Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ntucker
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
ntucker
12y ago
Hmm, interesting suggestion. We wouldn't want to encrypt the entire row since we want to be able to query on specific columns (version in particular). My only excuse otherwise is that the goal was "disassociate the hashes from t
32.
▲
by
ntucker
12y ago
That's a great point about rolling the mapping key. We would likely be dropping all the rows in the password hash table for such an extreme event anyway, though, since otherwise there's no way to garbage collect the orphaned ones
33.
▲
by
ntucker
12y ago
Yes, but we currently have 2.1 million users, so that's still no small burden. And don't forget that's only after you brute forced the passwords.
34.
▲
by
ntucker
12y ago
Yeah, what I'm getting at is that those posts don't actually come right out and say your code should be calibrating itself regularly. They talk about selecting a work factor by benchmarking your current hardware, but they leave i
35.
▲
by
ntucker
12y ago
We have an approach to this which doesn't modify the password hashing at all, so it can't possibly reduce the strength: we store users and password hashes (currently bcrypt * ) in two separate tables, and the key used to look up a
36.
▲
by
ntucker
12y ago
Why do articles talking about this always talk about specific work factors and choosing a correct work factor, as if it's fixed? I thought good practice was to choose the work factor dynamically so it's calibrated to whatever har
37.
▲
by
ntucker
12y ago
Easy enough to include a version number as another arg with the identifier, and include that in the hash. Then all you have to do is keep track of what version each of your passwords is on, which is not sensitive information and could be s
38.
▲
by
ntucker
12y ago
Me too. And on 34, "You'll see that when the item reaches its flex basis, it stops flexing and something else has to flex" doesn't actually seem to be true. Can't tell if there's a bug or if it's somethi
39.
▲
by
ntucker
12y ago
Yeah, I look at it this way: Let's just focus on set B. You're staring at two doors. Some random process decided whether the things behind the doors are a goat and a car (2/3 of the time) or two goats (1/3 of the time
40.
▲
by
ntucker
12y ago
This looks really great. I watched the video and the rationale and tradeoffs they discussed sounded exactly like conversations we had back when building our system. The FUSE filesystem and agent panics are features that I wish I'd th
41.
▲
by
ntucker
12y ago
> At this point you could have used ssh right away, no? Any reason you used TLS + checking SSH agent instead? Yeah, using the SSH login method is actually quite slow for something you want to call at app startup on N instances during a p
42.
▲
by
ntucker
12y ago
My company has an internal bit of infrastructure that I think is a somewhat novel approach that allows us to never have any secrets stored unencrypted on disk. There's a server (a set of servers, actually, for redundancy) called the s
43.
▲
by
ntucker
12y ago
I used to have my retirement accounts at Fidelity. One day I needed some assistance with something I was seeing on their web UI, so I called them up. The support person said (not an exact quote, but the gist), "in order to see what y
44.
▲
by
ntucker
12y ago
Oh man, I just discovered the magic of tapping on an unused instrument on the bottom. Build a sequence using no sax and then start wailing away on saxy bill. Wonderful.
45.
▲
by
ntucker
12y ago
This is great. I laughed out loud when I discovered that notes you throw upward off the screen eventually come back down if you throw them straight up. Definitely getting my toddler to play with this. I have two suggestions: one is a tool
46.
▲
by
ntucker
12y ago
If you know your passwords are strong without those requirements, you could always come up with a standard prefix that adds no security but serves only to satisfy those rules. For example, all your passwords could begin with "$A1a&quo
47.
▲
by
ntucker
12y ago
Nope, but I've performed plenty of memory corruption over the years. :)
48.
▲
by
ntucker
12y ago
For the author's challenge about injecting code: I was able to get it to execute arbitrary code by making the compiled code longer than 128 bytes. When that happens, execution runs right into your data memory, which you can populate w
49.
▲
by
ntucker
12y ago
> A number of people spend significant time working for Google as 'visiting experts' (think professors on sabbatical) and that effort is hindered by the challenges of finding a nice place to stay, except there is housing for a