Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
goodwink
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
goodwink
14y ago
Perhaps they were compromised?
62.
▲
by
goodwink
14y ago
A conspiracy theorist might surmise that's the point. It'd be very funny in a very SV sort of way, but I don't think it's true.
63.
▲
by
goodwink
14y ago
If you wouldn't mind sharing, could you please elaborate on your reasoning for flagging them? I'd like some further insight into which elements of the coverage of the story (rather than the story itself) you find objectionable.
64.
▲
by
goodwink
14y ago
Agreed, if this is manual intervention it should be explicitly announced so that it's both transparent and people stop submitting more links on the same story for them to moderate.
65.
▲
by
goodwink
14y ago
I think he was arguing that newly created accounts from those groups were upvoting and the deletion was to counter that. It seems equally far-fetched, but at least not technically impossible. I highly doubt though that the majority of p
66.
▲
by
goodwink
14y ago
Perhaps the more accurate way of describing it is marked "[dead]", although some are not showing up that way either it seems even though you can still follow a direct link to them.
67.
▲
by
goodwink
14y ago
Comments about why the stories are being deleted are also being deleted as are questions posted about why the stories were deleted like this one. It's clear that either someone doesn't want this to be discussed on the site or some sort of
68.
▲
by
goodwink
14y ago
Comments about them getting deleted seem to be getting deleted as well.
69.
▲
by
goodwink
14y ago
These articles keep disappearing from the front page. I wonder if they're being caught up in some sort of upvoting-too-fast detection or if it's manual intervention?
70.
▲
by
goodwink
14y ago
I found this service while doing research into launching a similar competing service. I didn't really expect it to show up on HN, though! Congrats on the launch. :)
71.
▲
by
goodwink
14y ago
I don't think you reads the whole article.
72.
▲
by
goodwink
14y ago
I think you missed the part where they retained a root password over a machine rebuild.
73.
▲
by
goodwink
14y ago
I have ssh keys set up so it doesn't do this. Instead what it seems to do is reuse your old root password for the new image.
74.
▲
by
goodwink
14y ago
To answer some common questions about this article: Yes, I know my setup was very flawed. It was a test machine and in the midst of having automated config scripts written for it which were being tested. This is why the machine was vulner
75.
▲
by
goodwink
14y ago
The article mentions that this was verified to not be the problem.
76.
▲
by
goodwink
14y ago
My setup was clearly flawed and I acknowledged that in the message. Their system /does/ have serious problems though since someone is likely intercepting their password reset emails or else accessing their root password database which shou
77.
▲
by
goodwink
14y ago
No I didn't change the password. Instead I rebuilt the machine from the base OS image. Would you expect that a new system with the disk wiped would retain the old root password? I certainly wouldn't. Where were they keeping it?
78.
▲
by
goodwink
14y ago
The shocker is that this is true even if you rebuild the box from the scratch image.
79.
▲
by
goodwink
14y ago
I'm not upset I got compromised, it was very likely given my configuration, I acknowledge that. I did have keys enabled so the password wasn't email initially, it was only emailed as a result of a root password reset. The article is about
80.
▲
by
goodwink
14y ago
But if you reset the root password it's still emailed, regardless of ssh key.
81.
▲
by
goodwink
14y ago
The brute force attack would have been disallowed due to fail2ban being enabled.
82.
▲
DigitalOcean Root Vulnerability in the Wild
(badassrockstartech.com)
38 points
by
goodwink
14y ago
|
55 comments
83.
▲
Experience Versus Enthusiasm in Hiring
(badassrockstartech.com)
1 points
by
goodwink
14y ago
|
0 comments
84.
▲
by
goodwink
14y ago
I had hoped that in place of the final advertisement slide would be a presentation full of advice and strategies on using 3rd party APIs defensibly. I'd have been happy to have a few ad slids at the end of /that/ information, but here the
85.
▲
by
goodwink
14y ago
It seems to solve a very similar problem to Angular UI's bootstrap project: http://angular-ui.github.com/bootstrap/
86.
▲
by
goodwink
14y ago
The dot indicates division of something into smaller parts. For most things we choose our range for the minor denomination to coincide with our base or a multiple thereof like having 100 cents in a dollar, but software being what it is we
87.
▲
by
goodwink
14y ago
THey've defined their versioning based on a subjective assessment of stability, willingness to add new features, and API compatibility. They plan 0.12 to be the final 0.x release before a 1.0 release.
88.
▲
by
goodwink
14y ago
I think my next project may well use balanced instead of stripe. This is great stuff!
89.
▲
by
goodwink
14y ago
How do you know if you're in this situation or if you simply haven't been able to get the exposure you need?
90.
▲
by
goodwink
14y ago
This is very nearly the "Stripe, but also with ACH" that I've been wanting for a while now. Being able to let businesses set up recurring ACH debit for subscription plans is very good for the B2B SaaS market.
More ›