Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kpeekhn
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
kpeekhn
7y ago
sorry, that is not what I mean. I don't care really about a badge, I care about the information being available so that it can be used in Bundler. Its about developers being given the choice in their gemfile to disallow installation of
2.
▲
by
kpeekhn
7y ago
It would have prevented this attack, so I'm not sure how its pointless. Obviously it doesn't fix everything. MFA is MFA. I don't know why anyone would take it as a guarantee that some third-party has audited all the code.
3.
▲
by
kpeekhn
7y ago
Is there a way to check if a gem was released by an account using MFA? If there was a "published with mfa" flag on every gem release and it would allow a Bundler setting to block installing gems without 2FA. Of course, this would
4.
▲
by
kpeekhn
7y ago
Isn't it normal to send passwords over HTTPS? This is usually how login and password reset work. Obviously you have to be careful they don't get logged.
5.
▲
by
kpeekhn
7y ago
AWS Trusted Advisor has warned of this since 2017: https://aws.amazon.com/about-aws/whats-new/2017/06/aws-trust...
6.
▲
Obtaining AWS credentials via SSRF attack to access instance metadata (April)
(medium.com)
2 points
by
kpeekhn
7y ago
|
0 comments