Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ffo
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
91.
▲
by
ffo
5y ago
Maybe the sell there leftover ingress bandwidth to apple :-)
92.
▲
by
ffo
5y ago
hey don't forget samesite ;-)
93.
▲
by
ffo
5y ago
From a design perspective you are right. But from a threat model I would dare to say, if you control the platform (OS, Cloud Service) you can easy bypass encryption or deploy your own keys as well. In the end it is still a trust question.
94.
▲
by
ffo
5y ago
Oh yes, they are hideous.
95.
▲
by
ffo
5y ago
Thank you, this really well summarises my article.
96.
▲
by
ffo
5y ago
Totally agree with your point here. Would love to see a TB implementation depending on hardware keys. But yeah it is gone. If the UX for mTLS (client certs) just was not so terrible it might be a great alternative with even better Security,
97.
▲
by
ffo
5y ago
To use ip binding as means already fails today. I mean CG-NAT and the slow adoption of ipv6 also did help dig that grave and I would argue that with that you can't rely on the IP because it is volatile anyway. From a threat model persp
98.
▲
by
ffo
5y ago
With the Developer Beta 2 it was more consistent in staying somewhat in the region. But still if you IP is consistently changing it is hard to adapt. Btw. Oftentimes Geo Databases are wrong as well.
99.
▲
by
ffo
5y ago
It is patched now.
100.
▲
by
ffo
5y ago
Ok, maybe I remembered wrong. This makes things even worse.
101.
▲
by
ffo
5y ago
Well as of now the traffic egresses with Cloudflare in Zürich or Bern with the IP 104.28.19.67 :-)
102.
▲
by
ffo
5y ago
Whops, good catch! There is definitely the link missing. Going to correct that ASAP. In the meantime: https://zitadel.ch/blog/imo-passkey-in-icloud-keychain/
103.
▲
by
ffo
5y ago
True :-)
104.
▲
by
ffo
5y ago
It did change a lot in the last few days. As of now I get some datacenter in Switzerland and Liechtenstein sometimes.
105.
▲
by
ffo
5y ago
Been there done that. Google flagged my account several times already, with nice captchas :-)
106.
▲
by
ffo
5y ago
True it applies to other services as well. I just scoped my IMO to our Identity and Access Management World.
107.
▲
by
ffo
5y ago
Exactly this is the intention!
108.
▲
by
ffo
5y ago
You can choose in the OS to use a general location or stick to something in your proximity. At least in the Developer Beta 2
109.
▲
by
ffo
5y ago
I think it is still there, even in Edge on Chromium. But still Chrome dropped the hidden support a while ago.
110.
▲
by
ffo
5y ago
We still have separate laws here. But we are moving towards the EU regulations in small steps.
111.
▲
by
ffo
5y ago
Well, in the end channel binding would be the best option which really mitigates some threat vectors. For example MITM, secrets extraction out of the browser and so on. But the big issue is that this is not widely supported. Using the IP as
112.
▲
by
ffo
5y ago
What did you see that felt wrong to use GitOps?
113.
▲
by
ffo
5y ago
True, cost is not the biggest issue. Separation of teams with different velocity and needs on the other hand is. One API as abstraction with shared processes eases the pain for the people relying on a platform.
114.
▲
by
ffo
5y ago
You mean EKS needs re-engineering?
115.
▲
by
ffo
5y ago
Hey we used tectonic ;-) was a great tool at that time. Tectonic did influence some of the concepts around ORBOS. Just think of Tectonic combined with GitOps, minus the iPXE part. Disclaimer: I am working with ORBOS
116.
▲
by
ffo
5y ago
You don’t exactly need to run a cluster per service ;-) Instead you can choose to collocate services who belong together and form a „domain“. But don‘t go the route and build the almighty one Kubernetes cluster where all your domains run in
117.
▲
by
ffo
6y ago
We are building a cloud-native IAM over here https://github.com/caos/zitadel It is written in Go and built around event sourcing for a great audit trail. We already support OIDC, Passwordless, RBAC and working on more
118.
▲
by
ffo
6y ago
Well, this is a fresh approach. I really like the way kreya is built. IMO this is simply the most mature GUI client for gRPC!