Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mschempp
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
1.
▲
by
mschempp
6mo ago
Not sure I understand you correctly, but the study I linked shows that mother's earnings drop significantly after the First child. That has nothing to do with the significant monetary cost of children, which are added on top of that.
2.
▲
by
mschempp
6mo ago
Most of the gender pay gap can be attributed to children: See https://www.henrikkleven.com/research/published/kleven-landa... On page 43, it shows very clearly, that women who do not have children have almost no e
3.
▲
by
mschempp
6mo ago
Not sure where this "pushback" comment is directed at, but I was not trying to Push back - I am agreeing with you in general. Just because institutions are oversimplifying doesn't mean we have to
4.
▲
by
mschempp
6mo ago
"There is definitely social sexism being surfaced by the wage gap statistic, but it's against men, not women." I would say against both genders.
5.
▲
by
mschempp
6mo ago
As a father, I really can't understand how every article about this topic talks about as if fathers and mothers are just interchangeable. We are not. Mothers carry their child for ~9 months, they give birth to that child. The bond betw
6.
▲
by
mschempp
2y ago
btw.: ruroco DOES prevent replay attacks, by saving the deadline (which is in ns) in a blocklist. It does not matter if the deadline has "passed", the deadline is added to the blocklist as soon as the packet reaches the server and
7.
▲
by
mschempp
2y ago
a replay attack won't work, because every UDP packet data has deadline in nanoseconds. Once this UDP packet reaches the server the deadline will be added to the blocklist. If an attacker sends the same packet again, the server will che
8.
▲
by
mschempp
2y ago
hmmm just validated my implementation the deadline that is sent from the client is being added to the blocklist after the command was executed, so sending the same packet again will not work, because the deadline (which is in nanoseconds) i
9.
▲
by
mschempp
2y ago
"Modern port knocking also incorporates secure cryptographic hashes." Are you referring to fwknop? Thats not "port knocking" but Single Packet Authorization. That is very different from port knocking. How can one incorpo
10.
▲
by
mschempp
2y ago
the client COULD use something like https://www.ipify.org/ to get the IP, which can then be used as an additional client argument. But if an adversary uses the SAME network, then the IP address that the server sees will be
11.
▲
by
mschempp
2y ago
I think what rmholt means is that ruroco does not improve security in the sense, that it has stronger and safer encryption/algorithms/... but that it merely "hides" existing services. I would argue that it does improve s
12.
▲
by
mschempp
2y ago
Thanks for the feedback and pointing out ostiary. Fixing replay attacks is on my todo list, maybe I can learn some things from how ostiary does it. Kind advice from my PoV: Your comment could be read as "your project is shit, there is
13.
▲
by
mschempp
2y ago
that is correct. The configuration is not even ufw specific, you could run any command that you like. This means you could also, for example, disable or enable certain nginx configurations.
14.
▲
by
mschempp
2y ago
You are right, but if you are in a network that blocks every packet that is sent to any port which is not 80 or 443 your port knocking capabilities are very limited. Ultimately reading firewall logs to do port knocking is most secure way, b
15.
▲
by
mschempp
2y ago
"Maybe the OP simply hasn't yet heard about or used Wireguard." I have, but I do not want to run a VPN solution on my private sever, for which I barely have any need. Also Wireguard, although VERY secure is still not "si
16.
▲
by
mschempp
2y ago
"The example shows you opening port 80 (HTTP standard port)" that's because I run my ssh on port 80, but that's not standard, so I agree that it's confusing. Thanks for pointing it out. I will fix it :)
17.
▲
by
mschempp
2y ago
yes thats correct. Should have stated that in the headline
18.
▲
by
mschempp
2y ago
Thanks for the link. Looks interesting!
19.
▲
by
mschempp
2y ago
I used port knocking in the description, because anyone here probably knows what port knocking is and ruroco is kind of similar to that. Ruroco can be used for more than just keeping sshd logs clean, for example I could also enable a servic
20.
▲
by
mschempp
2y ago
One of the reason why I wrote ruroco is, that I can run this from probably anywhere in the world, if I put the service on port 53, because thats DNS and that does not get blocked by any wifi whatsoever. I used to use port knocking, but at s
21.
▲
by
mschempp
2y ago
"+ Relatively infrequent access by limited # of people to servers which are not top targets for attacks. Solutions like the one above are great for this." Thats exactly what I'm using it for - I'm the only one on my serv
22.
▲
by
mschempp
2y ago
RSA
23.
▲
by
mschempp
2y ago
Thanks for the feedback! Will definitely put some thought into it.
24.
▲
by
mschempp
2y ago
Did not know fwknop, but since it came up multiple times in this thread, I'll look into it. I have no protection against DoS attacks, but I'm working on it (there is also a WIP in the README about that :) )
25.
▲
by
mschempp
2y ago
I'm not good at describing things easily. I will put the hn description on top of the git repo :) Thanks for the feedback!
26.
▲
by
mschempp
2y ago
RSA allows encrypting with the private key, see https://github.com/beac0n/ruroco/blob/ce766751b51c8ff6246a2b... and decrypt with the public key, see https://github.com/beac0n/ruroco/
27.
▲
by
mschempp
2y ago
Funny. Haven't thought of that, probably because I'm german. The way I pronounce it is with long vowels. So in an extreme way it would be ruuurooocooo :)
28.
▲
by
mschempp
2y ago
Hi Tepix. Im the author of the tool. Thanks for the feedback! It doesn't describe how it prevents that attack, because it doesn't prevent this attack :). As someone else wrote, I could put the IP address of the sender into the enc
29.
▲
Show HN: Ruroco – like port knocking, but better
(github.com)
127 points
by
mschempp
2y ago
|
102 comments
30.
▲
by
mschempp
4y ago
Maddox.ai | Software Engineers | Full-time | German + English | Germany | REMOTE (CET +/-2 hours), Berlin, Cologne, Tuebingen https://www.maddox.ai/en/ | https://maddox-ai-gmbh.jobs.personio.de/?la
More ›