Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ejcx
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
17 ms
·
61.
▲
by
ejcx
7y ago
I'm a Cloudflare employee, so obviously biased (shilling incoming). Cloudflare Access is worth having on the list (and it's free right now [1]). It is a pretty flexible identity aware proxy, and ssh gateway. We use it internally f
62.
▲
by
ejcx
7y ago
Very good post. This ticks all the boxes on the fundamentals when spinning up a security program. SOC2 Type2 is really where you want to be, but it takes time. Navigating compliance for startups is pretty challenging and I see so many not h
63.
▲
by
ejcx
7y ago
I’ve never heard of Erdos Bacon numbers. My university professor Dr Tjaden pioneered the Bacon Number and it was a pretty obscure claim to fame he had. I’m guessing his Erdos Bacon number was 3+1=4. He appeared in a documentary with Kevin B
64.
▲
by
ejcx
7y ago
I've worked with both Josh and Cyrus at DevicePlane and can say I'm really looking forward to what these folks deliver. Really great engineering talent all around working on a solution to a non-obvious but hard problem that exists
65.
▲
by
ejcx
7y ago
This is probably the last thing to knock Cruise on. They've hired a lot, a lot, a lot of good people on the security front
66.
▲
by
ejcx
7y ago
Definitely a little cynical =]. I think the same thing about a lot of 3rd party security consulting. OpenVAS is free, but the big issue we've had with it is the complexity of setting it up and maintaining it. We are a security team, an
67.
▲
by
ejcx
7y ago
Yes it’s unfortunately standard for expensive scanners too. Our goal was to make something easy to run and deploy with similar results to something like openvas or Nessus. I personally think accuracy issues are because security vendors don’
68.
▲
by
ejcx
7y ago
This is really our use case. A little bit of packaging around a pretty good vuln scanner you can set up in 10 minutes I’ve managed Nessus in a past life and it was a nightmare.
69.
▲
by
ejcx
7y ago
Feel free to ask any questions you have. We have quite a few folks from Cloudflare's security team here.
70.
▲
by
ejcx
7y ago
350 people across a 25,000 person company sounds more like performance management than layoffs, especially since they are still hiring. I think Uber has way overhired but this doesn't seem to be the signal a lot of you all are making i
71.
▲
by
ejcx
7y ago
Cloudflare | Austin, TX | Security I'm looking to fill two roles on my team. We have a great security team and work in an environment where we are kind of in the middle of everything. Everyone at the company loves working with us and w
72.
▲
by
ejcx
7y ago
It's not rooted in reality and a gross oversimplification of the problem. GSuite is exposed to the open internet. Dropbox is exposed to the open internet. All of these services have permission models with "elevated access". 1
73.
▲
by
ejcx
7y ago
From the blog posts slack has released we know nothing about their security practices. They have a lot of high quality security features and you can see they actually work because they alerted Max that his account was compromised. Saying th
74.
▲
by
ejcx
7y ago
You can read our SOC3 (public facing SOC2) if you're curious about your availability question: https://www.cloudflare.com/compliance/ There's a lot of good info in there
75.
▲
by
ejcx
7y ago
Congrats Tejas!
76.
▲
by
ejcx
7y ago
Really interesting stuff here. The little cluster in North Carolina is "Amazon Wind Farm US East". I wonder if Amazon announces an electricity play soon, or if it's just related to sustainability efforts? Their use of wind is
77.
▲
by
ejcx
7y ago
There's more than one way to burn out. Some employees will push themselves to burn out. I know first hand.
78.
▲
by
ejcx
7y ago
You're correct. No js bloat. In order to load Js files it has to be in accordance with the AMP spec and they have a strict list of js you can load.
79.
▲
by
ejcx
7y ago
I don't think anything about Bowie or PG county is notable given its location. The entire DC area is propped up by the defense industry. Everywhere else in the country is really different. DC didn't even experience the 2008 great
80.
▲
by
ejcx
7y ago
Cloudflare | SF, SJ, Austin, London | Onsite | https://cloudflare.com Cloudflare's Security team is hiring a variety of different skillsets. We are looking for people who can take ownership over the security of specific par
81.
▲
by
ejcx
7y ago
Way to go Rick! You know you've made it when people write blog posts about your hot takes on Twitter
82.
▲
by
ejcx
7y ago
I'm not a C# expert by any means. Is the IntegrityHash of the plaintext, and not the ciphertext? https://github.com/nrosvall/ylva/blob/2a4afcfb3727151fa09fdd... That would be a really serious flaw. If n
83.
▲
by
ejcx
7y ago
The first thing I do whenever someone writes their own password manager is to read the Encrypt function. This one is AES-CBC with its own hand rolled integrity scheme. Not very strong by modern standards
84.
▲
by
ejcx
7y ago
Cloudflare | SF, SJ, Austin, London | Onsite | https://cloudflare.com Cloudflare's Security team is hiring a variety of different skillsets. We are looking for people who can take ownership over the security of specific par
85.
▲
by
ejcx
8y ago
Cloudflare's Security team is Hiring. We are hiring across all of our security teams. Program Management, Edge Security, Infrastructure Security, and Product Security. Our security team works closely with every part of the company. Fro
86.
▲
What Is the Boeing 737 Max MCAS?
(theaircurrent.com)
2 points
by
ejcx
8y ago
|
0 comments
87.
▲
by
ejcx
8y ago
No browsers present that to users as a secure context, so nobody is being tricked. More HTTPS == Better. If you can load this over HTTPS you should, no matter what circumstance. The browsers iconography will handle notifying people when the
88.
▲
by
ejcx
8y ago
Good to know. I will buy this doc and give it a read, thanks.
89.
▲
by
ejcx
8y ago
Jtsummers, I don't disagree with you. The reality is the DO-178C is no different than PCI or other compliance standards, and there are ways to game it with docs. With that said, if formal methods were really required to fly the plane t
90.
▲
by
ejcx
8y ago
Even aircraft software doesn't require formal methods. I have a copy of the DO-178C on my laptop. It's mentioned once in the glossary, once in the appendix A, and once in appendix B. Formal methods would be great, but most people
More ›