Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
eyakubovich
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
eyakubovich
3y ago
In my experience, the hardest part of developing with eBPF is dealing with the multiple kernel versions and configurations that the target machines may have. It's a challenge not only because eBPF features were added gradually but beca
2.
▲
The True Cost of Automatic Vulnerability Patching
(edgebit.io)
1 points
by
eyakubovich
3y ago
|
0 comments
3.
▲
by
eyakubovich
4y ago
100% agree. The reality is that updating a dependency always carries some risk and sometimes requires changes to code. Reducing the amount of upgrades that have to be done under a stringent SLA makes life easier. In larger orgs we’ve talke
4.
▲
by
eyakubovich
4y ago
Great feedback. 1) We want to be cautious about changing a score that someone else assigned (CVSS) but we'd like to add our insight to inform of its impact. 2) Absolutely and we'd like to bundle it with active blocking. After revi
5.
▲
by
eyakubovich
4y ago
IIUC, Infisical uses end-to-end encryption. Does that change your attitude towards cloud-only options? I'm genuinely curios to understand how SaaS products can be made secure so people are comfortable using them for sensitive data.
6.
▲
by
eyakubovich
4y ago
Most backend services get an identity assigned to them by having a token tied to a service account. This accomplishes the same goal, just in a more secure way.
7.
▲
by
eyakubovich
4y ago
It's unclear when homomorphic encryption will be ready for prime time, especially at big tech scale. It's easier to give up the data under assurances of how exactly that data will be used. Secure enclaves (e.g. AWS nitro enclaves)
8.
▲
by
eyakubovich
4y ago
Hi, the author of the blog post here. I wanted to point out two neat features of the Enclaver: (1) it solves the enclave image distribution problem by packaging the underlying enclave image into a Docker container so it can be pushed to any
9.
▲
Preventing Data Exfiltration with eBPF
(goteleport.com)
5 points
by
eyakubovich
5y ago
|
0 comments
10.
▲
by
eyakubovich
8y ago
> Yes, those are the cases where it isn't possible to avoid forward declarations, so it's fine to use them? But my point was that it _is_ possible to avoid them by type-punning via void*. Now, one can argue that it's unrea
11.
▲
by
eyakubovich
8y ago
I don't accept that any reasonable sized shop needs to subset C++ or insanity will prevail. Any particular slice of code needs to subset the language. You may have some perf sensitive code that can't afford virtual function overhe
12.
▲
by
eyakubovich
8y ago
The trouble with "this is not the law" argument is that it's not clear how to make the judgement. The reviewer should be using the style guide during the review and should call out any violations. A restrictive guide then pla
13.
▲
Google C++ Style Guide Is No Good
(eyakubovich.github.io)
77 points
by
eyakubovich
8y ago
|
104 comments
14.
▲
Break open that container
(dev-perspective.blogspot.com)
1 points
by
eyakubovich
10y ago
|
0 comments
15.
▲
by
eyakubovich
12y ago
Correct, tinc is another example of a mesh overlay network. However tinc requires configuration files to be created on each host and then distributed to others. If machines are part of an etcd cluster, you can use Rudder to create a mesh wi
16.
▲
by
eyakubovich
12y ago
If your hosts in different data centers share IP space (you're able to route between them) then you can use Rudder. Please note that the traffic is not currently encrypted so if the interconnect between the data centers is over open pi