Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
_wldu
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
41 ms
·
121.
▲
by
_wldu
5y ago
You should avoid ecdsa and use ed25519 instead. https://www.schneier.com/blog/archives/2007/11/the_strange_s...
122.
▲
by
_wldu
5y ago
If you setup Sqlite properly (Remote Clients <-> RESTful API <-> DB) and use WAL mode, you can run a DB backed website fairly cheap. It will be performant, reliable and simple to maintain as well.
123.
▲
by
_wldu
5y ago
They want us to be compliant, not secure: https://www.go350.com/posts/they-want-us-to-be-compliant-not...
124.
▲
by
_wldu
5y ago
Building applications is a complex problem. If you want a secure system, then security details have to be carefully considered at every layer (DB, API, front-end). Doing that requires expert security employees/consultants, time and mon
125.
▲
Attacks on Email Sender Authentication
(blackhat.com)
85 points
by
_wldu
5y ago
|
13 comments
126.
▲
by
_wldu
5y ago
If you use Tor, you should stop. I believe that it is mostly used by criminals and that it is largely ran by law enforcement agencies. I cannot prove this but I believe it is true. Simply using it makes you suspect. Also, if you have a need
127.
▲
by
_wldu
5y ago
I think the poster was joking about the effectiveness of the current IT security community (or ineffectiveness). "The Traffic Light Protocol (TLP) was created in order to facilitate greater sharing of information" . More info her
128.
▲
by
_wldu
5y ago
The military in the US is a great opportunity for young people (just out of high school) who can't afford college. They identify and promote talent. I know several ex Army guys who served and they are top notch people to work with. The
129.
▲
The Ultimate Persistence Bug Noreboot
(blog.zecops.com)
3 points
by
_wldu
5y ago
|
0 comments
130.
▲
by
_wldu
5y ago
Thanks for the links everyone. I wasn't aware of Crystal. I'll check it out.
131.
▲
by
_wldu
5y ago
If someone would combine the syntax of Ruby (it's fun to read and write) with the performance and static binaries of Go, I think it would be very popular. I would like to enjoy writing Go as much as I enjoy writing Ruby. But Ruby apps
132.
▲
by
_wldu
5y ago
Large corporate and government jobs are probably not available to you now. But, you can work for yourself as a consultant or contractor. There are pros and cons to being self-employed. Many people find it freeing, but maybe a bit less stabl
133.
▲
by
_wldu
5y ago
Blog post about the design flaws of password managers: https://www.go350.com/posts/the-design-flaws-of-password-man...
134.
▲
by
_wldu
5y ago
Interesting. I don't hear anything when I use the -a flag.
135.
▲
by
_wldu
5y ago
Here's my small webserver: #!/bin/bash while : ; do cat conference.txt | nc -l 80; done Here's the story behind it: https://www.go350.com/posts/finding-a-hacked-server/
136.
▲
by
_wldu
5y ago
I do agree that bug bounties are too small, but isn't selling bugs on the black market illegal? I would much rather get $40 dollars for a bug and some public acknowledgement (which I could use to get a better paying job) than to sell i
137.
▲
by
_wldu
5y ago
For signatures, I hope EdDSA wins out over ECDSA.
138.
▲
by
_wldu
5y ago
I wrote a short blog post comparing PGP and Age a few weeks ago. Some may find it of interest: https://www.go350.com/posts/age-file-encryption/
139.
▲
by
_wldu
5y ago
Try to always remember that bad things must exist so that good things can exist. Without bad things, we cannot have good things. This is called duality or inter-being in Buddhism. Take water as one example. It causes trees to grow that we u
140.
▲
by
_wldu
5y ago
IMPO, the only significant advantage of micro services and JS is client-side rendering. If you need to publish content to hundreds of millions or billions of clients, then that makes sense. But for most systems, a Linode VPS running Rails,
141.
▲
by
_wldu
5y ago
A MAC in enforcing mode would have prevented it.
142.
▲
by
_wldu
5y ago
It's a fundamental and systemic problem. We have a ton of software written in unsafe languages (C and C++). Our operating systems, web browsers, email readers, file editors, etc. Our governments and cyber-criminals have stock-piled 0-d
143.
▲
by
_wldu
5y ago
A LSM in enforcing mode (such as SELinux or Tomoyo) on a Linux system would prevent this. I configure and run tomoyo on all my Internet facing servers. https://tomoyo.osdn.jp/
144.
▲
by
_wldu
5y ago
This is a great demo. The old C compiler backdoor, but in Go: https://github.com/yeokm1/reflections-on-trusting-trust-go The Gopher Con Singapore (2018) video is a really great summary (20 mins). He modifies the compil
145.
▲
by
_wldu
5y ago
Same here and I use us-east-2.
146.
▲
by
_wldu
5y ago
Web security is completely broken. We have super complex web browsers (written in unsafe languages such as C++) that we try to secure by installing 'add-ons' and those have vulnerabilities that can steal our data. Who thinks this
147.
▲
by
_wldu
5y ago
I've done this in go. It's fun to do, but the real reason I did it was memory safety issues in C. We need to implement as much code as we can in memory safe languages.
148.
▲
by
_wldu
5y ago
The sooner we can rewrite our programs in Go and Rust, the more secure we will be. Our shells, coreutils, mail readers and web browsers have to be written in safer languages.
149.
▲
by
_wldu
5y ago
That makes me wonder if people are complaining about OpenPGP or instead about GnuPG? It probably doesn't really matter, but many newer encryption solutions ridicule PGP in general. Now I wonder if they mean to ridicule GnuPG instead?
150.
▲
by
_wldu
5y ago
PGP has RFCs (2440 and 4880) but people still complain about it. https://datatracker.ietf.org/doc/html/rfc4880
More ›