Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
DanielDent
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
61.
▲
by
DanielDent
9y ago
I wrote about this a while back, and also proposed a solution which doesn't involve parsing console output: https://www.danieldent.com/blog/ssh-requires-a-chain-of-trus...
62.
▲
by
DanielDent
10y ago
This is precisely the conclusion Google reached and has used as they work on QUIC. Even protocol state (equivalents of TCP FIN/SYN/etc) is encrypted, to ensure that middleboxes don't get ideas about what the protocol is '
63.
▲
by
DanielDent
10y ago
There are still a lot of results with leaked data in Google's Cache and they are pretty easy to find.. Some possible queries: "CF-Int-Brand-ID", nginx-cache "Certisign Certificadora Digital", Once you find one, you
64.
▲
by
DanielDent
10y ago
The IPs seem to belong to Squarespace
65.
▲
by
DanielDent
10y ago
Meant to mention this earlier: Gitlab self-hosted actually has a built-in importer to import projects from Gitlab.com - including issues. It's mostly worked reliably in my experience (it's only failed to import one project across
66.
▲
by
DanielDent
10y ago
Ping me and we'd be happy to discuss hosted Gitlab for you.
67.
▲
by
DanielDent
10y ago
They could, and as a stopgap measure that might work, but.. (1) Some of the collaboration features (e.g. work on Gitlab itself) depend on having everyone on the same instance. (2) Gitlab.com gives them a nice dogfood-esque environment for w
68.
▲
by
DanielDent
10y ago
I'm a huge Gitlab fan. But I long ago lost faith in their ability to run a production service at scale. Nothing important of mine is allowed to live exclusively on Gitlab.com. It seems like they are just growing too fast for their leve
69.
▲
by
DanielDent
10y ago
A lot of stuff from this made it's way into the chromebook. There's a verified boot process, hardware assisted key management, rollback protection, ... And it's all open source and nicely documented for anyone who cares to lo
70.
▲
by
DanielDent
10y ago
Thank you for adding this detail... what you said makes WAY more sense to me now.
71.
▲
by
DanielDent
10y ago
Circuit breakers aren't just there for the amusement value of watching a clustered system go into split-brain mode... I.e. you would also want to be sure that your wiring was rated for 100% utilization, and that other circuit-breaker-l
72.
▲
by
DanielDent
10y ago
You can certainly do some math/estimates based on looking at individual component specifications, but I like using a power meter (built in to some PDUs - which is a feature worth having, or you can buy one, they are quite inexpensive).
73.
▲
by
DanielDent
10y ago
This is such a good example of the difference between Strongly typed and Stringly typed.
74.
▲
by
DanielDent
10y ago
It's an interesting idea, but attackers would switch to using javascript. And I don't think it's realistic for typical users to have javascript default off.
75.
▲
Own Your Identity. Join a Decentralized, User-Owned Internet
(about.qa2.com)
2 points
by
DanielDent
10y ago
|
0 comments
76.
▲
by
DanielDent
10y ago
I'd be happy to give it a try. I suspect rclone is the wrong tool for the job, but I haven't looked closely at the rsync.net service.
77.
▲
by
DanielDent
10y ago
It does seem to use S3 behind the scenes based on URLs I've seen. The data loss incidents I've seen reported have tended to be after outages. Amazon Cloud Drive seems to keep an index mapping amazon cloud drive filenames to S3 obj
78.
▲
by
DanielDent
10y ago
Rclone is great. I wrote an integration to use it with git-annex ( https://github.com/DanielDent/git-annex-remote-rclone ). Some of the supported providers (e.g. Amazon Cloud Drive) have a reputation for days-long servic
79.
▲
by
DanielDent
10y ago
(1) Cloudflare does do BGP-based protection (rerouting of a packet) on their enterprise tier. (2) They really aren't adding functionality into the network. If I put a cluster of Nginx servers in front of my web server, or if I have Clo
80.
▲
by
DanielDent
10y ago
I think we fundamentally agree. But I would point out a subtle distinction: I believe TCP/IP and DNS provide an adequate building block for what needs to happen in a backwards-compatible progressive enhancement way. I distinguish this
81.
▲
by
DanielDent
10y ago
But do they actually alter the architecture of the internet? Or rather, how is Cloudflare making things worse or substantially different? Example plausible flows in the life of a packet or HTTP transaction: Before: Packet goes Comcast->L
82.
▲
by
DanielDent
10y ago
There's a lot of different technologies and ideas that need to come together in an easy to use way. Three of the most important: * Blockchains * Protocol-level anti-DDoS changes (protocols specifically designed to make them less suit
83.
▲
by
DanielDent
10y ago
A pre-funding project I am working will achieve DDoS resilience without gatekeepers like Cloudflare, if I am able to bring it to market. It turns out that there's actually a ton of academic research on a number of very promising techni
84.
▲
by
DanielDent
10y ago
As a strong believer in the end-to-end principle, I don't understand what you mean. They have: * A reverse proxy service, open to anyone * A network-level traffic volume management system, open to those that can afford it I can come up
85.
▲
by
DanielDent
10y ago
So far Cloudflare appears to be acting in a non-destroying way. They take as content-neutral a stance as they can, and have had to defend lawsuits as a result of that stance. They recognize that the internet only functions and they can only
86.
▲
by
DanielDent
10y ago
I think these types of issues are why apple has started removing some of the encryption of the firmware itself.
87.
▲
by
DanielDent
10y ago
I'm not sure the distinction is likely to matter. A small number of sites which account for a significant chunk of all traffic, and many of those sites are compatible with non-legacy internet protocols.
88.
▲
by
DanielDent
10y ago
Quick plug for my related project: https://github.com/QA2/public-suffix-metalist - pull requests welcome.
89.
▲
by
DanielDent
10y ago
I wonder how this leak affects their "vulnerabilities equities process". The publicly available data would suggest that thus-far NSA-hoarded vulnerabilities are definitively known to actors who appear willing to act against US int
90.
▲
by
DanielDent
10y ago
I've seen photonic switching refer to a lot of different ideas. Sometimes it's just a remotely-controllable add-drop multiplexer. Does this type of photonic switching differ from CWDM/DWDM? Are routers putting the signal onto
More ›