Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
__jf__
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
__jf__
6y ago
Trust boundaries make most sense when used in a data flow diagram, where for every flow between processes you ask yourself: “what could go wrong here?” That question deserves additional attention if these flows reach processes controlled by
32.
▲
by
__jf__
6y ago
I like the fact that malware authors also seem to have trouble setting up a (secure) software development lifecycle. On the other hand if they were to threat model it, expoiting weaknesses in the agent does not cross a trust boundery so why
33.
▲
by
__jf__
6y ago
S3 Glacier Deep Archive in a tar.gz.aes per calendar year.
34.
▲
by
__jf__
6y ago
That article is a gem! Thanks! The author - a surgeon - describes his experience asking and getting a retired surgeon to coach him for self-improvement purposes. It works out really well although he does mention some minor uncomfortableness
35.
▲
by
__jf__
6y ago
This is a fascinating peek into the unglamourous administrative moving parts of supply chain risk management. Octave [0], Cygwin [1] and GIMP [2] mailing lists were also fortunate enough to be included in this process. Given the timespan be
36.
▲
by
__jf__
6y ago
Also did lots of things that didn’t scale!
37.
▲
by
__jf__
6y ago
The NYT experience is indeed the fastest way for a company to lose trust. It took me 3 tries to cancel. First rep said: yep cancelled all done. Except it wasnt: renewed at a discount. The 2nd rep: said sorry sorry and produced a chat transc
38.
▲
by
__jf__
6y ago
There is an interesting talk [0] by Philipp Krenn (Elastic) on “Open Source as a Business. Strategy, struggle, success”. This talk takes the perspective of Elastic, the company behind the open source products Elasticsearch, Kibana, Beats,
39.
▲
by
__jf__
6y ago
There should be a CIS [0] hardening guide for LinkedIn like there is for iOS, Safari and AWS. [0] https://www.cisecurity.org/cis-benchmarks/
40.
▲
by
__jf__
6y ago
These 2 worlds increasingly overlap. For example the collateral damage of the 2017 NotPetya cyberattack made tens of multinational companies disclose material impact to their P/L. The retaliatory DDoS attacks following the Iran sanctio
41.
▲
by
__jf__
6y ago
“Using Internet scanning, we found a unique signature associated with the hostnames of Check Point firewalls used in Circles deployments. This scanning enabled us to identify Circles deployments in at least 25 countries.” Nice OSINT find!
42.
▲
Ask HN: How does your org deal with supply chain risk?
1 points
by
__jf__
6y ago
|
0 comments
43.
▲
by
__jf__
6y ago
Thanks for the rabbit hole. It made me discover an interview [0] with Googles captain of moonshots. In it he also discusses other interesting moonshot management strategies, besides the monkey-pedestal one. [0] https://www.wsj.co
44.
▲
by
__jf__
6y ago
Decibels. 35 at home, 55-60 at the (open) office.
45.
▲
by
__jf__
6y ago
Maybe I’m overdoing it but like true Bayesians mine just don’t believe me anymore. Instead they will just believe troll stories from others.
46.
▲
by
__jf__
6y ago
Phase six-a: The open-source license disillusionee Your project didn’t just scratch your own itch, but also that of a powerful large commercial entity. It copied your permissively licensed mouse trap into its moneymaking SAAS machine. You s
47.
▲
by
__jf__
6y ago
Better late than never, says the optimist. If you break these numbers down by industry it looks like climate risk is primarily identified by (european) financials. Fiscal 2019: US EUR APAC financls 12% 37% 16% energ
48.
▲
by
__jf__
6y ago
Source: own research after collecting and processing 14000 annual reports the last 2 years. Mostly for infosec purposes but it seems to be useful in other areas as well.
49.
▲
by
__jf__
6y ago
Meanwhile, awareness/disclosure of climate risk is rising sharply in large publicly traded companies, measured by counting the percentage of companies reporting "climate risk" in their 2019 annual reports: - 26% of companies
50.
▲
by
__jf__
6y ago
Yep from $99M to $65M to $18M. From their 2019 annual report: In July 2019, the ICO issued a formal notice of intent under the U.K. Data Protection Act 2018 proposing a fine in the amount of £99 million against the Company in relation to t
51.
▲
by
__jf__
6y ago
From their 2018 annual report: To date, we have not seen a meaningful impact on demand as a result of the Data Security Incident. In 2018, we recorded $28 million of expenses related to the Data Security Incident, partially offset by $25
52.
▲
by
__jf__
6y ago
TLDR from the article: “I’m not here to teach you how to write a Hollywood movie,” McKee said, the scorn in his voice sending a wave of reassurance through his well-educated audience. But then he drew a triangle on an overhead projector sl
53.
▲
by
__jf__
6y ago
Yep that pottery class also comes up as an anecdote in “Art and Fear: Observations on the perils and rewards of artmaking”: https://www.amazon.com/Art-Fear-Observations-Rewards-Artmaki...
54.
▲
by
__jf__
6y ago
Envy is ignorance, imitation is fear. Fear is the mind-killer. - Ralph Waldo Herbert
55.
▲
by
__jf__
6y ago
The blog post seems like a more applied, personalized and re-imagined version of "How to read a book". And shorter. I quote like it too.
56.
▲
Sonia Marciano – Strategy and Enterprise Value
(vimeo.com)
1 points
by
__jf__
6y ago
|
0 comments
57.
▲
Detecting APT29: MITRE EDR evaluations round 2
(medium.com)
5 points
by
__jf__
6y ago
|
0 comments
58.
▲
by
__jf__
7y ago
“Hi” initiates the TCP equivalent of the 3-way handshake
59.
▲
by
__jf__
7y ago
From the article: This check of Hive revealed quite a few defects and suspicious fragments. If the authors of Apache Hive come across this article, we'll be glad to help with the hard job of improving the project.
60.
▲
Comparing Evaluations of Endpoint Detection and Response (EDR) Solutions
(medium.com)
1 points
by
__jf__
7y ago
|
0 comments
More ›