Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
netsectoday
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
91.
▲
by
netsectoday
7y ago
I've been using Docker Swarm in production for about 2 years now... processing about 1TB of data / month across 30+ containers. The networking and routing has been rock solid except for that one day that the Docker dev team, in on
92.
▲
by
netsectoday
7y ago
Mirantis is just some cloud hosting provider and from what I can tell it has no connection to Docker. I'm generally interested in why all the FUD around Docker and Swarm. Can you support these FUD statements with some legit news storie
93.
▲
by
netsectoday
7y ago
Without HSTS preload anyone on your local network can arp/dns spoof your traffic, MITM you, and automatically inject malicious javascript (cryptominers, credential-stealers, etc.), access all of the page content, and manipulate the pag
94.
▲
by
netsectoday
7y ago
I block all Tor traffic with iptables and ipset - which allows O(log n) lookup time for each request when checking it against the Tor list. I wonder if this would have been your end-all solution. http://ipset.netfilter.org/i
95.
▲
by
netsectoday
7y ago
Practice some red team exercises against your apps and infrastructure, or do it against a site in the wild and responsibly disclose what you found to them - then harden your systems against your tactics.
96.
▲
by
netsectoday
7y ago
Here is a server vulnerability matrix... pretty much if you are running HTTP/2 you are exposed and your vendor has a patch waiting for you. https://vuls.cert.org/confluence/pages/viewpage.action?pageI...
97.
▲
by
netsectoday
7y ago
I'm pretty sure the crypto exchanges own this data and will be hostile when they see it being repackaged and resold like this.
98.
▲
by
netsectoday
7y ago
Look everyone! We found a product manager for the Boeing 737 Max! How was your tenure at Equifax? Seriously, though... A workplace with this mentality has a high-turnover rate from burnout. Things keeps breaking, things are perpetually behi
99.
▲
by
netsectoday
7y ago
The employee has responded to all other questions that don't touch on the specifics of their fraud detection algo. After those responses it sounds like they have a behavioral threshold that looks something like: "x number of video
100.
▲
by
netsectoday
7y ago
So was this a UI-level filter that failed and let un-sanitized html hit the server, which triggered the auto-block?
101.
▲
by
netsectoday
7y ago
You navigate these types of controls every day without realizing it. The web is now a nuclear testing range and these insanely aggressive countermeasures are necessary to operate. My assumption here is that they have a back-end system auto-
102.
▲
by
netsectoday
7y ago
amen
103.
▲
by
netsectoday
7y ago
> My butt starts to pucker again above 95%, because it’s all lies. With the way you are describing false-positives; it sounds like most of your tests are written as integration or feature specs. Exercising the UI at 95% coverage is insan
104.
▲
by
netsectoday
7y ago
Bumping the test coverage up past 90% definitely has lines re-run multiple times, with core logic even being re-executed possibly hundreds of times. This is absolutely ok! Your main purpose of writing tests is to make sure when you change b
105.
▲
by
netsectoday
7y ago
* you've worked for companies That's all I can see in your description. At the end of the day you revealed that you are grossly under qualified with shit programming standards, a huge ego, and an abusive communication style. And w
106.
▲
by
netsectoday
7y ago
Yeah, didn't tackle that one... I highlighted the fact that ignoring OOP is a weakness for @foobar_ and their response was essentially "you force every problem into objects and you suck". Interacting with this person is like
107.
▲
by
netsectoday
7y ago
I've run my own startups (4), been through startups, ran the corporate race, successfully exited, successfully failed, ran successful projects, ran successful dev teams, ran some projects and dev teams into the ground, and now I'm
108.
▲
by
netsectoday
7y ago
Not quite sure what I'm projecting here... Your statement "I would probably classify myself as a 10x" is very misguided, and your response here is a poor attempt at manipulation. I only spoke up because I saw others agreeing
109.
▲
by
netsectoday
7y ago
Thanks, I was also wrong because there is no such thing as expert syndrome - it's called the Dunning-Kruger effect. This doesn't change my belief that all of foobar_'s coworkers hate him/her.
110.
▲
by
netsectoday
7y ago
* avoiding object-oriented programming * avoiding testing * avoiding security * avoiding documentation * fixating on known platforms * a highly inflated ego * demeaning other programmers * arguing with experienced programmers during code re
111.
▲
by
netsectoday
7y ago
Here are some indicators I've seen from 10x and 100x: The 10x person fits very well in their organization. They are admired by upper-management for their ability to quickly comprehend, estimate, and deliver solutions to problems. They
112.
▲
by
netsectoday
7y ago
In production since 2016 with 3 x Raspberry Pi 3s. Very reliable - they only need a reboot once a year. These guys are hardcore - processing bursts of thousands of records from a serial interface 24 hours a day 7 days a week and shuffling i
113.
▲
by
netsectoday
7y ago
They really have no clue what they are doing... No security headers and their SSL is insecure. Someone needs to tell them to shut their servers down right now. Directly from their website: "Patrick Brown - Chief Technology Officer. Mr.
114.
▲
by
netsectoday
7y ago
Yes, you are right. You need to balance that tradeoff with your application/business risk profile. High-security applications or those not tailored for mobile can still lock the IP to the JWT.
115.
▲
by
netsectoday
7y ago
Cool article - but the author didn't even scrape the surface of making this secure. Don't even use this in development. 1. Make sure to use HTTPS (TLS v1.2 or v1.3). 2. Tag your cookie as HttpOnly so only Node can read it (not the
116.
▲
by
netsectoday
7y ago
> maybe 1 in about 50-60 job applications Are you submitting your resume with a script? This sounds like you are part of the problem. What if you got 50-60 low-quality job offers each day? You'd probably do the same thing: respond t
117.
▲
by
netsectoday
7y ago
This seems to be the script. Has anyone else NOT experienced this?
118.
▲
by
netsectoday
7y ago
> because implementing the totally correct way is too time-consuming and expensive for the client There's your problem! > think about this as a structural problem of web development, not a problem of a dev not understanding enoug
119.
▲
by
netsectoday
7y ago
I'm not sure redesigning this would help because it's just a mechanism to define an ACL. Yes, it's hard to implement correctly and maintain, but that's because of the wild number of external dependencies developers toss
120.
▲
by
netsectoday
7y ago
As a full-stack dev I recently locked down my security headers and I have a new perspective on what a web browser actually is. Before I saw all web-browsers as just a window that renders web content and enables user interaction. Now, I see
More ›