Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
midas007
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
midas007
12y ago
There is none, OpenBSD uses CVS.
62.
▲
by
midas007
12y ago
Yup. I've done enterprise Rails consulting, which is almost a contradiction in terms. But it's possible and I've brought fixes like net ldap to work with AD. Edit: Can't take all the credit, client hacked together the
63.
▲
by
midas007
12y ago
Generally: don't trust anything from the outside world or anything that can transit untrusted infrastructure, that means check types and sanitize values before passing along. Break loudly and quickly to get attention for a fix. Keep
64.
▲
by
midas007
12y ago
Yup, it's one of those annoying things that makes run scripts more complicated. I rewrote phusion's runit setuser helper in Go because it didn't set all the right env vars. https://raw.githubusercontent.com/s
65.
▲
by
midas007
12y ago
It's cool. I think it's a good idea for them to get more than $4k AND code help from industry.
66.
▲
by
midas007
12y ago
Exactly. When a popular security project has no clear competition, a code "monopoly" may exist and it's much easier to get complacent. By introducing "competition," it tends to keep both projects adversarial and v
67.
▲
by
midas007
12y ago
Starting over on OpenSSL would cost about 20 mega USD, so that's unlikely. Currently, Ohloh esimates $6.7 mega USD in code cost, but figure 3x for a crypto lib due to inherent challenges of correctness. [0] [0] https://www.o
68.
▲
by
midas007
12y ago
Yeap, aware. But handing someone a multi-million lottery ticket can Anna Nicole Smith them. To start, 50k or so and see how they use it. More as they show ability to budget and results.
69.
▲
by
midas007
12y ago
Yes, this is the core worry. OpenSSL needs a press release to commit to a 360-review, top-to-bottom and engage more to lead the tech / stds WG to reduce complexity.
70.
▲
by
midas007
12y ago
Not switching, not angry... just hold them accountable to simplify their code base AND get the TLS WG to cut back on features. Heartbleed AND LibreSSL will force their hand to make changes.
71.
▲
by
midas007
12y ago
For a while, GnuTLS was faster to support newer TLS standards. But again, same boat of not taking a leadership approach to engage TLS WG. More implementations: https://en.wikipedia.org/wiki/Comparison_of_TLS_Implementa
72.
▲
by
midas007
12y ago
I think if Linux extended an olive branch to engage the three main BSD's, that would be a smart political and actual move. Religousity doesn't scale anything but egos and pitchfork-toting, angry people looking for an ego-oriented
73.
▲
by
midas007
12y ago
For 99% of uses, esp desktop, laptop, embedded... it's great. For that tiny percent of use cases where services can do all kinds of crazy things and there needs to be extra control, other things like supervisor, foreman_god, daemontool
74.
▲
by
midas007
12y ago
Might try the old-school daemontools, even though the commands are a bit different, it might be less work to get something going.
75.
▲
by
midas007
12y ago
No, sorry, but you don't know what you're talking about. daemontools is battled tested. We used it at Stanford on thousands of boxes. I used at a lot of shops, one in SF for example had 40k boxes (CentOS) and 6 ops staff, deploy
76.
▲
by
midas007
12y ago
Like removing long long multiplication just for Tandem.
77.
▲
by
midas007
12y ago
The point of LibreSSL is to be a potential competitor and an apparent existential threat to scare OpenSSL into getting its house in order.
78.
▲
by
midas007
12y ago
The Linux ecosystem has a shit-load of money and OpenBSD claims to not seen a dime of it, despite Linux'es use of OpenSSH Portable. [0] One would think something as vital as OpenSSH would get a reasonable share of funding, rather than
79.
▲
by
midas007
12y ago
OpenSSL needs a competitor to keep them honest, because clearly they've failed at their duty to push back on TLS WG features, failed at deprecating old code (Tandem multiplication, really?) and failed at writing secure code.
80.
▲
by
midas007
12y ago
Throwing money at a problem without competent leadership just makes matters works. The leadership has to have a grasp of what's wrong for any of that money to be used effectively. If history were any measure, it seems as likely as a
81.
▲
by
midas007
12y ago
This comes off as a few companies trying to throw money at a rotten crypto lib, when only leadership like Theo's way (minimalism, dropping features) would have a prayer of rescuing it. So giving OpenSSL more money doesn't make se
82.
▲
by
midas007
12y ago
Agreed. Even Theo sees the value in a popular but crappy crypto lib that works that just needs a good gutting. Starting from scratch would be costly reinventing a security wheel and likely incompatible with OpenSSL... IOW dead-on-arrival.
83.
▲
by
midas007
12y ago
Until there's a viable alternative, it looks like whining.
84.
▲
by
midas007
12y ago
runit (from daemontools) might not start things up in parallel, but it's a whole lot simpler and reliable. Phusion uses it instead of upstart in their base docker VM. Also a lot of enterprise shops use daemontools and runit, because t
85.
▲
by
midas007
12y ago
That's the honorable thing to do and it prevents sour grapes, bad press.
86.
▲
by
midas007
12y ago
The courtesy of asking should've happened though. Because it looks really bad to the public face person to not give credit where credit is due.
87.
▲
by
midas007
12y ago
That's an immediate average valuation boost of around 5x. (1.5 mil vs 300-ish k previously)
88.
▲
by
midas007
12y ago
There's no audio until 11:15.
89.
▲
by
midas007
12y ago
By the way, how apropos: Pandora just played George Thorogood's "Get a haircut." This reminds me of my father yelling at me when I was 16: "If you don't do good in school, you won't get into a good college, and
90.
▲
by
midas007
12y ago
Those sort of arguments are broad generalizations. It's impossible to say anything's impossible given determination, but the level of difficulty varies and it's context-dependent. It's harder to become wealthy if your ca
More ›