Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
helper
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
helper
7y ago
I'd love to read a "cryptographic doom principle"-esque latacora blog post on all the failures over the years of not using your OS provided CSRNG.
32.
▲
by
helper
7y ago
chrchang523 is correct. In my test the caller function can still get inlined.
33.
▲
by
helper
7y ago
I tested this and it does indeed eliminate that code.
34.
▲
by
helper
7y ago
In go you can use build tags to achieve this. The compiler will drop function calls to empty function implementations (tested on go 1.11.5).
35.
▲
by
helper
7y ago
The option comes up for me on the lock screen.
36.
▲
by
helper
8y ago
No. Lambda charges you only for when your application is actually handling request (or other events). That isn't an option with Fargate.
37.
▲
by
helper
8y ago
Thanks!
38.
▲
by
helper
8y ago
What does "Cloud Run on Google Kubernetes Engine" mean? Is there anything beyond the idea that a plain docker container can run on Cloud Run or on GKE?
39.
▲
by
helper
8y ago
From a developer perspective, deploying a docker container with a plain http server is much more appealing than the hoops you have to jump through to use the lambda custom runtime stuff. I hope this gets AWS to provide a docker on lambda op
40.
▲
by
helper
8y ago
The author of this service didn't think it important to provide the ssh key and based on the comments in this thread people have already signed up for this service without caring about the key. So yes, I think even people who would use
41.
▲
by
helper
8y ago
Registration over ssh is cute but not safe from MITM attacks. Even if the ssh key was published somewhere (which as far as I can tell it isn't) you would be dependent on people manually adding the key to their known_hosts file which yo
42.
▲
by
helper
8y ago
What do you want me to read?
43.
▲
by
helper
8y ago
Because it doesn't solve the problem the author is trying to solve? The goal of this is to be able to produce backwards compatible tar.gz files that can be served from a docker registry that also can be on demand streamed instead of pr
44.
▲
CRFS: Container Registry Filesystem
(github.com)
104 points
by
helper
8y ago
|
21 comments
45.
▲
by
helper
8y ago
There's a really interesting book about the NTSB investigation into flight 427 called "The Mystery of Flight 427: Inside a Crash Investigation". If you like the story behind root cause analysis of engineering failures (and ar
46.
▲
by
helper
8y ago
This is the CAB Forum rationale for serial number entropy[1]: > As demonstrated in https://events.ccc.de/congress/2008/Fahrplan/attachments/125... , hash collisions can allow an attacker to forge a si
47.
▲
by
helper
8y ago
Interesting. Here's an article describing the changes: https://9to5google.com/2019/02/15/google-chrome-detect-incog...
48.
▲
by
helper
8y ago
> Beeing GDPR compliant is not rocket science. Its also not free. Rational companies will apply a cost benefit analysis to GDPR compliance and some of them will determine it is better to block EU visitors than to do the GDPR work.
49.
▲
by
helper
8y ago
Blockchain, literally just a merkle tree..
50.
▲
by
helper
8y ago
This is a really great exploration of this vulnerability. It makes me sad that lxc doesn't get more love. LXC has had unprivileged containers as its default for 5+ years now. Its a really solid tool set that has mostly been passed over
51.
▲
by
helper
8y ago
They are working on it: https://git.zx2c4.com/wg-dynamic/about/docs/idea.md
52.
▲
WireGuard for MacOS
(lists.zx2c4.com)
575 points
by
helper
8y ago
|
154 comments
53.
▲
by
helper
8y ago
Its not hardcoded, its just the default server. You can specify your own via a cli flag.
54.
▲
by
helper
8y ago
Its interesting that pass[1] uses GPG and was created by the author of wireguard, Jason Donenfeld. I wounder if he would build it differently if he were starting today? I feel like the one thing that keeps me from abandoning GPG completely
55.
▲
by
helper
8y ago
Its never been part of the stdlib, its part of x/crypto. They also aren't going to remove it, just deprecate it.
56.
▲
by
helper
8y ago
We use wildcard certs (*.example.com) so each customer can have vanity-customer-name.example.com domains. I think our model is fairly common for multi-tenant domain name segregated systems.
57.
▲
by
helper
8y ago
They have supported TLS termination for https connections for a long time. This adds support for TLS on TCP connections. The NLB load balancer also allows you to keep the same set of pubic IP addresses for your load balancer endpoints.
58.
▲
by
helper
8y ago
The nextmuni predictions are pretty good for buses that are already running on the route. The predictions break down as soon as it has to estimate when the next driver is going to actually start the route.
59.
▲
by
helper
8y ago
If an account that doesn't have this feature turned on is hijacked, the hijacker could turn this on to permanently lock out the owner of the account.
60.
▲
by
helper
8y ago
I tried it today with my speaker and it worked.
More ›