Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Titanous
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
61.
▲
by
Titanous
10y ago
> Is there any plan to support plugins in a similar way to Dokku? Specifically the volume storage plugin has made deploying some apps that don't play nice with 12f stuff much easier. Flynn is natively highly available and multi-host
62.
▲
by
Titanous
10y ago
Both Dokku and Deis focus on stateless webapps. Dokku is explicitly single-host. Flynn can run in a single-host configuration but typically deployed in a highly available configuration with three or more hosts. Flynn is designed to tackle s
63.
▲
by
Titanous
10y ago
BOSH operates at a lower level, working with VMs. Flynn is higher level and allows deployment and management of applications and databases in containers. Instead of relying on a lower layer like BOSH, Flynn is self-bootstrapping and self-ho
64.
▲
by
Titanous
10y ago
Yes, you can run a privileged container that bind-mounts / on the host into the container. root.
65.
▲
by
Titanous
10y ago
My understanding is that in practice this is quite hard to do. As far as I know, none of the mainstream block-layer encryption systems (BitLocker, FileVault, dm-crypt) provide authenticated encryption. Here's a short thread about the p
66.
▲
by
Titanous
10y ago
In order to do filesystem encryption properly, it needs to be done at the file layer, not the block layer. Block-level encryption is not authenticated because there are no extra bytes to add the authentication tag. If a ciphertext is not au
67.
▲
by
Titanous
10y ago
NaCl is basically this, but as a library instead of copy/paste. It's available in most languages if you look around. https://nacl.cr.yp.to/index.html
68.
▲
by
Titanous
10y ago
Comodo's CEO has responded on their forums: https://forums.comodo.com/general-discussion-off-topic-anyth...
69.
▲
by
Titanous
10y ago
Correct, the executable code is unencrypted, the source code has not been released.
70.
▲
by
Titanous
10y ago
It's not particularly well documented, but the code is here: https://github.com/flynn/flynn/tree/master/controller/schedu... We've basically implemented the minimum viable system for our u
71.
▲
by
Titanous
10y ago
Tesla does have a bug bounty program: https://bugcrowd.com/tesla
72.
▲
by
Titanous
10y ago
No, you retain all of the properties of Tor hidden services: censorship resistance, authenticated end-to-end encryption, onion routing that hides your source IP. Obviously if you log into a Facebook account with your real-world identity the
73.
▲
1M People Use Facebook Over Tor
(facebook.com)
388 points
by
Titanous
10y ago
|
158 comments
74.
▲
by
Titanous
10y ago
The driver for the network offload is proprietary, however the pre-installed OS is Debian Linux with a fork of Vyatta.
75.
▲
by
Titanous
10y ago
No. Both BoringSSL and LibreSSL use substantially different (and safer) systems for their CSPRNG. https://boringssl.googlesource.com/boringssl.git/+/refs/head... https://github.com/libressl-po
76.
▲
by
Titanous
10y ago
There are a bunch of great unofficial clients, several written in Go (I like acmetool): https://www.metachris.com/2015/12/comparison-of-10-acme-lets...
77.
▲
by
Titanous
11y ago
I have worked with systems implementing 3D Secure and have multiple credit cards that trigger it. I can assure you that the standard deployment for US-based banks and merchants uses iframes and in the majority of cases will ask for enough p
78.
▲
by
Titanous
11y ago
3D Secure is a complete disaster. It encourages users to put ridiculously sensitive information like social security numbers and bank credentials into an iframe in the merchant site. This trains users to be phished.
79.
▲
by
Titanous
11y ago
Is the source code available? I don't see it at https://github.com/docker
80.
▲
by
Titanous
11y ago
Especially when crypto is involved. Given the large number of completely broken cryptosystems, making this open source will give it a fighting chance to not be entirely broken.
81.
▲
by
Titanous
11y ago
This is basically a worst-case scenario. The entire public Certificate Authority trust model depends on the validation of ownership of domains that certificates are being issued for. If an attacker can get a trusted certificate for facebook
82.
▲
by
Titanous
11y ago
The Texas public intoxication law is apparently very broad (you could be arrested without having had a single drink) and is apparently used to discriminate regularly: http://www.motherjones.com/politics/2010/03
83.
▲
by
Titanous
11y ago
The feature exists to protect against less sophisticated attacks. It's not necessary, as setting a long alpha-numeric passphrase will mitigate brute force attacks.
84.
▲
by
Titanous
11y ago
At that point they can swap out the flash chip for a new one, new chips can be obtained easily. Also, the PIN is 4 numeric digits, no alpha characters.
85.
▲
by
Titanous
11y ago
Yes, there are many reasons to deploy TLS everywhere, and everyone should be working towards it for these reasons: - Increased resistance to surveillance. Instead of seeing the pages/information that a client downloads from your server
86.
▲
by
Titanous
11y ago
This is not a duplicate. The post is about a new lawsuit filed due to the change in rules, the suit has not been previously on the front page.
87.
▲
by
Titanous
11y ago
It's not open source in the traditional sense of the term, though they have published the source code. The license is proprietary.
88.
▲
by
Titanous
11y ago
This looks neat, but the license is fatal. It is not "just like an open-source license." First, what is a "user"? It is not defined anywhere in the license. I did not look at the source code, because of the potential IP
89.
▲
by
Titanous
11y ago
Flynn co-founder here. We plan to expand to support many more popular open source databases next year (and expose a framework for others to do the same). The goal is that a supported database should "just work" on the platform and
90.
▲
by
Titanous
11y ago
The discovery URL is only used for bootstrapping, nothing will break if you specify IPs instead. They are interchangeable.
More ›