Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
fjni
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
31.
▲
by
fjni
4y ago
This! Most haven't tried. It goes incredibly far.
32.
▲
by
fjni
4y ago
You are right of course. There’s a scenario where they have exhausted all possible ways in which it could have leaked, determined that it wasn’t and decided despite that conclusion to rotate the key. That would be doing so purely out of abu
33.
▲
by
fjni
4y ago
> This week, we discovered that GitHub.com’s RSA SSH private key was briefly exposed in a public GitHub repository > ... out of an abundance of caution, we replaced our RSA SSH host key used to secure Git operations for GitHub.com Yea
34.
▲
by
fjni
4y ago
I'm with you on this. I would expand this further yet and say that introducing this as a feature creates a whole set of security concerns that just weren't there before.
35.
▲
by
fjni
4y ago
“But the firm learned that its limited partners were encountering issues using SVB services as they tried to transfer the funds” This though was not in Thursday.
36.
▲
by
fjni
4y ago
Will this disable fallback to text message 2fa? Or is there another way to disable it?
37.
▲
by
fjni
4y ago
Absolutely this! The fact that no one bats an eye that GitHub is used to store proprietary source code is so surprising to me. Conversely if that is what it is meant for, why does it default to autocompleting to all users globally instead
38.
▲
by
fjni
4y ago
Their main product is breaking end-to-end encryption. You could certainly argue that that's no different than relying on azure, aws, or gcp to issue your cert and technically having the ability to decrypt traffic to your server for wha
39.
▲
by
fjni
4y ago
At work there's a command I run that then requires 2fa auth through our identity provider. As a result, my ssh key gets signed with both a time restriction and an ip restriction. Same mechanism for git interactions and server logins. I
40.
▲
by
fjni
4y ago
> I wouldn't call the Garmin G1000 a paragon of UX design though. In some ways I would. I wouldn't call it "intuitive," but once you understand its semantics, it's phenomenally predictable in its behavior. And qu
41.
▲
by
fjni
4y ago
> We blocked these IPs from accessing any of our services. > ... we’re tightening up our Access implementation to prevent any logins from unknown VPNs This requires clarification. I think this means cloudflare is completely blocking s
42.
▲
by
fjni
4y ago
Elephant in the room.
43.
▲
by
fjni
4y ago
Yosef Lerner and Rose Sacktor made a very funny video taking advantage of that: https://www.youtube.com/watch?v=i9jIsxQNz0M
44.
▲
by
fjni
4y ago
they deserve a lot of credit for how early they built this and made it relatively broadly available!
45.
▲
by
fjni
4y ago
The issue if I remember correctly was that you could require the email to be verified. But while that verification was pending, it would already use the new email as the user’s asserted attribute.
46.
▲
by
fjni
4y ago
I don’t remember exactly, but I think this also took away the ability for users to manage their factors (I.e. register a new hardware token)
47.
▲
by
fjni
4y ago
My biggest issue in the version I was evaluating: Some service providers use “email” as username (in fact many do.) Keycloak doesn’t make it easy to prohibit users from changing their own email, making it trivial to impersonate someone els
48.
▲
by
fjni
4y ago
This will work. But learning curve is steep as others have said.
49.
▲
by
fjni
5y ago
https://metal.equinix.com/ May work for what you need, and they also have spot instances.
50.
▲
by
fjni
5y ago
I always thought this was an interesting thought exercise just conceptually (not even legally.) If you and I are friends, is the knowledge of that friendship mine? Is it yours? Can I freely share that knowledge with someone else? The impact
51.
▲
by
fjni
5y ago
Use a tiny portion of that to continue support for local, non-cloud-based vault files please.
52.
▲
by
fjni
5y ago
I shouldn't be surprised any more, but how apple always gets away with hand-wavy explanations does still surprise me: Who are these "content-providers" who get insight into what domain names are being resolved? (I understand
53.
▲
by
fjni
5y ago
Got it! The distinction being that the location changed while in the vicinity of one iphone. Thanks for clarifying!
54.
▲
by
fjni
5y ago
I think this is a great question. And I don't have an answer for it. I do think it's much less clear though: If I attach it to your car to find out where you're parking your car, according to your logic it also presumably wou
55.
▲
by
fjni
5y ago
As a user, I'd love the option to decide whether I want to help in this system or not. Similar to how I can opt-in to sharing analytics with Apple. I just might help out. But the idea that by owning an iPhone I'm automatically opt
56.
▲
by
fjni
5y ago
This blew my mind: https://pkg.go.dev/golang.org/x/crypto/acme/autocert
57.
▲
by
fjni
6y ago
I had something similar so perhaps this helps: If you still have a google account that has the “calendar” feature enabled, this will lead to google sending invite acceptance emails. Especially if you have a business account (which was my ex
58.
▲
by
fjni
6y ago
nailed it: https://twitter.com/StanTwinB/status/1336890442768547845
59.
▲
by
fjni
6y ago
CapitalOne has (not even just for banking standards) an amazing developer platform. https://developer.capitalone.com
60.
▲
by
fjni
6y ago
This seems like an impossible task unless you have a European Facebook and a US Facebook and a user of one can’t interact with the other. If a US-based user interacts with data posted by the European user, is that not considered “Sending da
More ›