Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jamescun
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
Git techniques
(riskledger.com)
86 points
by
jamescun
5y ago
|
77 comments
32.
▲
by
jamescun
5y ago
Risk Ledger | London, UK | Full-Time | Senior Backend, Frontend and Product Managers | https://riskledger.com We're a London-based startup, with a mission to solve the problem of security risk in the supply chain, globally.
33.
▲
A Tale of DNS and BGP: The Facebook Outage, October 2021
(riskledger.com)
66 points
by
jamescun
5y ago
|
16 comments
34.
▲
by
jamescun
5y ago
Risk Ledger | London, UK | Full-Time | Senior Backend, Frontend and Product Managers | https://riskledger.com We're a London-based startup, with a mission to solve the problem of security risk in the supply chain, globally.
35.
▲
by
jamescun
5y ago
Interesting, I hadn't heard of MediaLab until just a few days ago when I listened to a Darknet Diaries episode[1] about Kik and some "content problems" that MediaLab are leaving unresolved. [1] https://darknetdiari
36.
▲
by
jamescun
5y ago
Another one, ensure the password validation on sign up and login are the same. Happened at least once with a large broadband provider in the UK where I was able to sign up with a password but never able to log in due to stricter validation
37.
▲
by
jamescun
5y ago
I welcome the return to brands using serif fonts. Nothing against sans serif, but there are only so many times you can see Helvetica or Gotham!
38.
▲
by
jamescun
5y ago
Coincidentally, Channel 4 in the UK broadcast a series called "The Bank of Dave" in 2012 where a resident of Burnley called David Fishwick tried to launch a bank of the same name. They subsequently couldn't get a banking lice
39.
▲
by
jamescun
5y ago
> Before the internet, that meant car ads in car magazines and watch ads in the Economist. Ads were based on context, and on inferring the audience from the context. You can still do this. Car ads on car websites. Watch ads on the Econom
40.
▲
by
jamescun
5y ago
> While investigation has not revealed evidence of unauthorized usage of the exposed GPG key I'm curious how they'd investigate or verify this, the key in question is used for downloaded releases and plugins.
41.
▲
by
jamescun
6y ago
This mirrors my experience. I've seen more problems caused by the JVM, by default on some configurations, caching DNS indefinitely, regardless of TTL, than caused by a short TTL.
42.
▲
by
jamescun
6y ago
So if I am reading this right, in addition to a null dereference, turning on strict certificate validation actually disabled the check asserting that non-CA certificates cannot issue other certificates?
43.
▲
by
jamescun
6y ago
We don't know what the vulnerability is yet. Sure it could be a buffer overflow, readily possible in a language like C, or could be a bug in the crypto/implementation itself, no memory safe language will save you there.
44.
▲
by
jamescun
6y ago
WireGuard is being removed from FreeBSD 13 (the base for pfSense). There were some tit-for-tat messages between devs here, and while the implementation was probably fine, it is pretty reasonable to take a step back here, take stock, and tak
45.
▲
by
jamescun
6y ago
What do you see as the biggest challenge at getting Mojeek integrated into existing platforms, like browsers or mobile devices, that typically rely on less privacy-preserving options, namely Google?
46.
▲
by
jamescun
6y ago
Some people just want to watch the world burn.
47.
▲
by
jamescun
6y ago
I've seen nothing to suggest SSE would be (or is even capable of being) deprecated on HTTP/2. You may be confusing it with HTTP/2 Push, where a server can inform a client of a future resource it will need, which is _de facto_
48.
▲
by
jamescun
6y ago
It may be quipped that Docker or Kubernetes is remote code execution (RCE) as a service! The vulnerability pointed out here is server operators who have exposed Docker's API to the public internet, allowing anyone to run a container. T
49.
▲
by
jamescun
6y ago
What are the proposed benefits of QUIC? May be misguided, but I feel a little uneasy about bundling TCP functionality, TLS and HTTP into a single protocol over UDP.
50.
▲
by
jamescun
6y ago
Haven't noticed any issues (London), but I do appreciate the attention FastMail give to their uptime and outages, given they handle something as critical as email.
51.
▲
by
jamescun
6y ago
Sounds very regular, may be worth contacting your ISP to see if that is their maintainence period or any other regular operation they may perform. I am with a broadband provider in the UK called Zen, at 23:15 every Sunday our PPPoE session
52.
▲
by
jamescun
6y ago
This post touches on "innovation tokens". While I agree with the premise of "choose boring technology", it feels like a process smell, particularly of a startup whose goal is to innovate a techology. Feels demotivating a
53.
▲
by
jamescun
6y ago
Bear in mind that the "results" of a notorious hack are often offered for sale as a diversionary technique, and in particular this offers up nothing beyond commercially sensetive information, if even legitimate at all.
54.
▲
by
jamescun
6y ago
The UK has left the EU however the Data Protection Act 2018 which implemented GDPR within the UK is still in effect.
55.
▲
by
jamescun
6y ago
Would this not be misuse of PII? You own a particular vehicle registration mark as much as you own a particular phone number, and both can reasonably be used to identify an individual (motor database verus telephone database).
56.
▲
by
jamescun
6y ago
Thanks!
57.
▲
by
jamescun
6y ago
> To lock an instance into a 6PN network, all we really need is a trivial BPF program that enforces the “don’t cross the streams” rule: you can’t send packets between different 6PN prefixes. Are you using eBPF for this egress filtering?
58.
▲
by
jamescun
6y ago
Preventing the target resolver from seeing client's IP address breaks GeoDNS. This is already a problem with 1.1.1.1 which doesn't honour the EDNS client subnet extension. Given generally DNS is just the start of an intereaction,
59.
▲
by
jamescun
6y ago
Not quite sure what they're suggesting, as CloudFlare's approach to privacy is put them in the middle and they promise it's private... not exactly phase 3 of the internet. In my opinion, "Phase 3" of the internet is
60.
▲
by
jamescun
6y ago
You are correct, however CloudFlare does support supplying your own certificate, and I'd consider it an element of dogfooding to use their own CA on their own site.
More ›