Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
gebalamariusz
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
The Trivy supply chain attack started 16 months earlier than you think
(haitmg.pl)
1 points
by
gebalamariusz
6mo ago
|
0 comments
2.
▲
by
gebalamariusz
6mo ago
I decided to create this tool for more pragmatic reasons. First, I've been at AWS for several years now, and security has always been a major issue in many companies I've worked for. Second, even if you're a specialist with a
3.
▲
Show HN: Cloud-audit – AWS scanner that chains findings into attack paths
(github.com)
3 points
by
gebalamariusz
6mo ago
|
1 comments
4.
▲
by
gebalamariusz
6mo ago
The 40% acceleration in the second half is the number that jumps out. That is not just "more groups", something changed operationally in the ecosystem around September 2025. SafePay dominating Germany with 72 claims is worth watch
5.
▲
CIS AWS v3.0: Automate Compliance with Terraform
(haitmg.pl)
2 points
by
gebalamariusz
6mo ago
|
0 comments
6.
▲
by
gebalamariusz
6mo ago
I use Claude Code a lot, especially when building infrastructure. The most important thing in my work isn't so much the memory architecture, but rather the good structure of CLAUDE.md (architectural decisions, file paths, rules like &q
7.
▲
by
gebalamariusz
7mo ago
It's the "healthy cluster" aspect that makes this scary. Partition errors are expected—that's what Jepsen is testing. However, stale reads during normal operation mean that most Galera deployments behind a round-robin lo
8.
▲
by
gebalamariusz
7mo ago
Well, this all makes sense for application code, but not necessarily for infrastructure changes. Imagine a failed Terraform merge that deletes the production database but opens the inbound at 0.0.0.0/0, and you can't undo it for 1
9.
▲
by
gebalamariusz
7mo ago
Generally, yes, the guidelines specify scope to repos and branches. However, the main problem is that the default policy only checks the recipient declaration when creating an OIDC. If you didn't manually create the second condition, y
10.
▲
Most GitHub Actions OIDC trust policies allow any repo to assume AWS IAM roles
(haitmg.pl)
2 points
by
gebalamariusz
7mo ago
|
2 comments
11.
▲
by
gebalamariusz
7mo ago
I see the UK government hasn't been on a good run lately. Google recently released the Cloud Threat Horizons H1 2026 report. A vulnerability in the OIDC trust policy can be exploited to gain admin access to AWS. The UK Government Digit
12.
▲
by
gebalamariusz
7mo ago
Overall, it's interesting. OIDC is probably the most common practice for inter-service authentication today. The problem is that in practice, I've seen many configurations where OIDC could be used as an attack vector (missing sub
13.
▲
by
gebalamariusz
7mo ago
In AWS, for example, DNSSEC Route53 signing is possible, but almost no one configures it. Generally, most people do a lot of good things about security, but they somehow forget about DNS.