Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
allset_
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
91.
▲
by
allset_
5y ago
Also, in future implementations it would be possible for security conscious publishers to attach cryptographic attestations produced by trusted third party hardware manufacturers to their signature demonstrating the private key was generate
92.
▲
by
allset_
5y ago
You have to be in person for that attack, which is a much higher cost than taking over someone's account remotely from a different country. It's also a much higher risk of getting caught and going to jail.
93.
▲
by
allset_
5y ago
Other management tasks are easier when you have separate clusters, such as applying environment-specific OPA policies and not having to filter them based on labels or annotations you hope everyone is using correctly.
94.
▲
by
allset_
5y ago
Almost all of the ransomware gangs now also exfil data and use that as additional leverage.
95.
▲
by
allset_
5y ago
Most attack campaigns start with compromised credentials, so MFA absolutely helps prevent ransomware.
96.
▲
by
allset_
5y ago
In Seattle (a couple years ago at this point) the highest lease break fee I saw was 1/2 month which already seemed quite high to me. 1.5x seems crazy.
97.
▲
by
allset_
5y ago
Except 99% of people wont accept month to month due to the instability.
98.
▲
by
allset_
5y ago
It's a layer you need regardless, it's not unique to Kubernetes.
99.
▲
by
allset_
5y ago
Agreed. Long(er) lived refresh tokens, and then having signed access tokens such as JWTs so that the API server doesn't have to hit the database on every request.
100.
▲
by
allset_
5y ago
It seems publishing to https://sigstore.dev/ and having your update agent use that would be a solid starting point for smaller developers.
101.
▲
by
allset_
5y ago
You do need a fairly recent version of OpenSSH though.
102.
▲
by
allset_
5y ago
It's not specifically a React thing, but JavaScript enables it. Lazy-loading content is a good idea if you're building dynamic web _applications_, as common components (buttons, modals, etc.) don't need to be reloaded over an
103.
▲
by
allset_
5y ago
I don't like Jira that much, but this is just blatantly false. > A cache-less refresh for me on a blazing fast dev machine takes between 3-10 minutes on a normal day, though it might only take 1m if the internet gods are feeling par
104.
▲
by
allset_
5y ago
Seems like the ideal use case for a hardware-backed token to be issued to each citizen to hold a private key and use MFA (PIN) to unlock that.
105.
▲
by
allset_
5y ago
It's true in the US. If someone manages to steal your debit card data and your PIN, all the banks say "well your PIN was used, so it must have been you" and you're SOL.
106.
▲
by
allset_
6y ago
What horrible carrier is that? Even in the US which has high cellular data costs it's usually $10/GB
107.
▲
by
allset_
6y ago
USB mass storage based authentication also does not protect against malware stealing the keys. A YubiKey (or similar token) performs all of the cryptographic operations in a separate environment that malware cannot access.
108.
▲
by
allset_
6y ago
Agreed. Having your lowest tier offering priced at over $500/mo is cost prohibitive in a lot of situations. Even their "dev" tier is $130/mo for a single instance. It would be much nicer if they just let you choose how m
109.
▲
by
allset_
6y ago
My S8 just received a security update a couple weeks ago, which puts it at over 3 years of updates. It's stuck on Android 9 though.
110.
▲
by
allset_
6y ago
This has gotten _a lot_ better since Google started contractually requiring OEMs to provide regular updates. My Galaxy S8, purchased through a carrier, is still receiving security updates (although probably not for much longer).
111.
▲
by
allset_
6y ago
I just looked to price one on their website, and it starts with some absurdly low specs including a 128GB SSD and a horrible 1366x768 TN screen for $1140. This is not acceptable in 2020.
112.
▲
by
allset_
6y ago
Any info about what domain is being visited would be client side, which could be easily changed.
113.
▲
by
allset_
7y ago
Google Meets has this as well, don't Zoom and others?
114.
▲
by
allset_
7y ago
It's odd they don't list OPA Gatekeeper, which is probably the best tool for enforcing security and other best practices in Kubernetes clusters. List of CNCF open source security projects without the blog post: https://
115.
▲
by
allset_
7y ago
I believe this is the right way to think about it. You can start off with a relatively monolithic architecture, and then break that out into smaller microservices as needed with a much easier transition.
116.
▲
by
allset_
7y ago
This is the work from home day each week.
117.
▲
by
allset_
7y ago
>or to make sure you're getting work that doesn't touch on the right metrics. What? The metrics should be distilled from the overall company/org/team goals and mission and if you're working on things that don
118.
▲
by
allset_
7y ago
XPS 13 Developer edition meets these requirements. The touch pad isn't as good as a MacBook (none are) but it's plenty sufficient for working when not at a desk and if you do Docker based development having a Linux OS is actually
119.
▲
by
allset_
7y ago
AFAIK, the POWER architecture consumes a lot of energy so it's not suited for mobile and/or embedded gadgets so it's not as appealing to the masses.
120.
▲
by
allset_
7y ago
Depending on where you live, your neighbors recording audio may be illegal and you should confront them about it https://www.southerncaliforniadefenseblog.com/2018/04/do-rin...
More ›