Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ejcx
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
Pql, a pipelined query language that compiles to SQL
(pql.dev)
262 points
by
ejcx
3y ago
|
131 comments
32.
▲
Pql, a pipelined query language that compiles to SQL (written in Go)
(blog.runreveal.com)
4 points
by
ejcx
3y ago
|
0 comments
33.
▲
Introducing Detection of Tor Exit Nodes
(blog.runreveal.com)
2 points
by
ejcx
3y ago
|
0 comments
34.
▲
The history of centralized logging
(blog.runreveal.com)
2 points
by
ejcx
3y ago
|
0 comments
35.
▲
Announcing impossible travel detection for all customers
(blog.runreveal.com)
25 points
by
ejcx
3y ago
|
9 comments
36.
▲
by
ejcx
3y ago
I have a similar program I run that does this stuff for United flights: https://github.com/ejcx/uwc/blob/master/uwc.go The code is horrendous but it has worked for years and I guess when I wrote it origi
37.
▲
by
ejcx
3y ago
I hate to shill in this thread, but that's exactly what we built at runreveal, so I completely agree! We saw the power of clickhouse when we were at segment and cloudflare, so built a company around it. And since clickhouse is open sou
38.
▲
by
ejcx
3y ago
Founder of runreveal here, if anyone is interested let me know. The news today was big, but not necessarily too surprising.
39.
▲
Own your security data with RunReveal. Announcing bring your own database!
(blog.runreveal.com)
3 points
by
ejcx
3y ago
|
0 comments
40.
▲
The 5 must have AWS security alerts
(blog.runreveal.com)
2 points
by
ejcx
3y ago
|
0 comments
41.
▲
by
ejcx
3y ago
The json parsing library that parses the config file allows either syntax. That was intentional since we get in the habit as go programmers of ending lines in structs/maps with commas, it's just for convenience.
42.
▲
Kawa: The Event Processor for the Grug Brained Developer
(blog.runreveal.com)
35 points
by
ejcx
3y ago
|
18 comments
43.
▲
We achieved SOC2 Type 1 in record time and you can too
(blog.runreveal.com)
3 points
by
ejcx
3y ago
|
0 comments
44.
▲
by
ejcx
3y ago
Happy wazero user here in production. The team supporting the project has been really helpful and it's a very solid project.
45.
▲
Level Up Your Startup Security
(blog.runreveal.com)
2 points
by
ejcx
3y ago
|
0 comments
46.
▲
by
ejcx
3y ago
I'm happy you fixed it. I would have nearly lost my mind too. Hopefully figuring out the issue and fixing it is as rewarding as the problem was maddening
47.
▲
by
ejcx
4y ago
That's not necessarily how I feel, but I think it's a possible explanation for the way Magnus feels.
48.
▲
by
ejcx
4y ago
There have been instances in chess where cheaters get caught and they receive light bans and many top players say the punishment is too weak. It's intuitive, if you've been caught cheating then you should be banned from competiti
49.
▲
by
ejcx
4y ago
Where's the lack of consistency? They do it once per year, but have the option to do it more and aren't limited to once per year. One is clearly a policy, while the others are written not in legalese.
50.
▲
Replay.io Achieves SOC2
(medium.com)
1 points
by
ejcx
4y ago
|
0 comments
51.
▲
by
ejcx
4y ago
What was missing was the server side ownership check. We decide which customer owns the real "example.com" which is very battle tested logic, but had missed the check in this new service. The client side validation is expected too
52.
▲
by
ejcx
4y ago
I lead Product Security at Cloudflare, thanks for the writeup Albert and the fantastic security research throughout the past year. Once this issue was fixed we investigated all prior email routing configurations to ensure that this had only
53.
▲
by
ejcx
4y ago
I lead Product Security at Cloudflare (and I'm one of Albert's biggest fans, he's contributed a lot to our bug bounty, thank you Albert). Once he reported the issue we investigated all prior email routing configurations to en
54.
▲
by
ejcx
5y ago
(I work at Cloudflare). You can sign up just a subdomain (sub.foo.xyz) as an enterprise customer and then add an NS records from your DNS provider to Cloudflare for that subdomain. Tunnels also has a testing domain you can use. It should gi
55.
▲
by
ejcx
5y ago
Yes, you do in fact need CORS to set the arbitrary header in the example if it's even possible to send from a browser. I suppose it might be possible to send as `HELP xss:` which is close Like you said, you can send requests, but not t
56.
▲
by
ejcx
5y ago
In the example image, why is ftp.bank.com:990 responding with CORS HTTP headers allowing attacker.com to establish a cross origin connection? The whole thing seems a bit impractical to me.
57.
▲
by
ejcx
6y ago
Congrats on the launch. As someone who has used this and denied it the product has a ton of potential
58.
▲
by
ejcx
6y ago
(I work at Cloudflare and manage the Product Security team, so...disclaimer). WAFs definitely help. No WAF is perfect, but having an additional layer to make exploitation harder, and having a tool designed to block specific attacks (like wh
59.
▲
by
ejcx
6y ago
Nothing changes. No matter what certification, there’s a scope of what parts of the business and product are in and out of scope of the audit. Fleetsmith having SOC2 doesn’t bring the rest of Apple into scope
60.
▲
by
ejcx
6y ago
Mission Bay apartments were built after 1979 (or whatever the exact date is). It's all new construction, which isn't subject to rent control: https://www.sftu.org/rent-control/
More ›