Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
noinsight
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
noinsight
2y ago
Yeah, I don't know if I would go testing such systems and then reporting the results under my own name (presumably)... I didn't see any comment about them being contracted to do this at least.
32.
▲
by
noinsight
2y ago
Tiling wm’s are a niche within a niche (Linux on the desktop)… you can’t really expect much engineering resources to be devoted to them.
33.
▲
by
noinsight
2y ago
Microsoft is like Google in this space. The previous iteration got killed right when it could have started gaining traction due to Microsoft's shift to "cross platform" and PowerShell Core. The previous iteration of the Local
34.
▲
by
noinsight
2y ago
Actually, arguably Windows has some impressive security features unseen on any other mainstream OS, they're just not used by default and - realistically - would be hard to enable on general purpose / non-corporate computers. For e
35.
▲
by
noinsight
2y ago
I've heard C-suite literally say: "if there's no logging, there can be no evidence"...
36.
▲
by
noinsight
2y ago
> Is it possible to limit the CA to only cover certain domain Sure, via the Name Constraints extension. Supposedly client support is spotty, but I have no experience in practice. Anything relatively modern could support it.
37.
▲
by
noinsight
2y ago
Here’s our friends at Amazon vs FTC: https://www.seattletimes.com/business/amazon/jassy-bezos-oth...
38.
▲
by
noinsight
2y ago
You can just use `-i` instead of `bash`. (This method indeed requires a shell configured, your method is needed with nologin.)
39.
▲
by
noinsight
2y ago
> I don't want any random machines behind my router to be able to open ports to the internet at large. The solution to this is a firewall, not NAT. As has always been. NAT is not a security feature and never has been. The fact that
40.
▲
by
noinsight
3y ago
Red Hat used to offer Red Hat Virtualization (RHV) - based on oVirt - but they killed that at approximately the same time this VMware deal was announced (supposedly coincidentally). Now they bolted on virtual machines onto their OpenShift c
41.
▲
by
noinsight
3y ago
You should just prepare an autounattend.xml to automate the install and be able to skip the OOBE wizard entirely - including the forced online account creation.
42.
▲
by
noinsight
3y ago
You could be using IPv6 ULA addresses internally on your home network to have static addressing. The real solution is moving to DNS names though with your router maintaining them based on DHCP leases or just using multicast DNS (Zeroconf).
43.
▲
by
noinsight
3y ago
They rebranded and split the company. WithSecure is the enterprise side, F-Secure is the consumer side.
44.
▲
by
noinsight
4y ago
If you implement an allowlisting proxy, the number of required domains for M365 / Azure is something like 120 [1]. Google basically requires three, tunnel.cloudproxy.app, *.google.com and *.googleapis.com. Amazon requires *.aws.amazon.
45.
▲
by
noinsight
4y ago
No. Microsoft will buy Canonical for Ubuntu and that sweet, sweet developer mindshare. Ubuntu is the developer distro after all. Ubuntu will become Microsoft Linux.
46.
▲
by
noinsight
4y ago
Central Banking 101 by Joseph Wang is the obvious choice and it's not even mentioned here...
47.
▲
by
noinsight
4y ago
Yeah these cables are definitely a minefield… The solution is to look for an officially certified cable, they will work as advertised. Displayport.org has a database of certified products. I already ran into this in 2016 when I got my 4K di
48.
▲
by
noinsight
5y ago
So how do you implement MFA in your SOCKS5 proxy?
49.
▲
by
noinsight
5y ago
You can use smart cards as plain SSH keypairs and sshd will of course log the fingerprint of the key used to authenticate. That's pretty foolproof accountability.
50.
▲
by
noinsight
5y ago
I don't think there's any nation state level actors or fancy zero days in play here, just ordinary organized crime. This appears to be very effective and profitable. Most corporate networks are very bad when it comes to administra
51.
▲
by
noinsight
5y ago
Even then, you can buy a Yubico YubiHSM device for 650€.
52.
▲
by
noinsight
6y ago
> ”Ubiquiti had negligent logging (no access logging on databases) so it was unable to prove or disprove what they accessed” Perversely, this is exactly the logging that you want to have in place in case of a breach. You can then (factua
53.
▲
by
noinsight
6y ago
Finland. https://en.wikipedia.org/wiki/Onkalo_spent_nuclear_fuel_repo...
54.
▲
by
noinsight
6y ago
It doesn't. Python would need to add support for it. The built-in scripting languages do, PowerShell enters constrained language mode and IIRC something also happens to VBScript/JScript, haven't even looked at those.
55.
▲
by
noinsight
6y ago
That is what Windows Defender Application Control does. It's probably the most cutting edge solution on the market actually. It's a pure whitelisting solution where every single executable and kernel driver needs to have an approv
56.
▲
by
noinsight
6y ago
Interesting that this creates virtual machines... I've been thinking of the same thing for a while now but I was thinking of utilizing containers instead of virtual machines. It would be sweet to have a jump box that creates an isolate
57.
▲
by
noinsight
6y ago
There's nothing simple about shell scripts. Idempotency is the main thing - and a great thing.
58.
▲
by
noinsight
6y ago
In Finland all school aged children (afaik) were vaccinated against the recent swine flu outbreak and then it was discovered it led to narcolepsy in some cases... On phone atm so no sources.
59.
▲
by
noinsight
6y ago
Unless Google arbitrarily decides to close your account (as has been known to happen) with no way to contact a human to correct things...
60.
▲
by
noinsight
6y ago
The equivalent to `set -e` is setting the `ErrorActionPreference` variable to "Stop" - all errors become terminating.
More ›