Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
eeZi
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
61.
▲
by
eeZi
10y ago
> FreeBSD has for years had some features that are only now reaching 'mainstream' popularity It's also lacking a bunch of features that reached "mainstream popularity" a long time ago. Example: ASLR, the most imp
62.
▲
by
eeZi
10y ago
Nope no ASLR. They're working on it but not yet.
63.
▲
by
eeZi
10y ago
Yes, the log is static. It only contains the subject name if the certificate. But there's little to fear from exposing internal domain names. DNS names are more or public knowledge - they are transmitted unencrypted, end up in plenty o
64.
▲
by
eeZi
10y ago
Yes, check_mk is great. I rolled out a 30000+ checks installation on a single server today. I've looked at most monitoring products on the market and check_mk easily wins. It's really popular in Germany, many huge companies are us
65.
▲
by
eeZi
10y ago
Firefox is significantly less secure though. Chrome has its sandbox and a highly effective XSS auditor. Firefox has neither. I do not appreciate this change, however, and I hope that they reconsider it.
66.
▲
by
eeZi
10y ago
I have location history turned off, yet it still shows me previous destinations (thankfully, I like that one).
67.
▲
by
eeZi
10y ago
Note that most BSDs (with the notable exception of OpenBSD, of course) lack modern anti-exploitation features like ASLR. FreeBSD is working on it, but it took surprisingly long.
68.
▲
by
eeZi
10y ago
Windows Docker is just around the corner!
69.
▲
by
eeZi
10y ago
For Python, you can just use Pyrasite ( https://github.com/lmacken/pyrasite ) and inject a script which prints a stack trace for all threads. I've done this to debug OpenStack in the past and it worked very well. Th
70.
▲
by
eeZi
10y ago
You can disable the remote management and the entire embedded network stack though.
71.
▲
by
eeZi
10y ago
They'd backdoor your machine instead. Same result.
72.
▲
by
eeZi
10y ago
On Thinkpads at least it can be much longer.
73.
▲
by
eeZi
10y ago
It does actually encrypt your data, and if it's correctly implemented, it's fine. Those drives sell for a few years now and not a single exploit is known. For most people this is more than enough.
74.
▲
by
eeZi
10y ago
The Python foundation won't budge on the 2020 EOL date, for sure. RedHat will support it until RHEL 7 is EOL (~2027), but that's security/critical fixes only - while Python 3 gets all the new features and development efforts
75.
▲
by
eeZi
10y ago
It is NOT a different language. It's not backwards compatible, sure, but usually, only minor changes are required and 2to3 helps a lot. At this point, pretty much all of the libraries are ported and their API stays the same. The librar
76.
▲
by
eeZi
10y ago
Nah. I'm a long-time Python developer (10 years+) and I moved everything over to Python 3 because there are so many advantages. This includes a number of massive internal code bases that I maintain at my day job. Porting is surprisingl
77.
▲
by
eeZi
10y ago
A few reasons which made me switch: - Python 2 will be EOL in 2020, that's four years - vastly improved Unicode support - a number new libraries are Python 3 only - asyncio and the new async syntax - exception chaining
78.
▲
by
eeZi
11y ago
Just use Phabricator! It's the best code review system I've used so far. Many large open source projects and companies have adopted it. Someone neatly wrote up the main advantages: http://cramer.io/2014/05
79.
▲
by
eeZi
11y ago
How does this compare to Autobahn / crossbar.io? http://autobahn.ws/ http://crossbar.io/ I really like the service discovery in Crossbar ("routed RPC").
80.
▲
by
eeZi
11y ago
> Another thing that was missed was that Lennart wasn't being unreasonable, nor was he saying it wasn't a problem (he specifically stated the opposite, in fact). I had a feeling at the time (based on his responses) that the rea
81.
▲
by
eeZi
11y ago
If you mount to r/o, a bunch of userspace applications break. Mounting it r/w is correct.
82.
▲
by
eeZi
11y ago
You should take a look at Phabricator, then: http://phabricator.org/ It has more features than Gitlab, anyway.
83.
▲
by
eeZi
11y ago
Good advice, except the "remove all system passwords" part. Do not do this. It's a really bad idea. There are occasions where you do need to authenticate using a password, most importantly on the local console - what if you
84.
▲
by
eeZi
11y ago
There's nothing in PCI which prevents the use of SSH keys. In no scenario is password auth more secure than key auth.
85.
▲
by
eeZi
11y ago
Then the VPN breaks, and you're out of luck.
86.
▲
by
eeZi
11y ago
For interactive data analysis, this is one very nice iPython library: https://github.com/catherinedevlin/ipython-sql Bonus points for native Pandas integration.
87.
▲
by
eeZi
11y ago
Even wget can (and does) have critical vulnerabilities: https://community.rapid7.com/community/metasploit/blog/2014/...
88.
▲
by
eeZi
11y ago
Why would I use it instead of SQLAlchemy? Simplicity?
89.
▲
by
eeZi
11y ago
Well there are use cases where you'd want to remove an EFI variable.
90.
▲
by
eeZi
11y ago
If they changed it to "ro" by default, people would complain as well if it breaks something.
More ›