Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kenmacd
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
21 ms
·
181.
▲
by
kenmacd
6y ago
Any advantages to this over https://www.zerotier.com/ ? Being p2p and using one PSK seems to make firewalling more difficult. ZeroTier's 'capability-based + tagging' rule engine is pretty amazing in that I can
182.
▲
by
kenmacd
6y ago
Okay, I see what you mean. I guess I assumed they wouldn't just accept that their server was hacked and not do a through investigation (or have someone do so), but I suppose that's mostly because I couldn't imagine not if it
183.
▲
by
kenmacd
6y ago
That does seem like a really good idea. If I make a protected branch that requires signed commits I really only care the signatures on the commits you'd see with `git log --first-parent`, as those are the ones by people I trust.
184.
▲
by
kenmacd
6y ago
Sorry, I'm not sure what you mean. The commit was almost certainly never meant to make it in to some server log, it was meant to be seen, and it was. In that way it 'burned' (ie destroyed) the backdoor in to the PHP code repo
185.
▲
by
kenmacd
6y ago
The other exploit, the one that allowed the commit to be injected.
186.
▲
by
kenmacd
6y ago
I don't see much point in discussing these latest commits. It's very unlikely they were actually malicious in intent (at least to PHP). The vulnerability that is of interest is the one that allowed these commits to be injected. Th
187.
▲
by
kenmacd
6y ago
You don't really pull down code though, you pull down commits. I'm not seeing a case where you sign the attackers code. You might sign a merge commit that has an attack commit somewhere in the tree, but that's very different
188.
▲
by
kenmacd
6y ago
Can you walk me a scenario where you and I are hosting our code on a malicious git server and Chuck can get their code in our our codebase? (assuming only signed commits)
189.
▲
by
kenmacd
6y ago
The commits say it was 'sold to zerodium, mid 2017', which would lead me to believe that someone has already been paid for this. I'd say the reason it doesn't hide better is because it's specifically meant not to hi
190.
▲
by
kenmacd
6y ago
It seems likely it was meant to be seen and fixed.
191.
▲
by
kenmacd
6y ago
The number of people with direct commit access is almost certainly less than the number of commits in a release though. Without signatures you have to verify every commit.
192.
▲
by
kenmacd
6y ago
It's not about the green label. A set if commits signed by some unknown person is a lot easier to spot and clean up. Looking at these commits they say mid-2017. Without signatures any previous commit could be by the same author.
193.
▲
by
kenmacd
6y ago
What do you mean?
194.
▲
by
kenmacd
6y ago
Do we know what that view is showing though? If you tapped in to a 3-month-old's visual system you would see things disappear too, but that's not the full story. Maybe it's the same here?
195.
▲
by
kenmacd
6y ago
Ignoring the rest of the stack for a minute, any crime group should be hesitant to us software connected to the US. National security letters are still very much a thing there. Signal has fought at least one and won ( https://sign
196.
▲
by
kenmacd
6y ago
The kernels is gpl-2 though, which afaik doesn't prevent tivoization
197.
▲
by
kenmacd
6y ago
I guess it depends on how likely you are to need to do that. Looking at b2 vs glacier deep it seems as long as you don't need the data more than every 2y that glacier still works out cheaper even with the high bandwidth costs.
198.
▲
by
kenmacd
6y ago
That's great, but companies are taking direct actions to make this more difficult or even illegal. Try to repair your tractor, or the software in an older phone/tablet/tv. The software will actively prevent it, and if you bre
199.
▲
by
kenmacd
6y ago
My TV runs WebOS. It's all open-source by LG. That still doesn't mean I can run my own code on it without LG specifically allowing me to.
200.
▲
by
kenmacd
6y ago
Sure, you can own that computer, but then you have to get online which requires another pile of knowledge to even hope at reducing now much you're tracked. This is not a reasonable solution. > People have to vote with their wallets
201.
▲
by
kenmacd
6y ago
While it might be possible for individuals to solve this problem with money, I feel you may be missing the forest for the trees. OP could just not connect to the internet, job done, right? The issue isn't so much they want privacy, i
202.
▲
by
kenmacd
6y ago
If you can't beat the NSA then you accept you can't beat any foreign governments spy agencies, right? That's part of the premise of the original article, that you can't have a private conversation. And your suggestion th
203.
▲
by
kenmacd
6y ago
Thank you. I had that set for my server, but I just wish there was a way to tell other servers not to send them. Disabling them on my server turns them in to a no-op, but it still has to process all those requests.
204.
▲
by
kenmacd
6y ago
My main issue with self-hosting has been federation bandwidth requirements. I joined the very quiet `#homeowners:matrix.org` announcement room, but because almost 600 other people are in there my server was inundated with presence messages
205.
▲
by
kenmacd
6y ago
A few comments on the post: - I would have liked to see a plug for gemini in the small-web space. - I'm not sure on lobste.rs. I like the content, but then Drew DeVault was banned so I wonder if the moderation is a little too arbitrary
206.
▲
by
kenmacd
6y ago
I don't know. It seems there can be quite an effect by shifting usage even slightly as power generation has to be real-time and handling the peaks costs up all more. Free-market pricing seems wrong, as would per-minute pricing, but som
207.
▲
by
kenmacd
10y ago
Ah yes, I remember the days before smartphones, and how it was impossible to get drugs.