Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
graystevens
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
graystevens
8y ago
I’m working on a skin for developer laptops so that you can apply those sweet conference and startup stickers. No more risking your resale value, or even physically risking damage to your expensive MacBook. I want the skins to be identical
32.
▲
by
graystevens
8y ago
You can find the actively maintained repository at https://github.com/tqdm/tqdm
33.
▲
Data Breaches like Apollo are why we exist
(breachinsider.com)
1 points
by
graystevens
8y ago
|
0 comments
34.
▲
by
graystevens
8y ago
I got fed up of going to conferences and getting some cool stickers that I never get to put anywhere. The obvious idea is to put them on your laptop, but that can make reselling it difficult, and you lose those stickers if you sell it with
35.
▲
Data Breaches like Apollo are why we exist
(breachinsider.com)
2 points
by
graystevens
8y ago
|
0 comments
36.
▲
by
graystevens
8y ago
* Breach Insider ( https://breachinsider.com ) * Data breach detection made easy, using pseudo-users with real information, unique to your business. * Current stage: Bootstrapped and profitable. Working on (gradual) growth! * Cont
37.
▲
Security for Startups Guide
(breachinsider.com)
3 points
by
graystevens
8y ago
|
0 comments
38.
▲
by
graystevens
8y ago
I thought the same, but according to Yubico themselves[0], it’s a Yubikey 4 with some branding. Unless that was a previous campaign? [0] https://www.yubico.com/2018/02/wired-ars-technica-experts-ch...
39.
▲
by
graystevens
8y ago
I’ve got the same machine and will be looking to upgrade the SSD shortly with a lovely nvme m.2 ssd thanks to an adapter. The thought of going from 128GB to 1TB for ~£280, plus the performance upgrade, almost certainly means I’ll be holding
40.
▲
by
graystevens
8y ago
I believe they are referring to proxying requests to third parties, rather than the first part of the post which refers to proxying to your own backend. Proxying requests to a third-party will mean browser security features like CORS will a
41.
▲
by
graystevens
8y ago
For those that took part in previous years, would this be suitable for those of us running (or thinking of starting..) bootstrapped startups, as solo-entrepreneurs? I ask because the curriculum looks great, but wondered if the mentoring mig
42.
▲
by
graystevens
8y ago
Top work Fastmail team! Good news! Mail access has been restored for users on some major networks. We apologize to those customers who still cannot reach their Inboxes - we're working to restore full access as fast as we can. No mail
43.
▲
by
graystevens
8y ago
Matches up with their current Twitter thread: We're experiencing a network outage. Stay tuned at https://www.fastmailstatus.com . We're in close communication with our provider trying to restore service. 1:34 AM - 1 A
44.
▲
by
graystevens
8y ago
It certainly depends how your company views its risks and how docker fits into their “threat model” - you’re running someone else’s code on your secure internal networks, so it should be treated like external/unauthorised software. It’
45.
▲
by
graystevens
8y ago
I'll add another data point, from the consumer telecoms industry. 90% feels way too high from what we had to head with, even prior to implementing rate-limiting and other defences. We ended up tracking actors as they switched up their
46.
▲
by
graystevens
8y ago
From my experience, and this may be because of the industry I am working in, the overall idea is "dont". That is not to say that it doesn't work for other sectors & I'm pretty sure there are lots of evidence to say o
47.
▲
by
graystevens
8y ago
Agreed, based on other thresholds and alerts, we certainly saw some more advanced actors - using in-country home broadband lines to conduct the attacks. This made tracking and blocking them much harder, as there was a risk of blocking genui
48.
▲
by
graystevens
8y ago
If the term Credential Stuffing is new to anyone, we’ve done a deep dive into what it is and the tools that are used here: https://breachinsider.com/blog/2017/credential-stuffing-how-... We saw this pretty regular
49.
▲
by
graystevens
8y ago
Thanks for the Edgerouter link, saved me doing some Googling - Off to got and apply this now and see what difference this makes to the Bufferbloat tests. As Arie mentions, this is a little more involved on the EdgeOS stuff, but doesn't
50.
▲
A Look at the Compromised Gitea Release
(grh.am)
2 points
by
graystevens
8y ago
|
0 comments
51.
▲
by
graystevens
8y ago
From what I’ve read, this is exactly what I was thinking too - this has POS/till malware written all over it. I look forward to getting some of the more technical details (if they get realised) to see exactly how widespread this issue
52.
▲
by
graystevens
8y ago
I'm happy to be corrected here, but in response to: I have to constantly be worrying about not putting "secret" things into the doc. Unless they have someone who's job is to take their real chat and transcribe it, in wh
53.
▲
by
graystevens
8y ago
A small suggestion, if I may - browsing your landing page, I found it would occasionally jump each time your ‘typing text’ changed towards the top of the page. You might want to set a static height on that div, or maybe just have a permanen
54.
▲
by
graystevens
8y ago
This has definitely been the case for me over at breachinsider.com too – the ShowHN brought our first handful of customers, which have been a real delight to work with and completely fit the description outlined above... they understand the
55.
▲
by
graystevens
8y ago
I've started to take a look at the binary that was uploaded - it seems it wasn't just Gitea that got hit by this, but also https://github.com/opencompany/www.opencompany.org which too has a strange release as
56.
▲
by
graystevens
8y ago
What issues do you have with HTTPS/TLS? I can’t say I’ve come across any issues so far - is it a specific usecase to Ahrefs?
57.
▲
by
graystevens
8y ago
Same experience here - we run a docker instance of Chrome using tabs for multiple pages rather than multiple browsers, and they regularly run for days without issues. Of course their RAM usage gradually expands but it is easy enough to syst
58.
▲
by
graystevens
8y ago
Latency would be the big issue here. You’d likely have to spin up instances in lots of key data centres to try and combat this... Each AWS location, each Google Cloud location.. and that’s not considering those that are colocating their own
59.
▲
by
graystevens
8y ago
Would be interesting to know if they fit the ‘classic’ credential stuffing methodology ( https://breachinsider.com/blog/2017/credential-stuffing-how-... ) or if they have moved on to something more sophisticated. My
60.
▲
by
graystevens
8y ago
Spot on - they’re often referred to as ‘stressers’ or ‘booters’, and can make a nice chunk of money. There’s always someone looking to knock someone off of Xbox Live or PSN, or even chance it and try to take down a popular website. Dependin
More ›