. These allow larger trades to be done without affecting the market price.
57.
▲
by
DanielDent
9y ago
My submission was unnecessarily terse. Thank you for expanding upon it. I agree with all your points about OAuth2 clients. But I would also add: All clients (Amazon official or not) will ultimately need to have API keys compiled into them,
58.
▲
by
DanielDent
9y ago
rclone was blessed by Amazon. It was an official app developed by a developer using their official API. And now, without any warning, it is not. For many use cases, rclone is the only practical way of getting data in and out of Amazon Cloud
59.
▲
Amazon Cloud Drive is currently broken garbage
(github.com)
32 points
by
DanielDent
9y ago
|
12 comments
60.
▲
by
DanielDent
9y ago
Ubiquity's products do traffic analysis locally, as you propose. Their Edgerouter X is MSRP $49 USD.. It's based on Debian/Vyatta. On the router, without sending data to someone else's computer, it will give breakdowns b
More ›