Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jenandre
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
by
jenandre
13y ago
I use supervisor with all of my node.js deployments... It seems straightforward for me just to drop a new .conf script in, it's agnostic to what code it's starting/monitoring (I use it with ruby as well) so I'm confused
62.
▲
by
jenandre
13y ago
Yeah, my point is, we don't really know what the scope is -- we have Snowden's word and some slides that mention direct access to servers. But the engineers who worked at the companies and performed the integrations know and prob
63.
▲
by
jenandre
13y ago
I would find it really interesting if some employees at companies like Google, Microsoft, etc would come forward and corroborate Snowden's claims as well. At some point, SOME engineering work was involved on their side to make it happ
64.
▲
by
jenandre
13y ago
I have no power to discredit him. I'm not famous, nor any access to a venue to do so. This is totally personal speculation based on how I would have behaved if I were in his position as a whistleblower that was a strong human rights
65.
▲
by
jenandre
13y ago
If he had connections in Hong Kong, why supply the weak excuse "oh, it's because of its history of dissidence and freedom of speech?" He would have been much more convincing saying "yeah, I know that China doesn't
66.
▲
by
jenandre
13y ago
lol, perfect example of why twitter is retarded. I live in DC and know tons of people who work for the government. Guess what? They are people like you and I, and in a lot of cases less capable or bright (which is why they go for cushy go
67.
▲
by
jenandre
13y ago
Sorry, but I don't buy this guy's story. Something is just incredibly fishy. I don't buy this guy's argument for going to Hong Kong, e.g. that has a history of free speech, and its supposed autonomy from the mainland --
68.
▲
What to do if you're hacked (advice for startups)
(medium.com)
7 points
by
jenandre
13y ago
|
0 comments
69.
▲
Be The Worst
(medium.com)
1 points
by
jenandre
13y ago
|
0 comments
70.
▲
by
jenandre
13y ago
The solution isn't intended as a measure to resist intrusion, I agree 100% with you that using PKI as a form of two factor for hardening authentication is a great idea. It's more of a secondary measure for forensics and incident response pu
71.
▲
by
jenandre
13y ago
The usernames do not need to be part of the audit trail -- the unique URL identifies the site it came from. You know you your own logins, presumably, so it doesn't need to be there. myaudithooks.com should not be centralized -- I 100% agree
72.
▲
I long for the future where I can safely assume my passwords are stolen
(medium.com)
96 points
by
jenandre
13y ago
|
93 comments
73.
▲
by
jenandre
14y ago
It looks comparable to me... I hadn't seen bouncy before though, so I'll have to check it out if I run into any problems with node-http-proxy. I agree, having the power to write your proxy code in javascript is really nice, especially compa
74.
▲
by
jenandre
14y ago
We're using this to reverse proxy websockets over SSL and it's simple and wonderfully stable. https://github.com/nodejitsu/node-http-proxy
75.
▲
by
jenandre
14y ago
If you have not shut down the machine, I would do a memory acquisition ( http://code.google.com/p/lime-forensics/ , can be analyzed with Volatility) and a raw disk acquisition (you can use dd) and get to someone for forensic investigation t
76.
▲
by
jenandre
14y ago
I don't think the RubyGems people were incompetent. The software serves its core purpose quite well (as a library delivery mechanism) and is quite reliable. But clearly they weren't thinking about security in decision, and what would happ
77.
▲
by
jenandre
14y ago
This story, and the recent RubyGems debacle should be teaching all of us one thing -- assume you can and will be hacked. Do you understand the implications (what data you are going to lose? what credibility?) Do you have a plan to deal wi
78.
▲
by
jenandre
14y ago
I think the arguments here are weak. Using a builder is extremely common in API wrappers like this (I just did this myself wrapping an API in Ruby). In the second example, the code you pointed out was similar really wasn't that similar.
79.
▲
by
jenandre
14y ago
"As an example, after university I discovered that when I'd been struggling alone to do my assignments and assuming all the guys were just finding it easy, all the guys were going round to each other's rooms, hanging out together, discussin
80.
▲
by
jenandre
14y ago
I think "even out" was a bad/lazy choice of words on my part. What I mean is, it will get to a point where the ratio of women in tech will be more or less equivalent to the ratio of women that WANT to be in tech. This may or may not be ex
81.
▲
by
jenandre
14y ago
I'm not saying her opinion is more or less valid than Faruk's, but in terms of the antecdotal "arguments" of her blog her authority may be less meaningful than, say, someone who works with 99% male neckbeards hacking linux kernel for 15 yea
82.
▲
by
jenandre
14y ago
I agree, it's a valid problem to deal with, but the wrong time/place for it. Remember, at an interview, you are putting the impression in that young person's mind: "wait, people won't take me seriously as a female?" -- that's something the
83.
▲
by
jenandre
14y ago
That's like saying "I work as a nurse in a hospital in the 1950s". Sure, you may see some sexism second hand, but if you're a female doctor in the same position, it's a totally different experience. The primary thing I didn't like about th
84.
▲
by
jenandre
14y ago
Ehh... Yeah. The original article was kind of a pile of crap, but it's hard to give this any credibility either. 1) She's only worked for 6 months 2) She works in UX, which is actually pretty well represented by women. My two cents from a
85.
▲
by
jenandre
14y ago
oh, ok, that makes it a lot more clear. thanks! If I were you I would consider a model where I would be to do a full scan, display only the top X vulnerabilities found, and simply charge more to show the rest of the results. Another thing I
86.
▲
by
jenandre
14y ago
"The direct comparison to competing tools just begs questions you don't want to answer." I agree. Additionally, I'm not sure who would actually subscribe to the paid version of this. Startups generally don't have a plethora of websites fo
87.
▲
by
jenandre
14y ago
dude, send me an email. I work for an infosec firm that would hire you in a sec, provided you aren't crazy (well, at least not crazier than the rest of us ;). jandre@gmail.com