Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jik
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
jik
10y ago
Amusingly, someone who works at LiveJournal just submitted a pull request to make the code shorter.
32.
▲
Delete your LiveJournal account without accepting the new ToS
(github.com)
3 points
by
jik
10y ago
|
1 comments
33.
▲
Show HN: Coal Mine – An Open-Source, Python3 Alternative to Dead Man's Snitch
(pypi.python.org)
13 points
by
jik
12y ago
|
0 comments
34.
▲
by
jik
12y ago
We don't look at the source code of algorithms submitted to the contests, and the code is not made public unless the entrant chooses to share it in our forum. (I work for Quantopian.)
35.
▲
RCN blocking inbound SSH after allowing it for many years
(blog.kamens.us)
2 points
by
jik
12y ago
|
1 comments
36.
▲
by
jik
12y ago
It looks like this was fixed on October 7.
37.
▲
by
jik
12y ago
Still broken as of less than an hour ago.
38.
▲
by
jik
12y ago
Still broken this morning.
39.
▲
by
jik
12y ago
I received the following from AWS support at 9:33am US/Eastern today (8+ hours ago): "... We have now been able to reproduce the behavior in tests similar to your scripts to pinpoint where the UDP packets were disappearing, and ye
40.
▲
by
jik
12y ago
We're seeing it in multiple AZ's, so I don't think it's isolated to just one. And I don't know if you were aware of this (I learned it just recently), but AZ's are labeled differently for different customers, i
41.
▲
by
jik
12y ago
Here's the script I'm running from cron both inside AWS and outside it at one minute past the hour (with our internal DNS domain replaced with example.com): #!/bin/bash tf=/tmp/out.$$ for turn in $(ye
42.
▲
Ask HN: Intermittent EC2 DNS failures at 1 minute past the hour
16 points
by
jik
12y ago
|
21 comments
43.
▲
by
jik
12y ago
Quantopian ( https://www.quantopian.com/about ), Boston, MA Quantopian is hiring software and operations engineers to help us disrupt the world of finance. We've built the world's first web-based algorithmic trading
44.
▲
by
jik
13y ago
I'm wondering if this is too specific. The other alternative proposal that someone floated in response to my proposal -- a file containing just CVE numbers and timestamps for when the site was no longer vulnerable to each of them -- se
45.
▲
by
jik
13y ago
MITM attacks require far more sophistication and many more moving parts than just stealing data from a web server's memory. Just because you have the SSL cert's key doesn't mean you have the ability to use it to MITM a site.
46.
▲
by
jik
13y ago
I could live with simplifying the proposal to just list CVE numbers and timestamps.
47.
▲
by
jik
13y ago
As others have pointed out, if they have metasploit installed they're just going to scan your site for all known vulnerabilities in a matter of minutes. Making it easier for the good guys to find out whether you've patched Heartbl
48.
▲
by
jik
13y ago
>What site operator would install something which turns users away? The point of this proposal is mostly to enable sites to tell users that they _have_ been fixed (and when), not to tell users that they _haven't_. Having said that,
49.
▲
by
jik
13y ago
We use CloudFlare at work, but I had not previously foreseen the possibility that it might be needed for my blog.
50.
▲
by
jik
13y ago
>Your proposal may want to follow RFC 5785 aka "/.well-known/" This is addressed in a comment below the blog posting. >That said, I don't see what problem you're solving or why the solution you propose sh
51.
▲
by
jik
13y ago
Well, yes, frankly, they should. ;-) Frankly, it doesn't matter whether they do or not, because if a vulnerability is known and there are exploits for it in the wild, then hackers are simply going to try to exploit it, not check /
52.
▲
by
jik
13y ago
It's obviously going to be a lot easier to convince maintainers of web sites with wildly varying stacks to drop a plain-text file into the root directory of their site, then it is going to be to convince them to implement a universal p
53.
▲
by
jik
13y ago
That requires keeping a huge amount of state and doing a lot more complicated programming then just checking a few fields in a YAML file.
54.
▲
by
jik
13y ago
Great, and how do the users keep track of which of the hundreds of sites they use have done that? With the idea I'm proposing, it's possible to automate this _in the client_, such that users can proactively defend themselves again
55.
▲
by
jik
13y ago
Sorry. My blog doesn't usually get this much traffic. ;-) Trying to increase the number of servers but httpd isn't cooperating.
56.
▲
by
jik
13y ago
Yeah, I added an update to the bottom of the posting mentioning the possibility of generalizing it.
57.
▲
by
jik
13y ago
I hardly think that a security hole, no matter how large, at a single web site, is on the same magnitude as one security hole that probably impacts the majority of web sites on the internet and could have been taken advantage of completely
58.
▲
We need a “/heartbleed.txt” standard, and we need it ASAP
(blog.kamens.us)
34 points
by
jik
13y ago
|
50 comments
59.
▲
by
jik
13y ago
According to whois for namecheap.com, the DNS for that domain is hosted on dynect.net, and "host status.namecheap.com" resolves just fine (to 204.232.212.56), so it does not appear to be a DNS issue that is preventing your status
60.
▲
by
jik
13y ago
If you're as big as NameCheap, you can afford to pay CloudFlare or somebody like it to protect your status page.
More ›