Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
_wldu
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
_wldu
4y ago
I agree with your suggestion. I think Post Offices, DMVs, and large reputable retailers (Walmart, Target, Cellular Phone companies, etc.) could verify our identities for a small fee and help us reset our social accounts when needed. I arriv
32.
▲
The Defcon Password Cracking Contest
(contest-2022.korelogic.com)
2 points
by
_wldu
4y ago
|
0 comments
33.
▲
by
_wldu
4y ago
That looks like nftables (the successor to iptables).
34.
▲
by
_wldu
4y ago
Here's a landlock wrapper for FireFox: https://github.com/62726164/misc/tree/main/go/landlock/firef... It's more restrictive than Firejail and is not suid.
35.
▲
by
_wldu
4y ago
If you are not modifying/editing the files (just reading them) and you run Linux, then do this: 1. Don't allow users to sudo. 2. chmod the files to 400 (read-only) as the normal user. 3. chattr +i the files (as root) to prevent mo
36.
▲
by
_wldu
4y ago
It's been my experience that IT management want to see metrics and dashboards for everything. The want to be able to plan, allocate resources, and justify purchases and staff. How many of these did we do, how many of those, how long di
37.
▲
by
_wldu
4y ago
Be clear on what is expected. Have weekly deliverables and weekly team meetings. Don't micromanage them or have them meet each day. Get them off to a good start (give them all the gear and info they need to do the job) and be very expl
38.
▲
by
_wldu
4y ago
Maybe he works for a company that does US government research? Maybe they require NIST approved algorithms. I'm pretty sure that would prevent the use of Age for file encryption.
39.
▲
by
_wldu
4y ago
Use the DNS: https://www.go350.com/posts/age-file-encryption/#age-pki-iss...
40.
▲
See SSL certificates as they're issued in real time
(certstream.calidog.io)
1 points
by
_wldu
4y ago
|
0 comments
41.
▲
by
_wldu
4y ago
IGA is a supermarket chain. Granted, it's like the older, smaller ones (it's not a Walmart Jumbo Center) but it's still a supermarket.
42.
▲
by
_wldu
4y ago
I attended a USENIX LISA conference a few years ago in Seattle. I met a lot of people and saw a lot of demos. Before I went, I thought Facebook was a joke. After the conference, I was convinced they were doing large systems better than any
43.
▲
by
_wldu
4y ago
I drink instant coffee from Walmart. It's cheap and effective. I actually like the taste too.
44.
▲
by
_wldu
4y ago
I go into the office daily and it's now quieter than my house! There's hardly anyone there. I get more done due to less chit-chat.
45.
▲
by
_wldu
4y ago
I'd be hesitant to consume this in a firewall or DNS RPZ. What if someone reported google.com as malicious?
46.
▲
by
_wldu
4y ago
I no longer use Tor either (unless I have to for work projects such as remote pentesting). What is you opinion of Landlock (Linux kernel 5.13 and newer)? If we wrap vanilla FireFox in LandLock, proxy that to tor and use Apparmor/Tomoyo
47.
▲
by
_wldu
4y ago
Thanks for that info. That's unfortunate.
48.
▲
by
_wldu
4y ago
Does anyone know if Red Hat enabled landlock in this release? The kernel supports it since 5.13 and they are running 5.14. The kernel config should look something like this: CONFIG_SECURITY_LANDLOCK=y CONFIG_LSM="landlock,lockdown,yama
49.
▲
by
_wldu
4y ago
Everyone should PGP sign their git commits with a secret key stored on a YubiKey. Make small changes to your code, read the diff, then commit and sign before pushing to the repo. IMPO, that's really the only way to protect the integrit
50.
▲
by
_wldu
4y ago
They care deeply about software security and memory flaws (everyone should). If rust had an ISO standard, then it could be used in more sensitive military and aerospace systems. https://www.stroustrup.com/JSF-AV-rules.pdf A
51.
▲
by
_wldu
4y ago
Once rust stabilizes, I think it needs an ISO standard like C and C++ have. I can't see automobile manufactures using rust without one. One reason C and C++ are still widely used is due to this. When we are writing code that is expecte
52.
▲
by
_wldu
4y ago
Who needs to send 20,000 emails per hour? Other than spamming people, who actually needs to do that?
53.
▲
by
_wldu
4y ago
So when organizations hire people that do not understand the DNS or PKC to maintain their DNS then it is the organization's fault (rather than the person who made the change). I accept that and agree.
54.
▲
by
_wldu
4y ago
DNSSEC is notorious for breaking things [1]. I use it on most of my domains, but I would not just 'enable' it on a domain that I cared about and that had real users without a lot of thought and planning. Nor should you. [1] - htt
55.
▲
The Linux Kernel Backdoor Attempt of 2003
(freedom-to-tinker.com)
3 points
by
_wldu
4y ago
|
0 comments
56.
▲
by
_wldu
4y ago
Thank you! And, yes, I agree. I don't want FireFox or Chrome reading ~/.ssh or ~/.gnupg or any other directories in my home that it has no business reading. Maybe one day we'll have web browsers that don't have any
57.
▲
by
_wldu
4y ago
I firmly believe that isolation is the future of endpoint security and I like experimenting with Mandatory Access Control (MAC) on Linux. Tomoyo is my favorite major MAC/LSM in the Linux kernel. If you have a newer kernel (5.13 or grea
58.
▲
by
_wldu
4y ago
I always ask what is your favorite language and why. And I've never laughed at the answer. I'm genuinely curious to know why they feel that way. I've learned a lot from the answers (about the candidate and about the language
59.
▲
by
_wldu
4y ago
I work on-site and from home. There are pros and cons to each. Some people prefer one or the other. A hybrid solution is probably best, but I can do either or both. Each side has valid arguments (empty office space, office rent cost, lack o
60.
▲
by
_wldu
4y ago
Yubikeys are awesome. I have a copy of a signing only PGP key on a Yubikey and I use it to sign all of my git commits. Easy and very secure. Cheap too.
More ›