Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ppierald
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
ppierald
7y ago
I just got back from a trip to Death Valley. While it was extremely hot (116F), it was very beautiful. The mountains are where you probably want to go for hiking and camping. The valley floor is where all the heat gets trapped in. I highly
32.
▲
by
ppierald
7y ago
Bummer for the company and I wish them well as they navigate the incident response waters. What I found interesting from the article was If users created or changed their password after March 14, 2012, it is hashed with a function called bc
33.
▲
by
ppierald
8y ago
We use it to "set a timer for 10 minutes" when cooking something and "what's the weather for tomorrow" to know whether to bring a coat or not.
34.
▲
by
ppierald
8y ago
I guess they are solving similar problem, but this is automatically sending the email to the recipient. Also the integration with GPG may be preferable to some people if they don't have an extensive community of Keybase peers.
35.
▲
by
ppierald
8y ago
I would agree with this sentiment, however, there are a number of things that you can to to make the job of the attacker harder, or to notice internally when there is inappropriate usage. Service abstractions to encrypt/decrypt the dat
36.
▲
by
ppierald
8y ago
vault ( https://vaultproject.io ) uses Shamir to generate shares for operators to unseal the vault. In the latest release (1.0beta), vault seal keys can be wrapped with something like AWS KMS which allow for operator-less unsealin
37.
▲
by
ppierald
8y ago
In the 90's this was rare and a big lure for candidates. Now it's table stakes.
38.
▲
by
ppierald
8y ago
We're still removing your code. Thanks buf. :)
39.
▲
by
ppierald
8y ago
Makes me think of the recent XKCD on voting machine software: https://xkcd.com/2030/
40.
▲
by
ppierald
9y ago
There is a lot of commentary about the use of vault as an alternative, number of secrets needed, etc. I think the inclusion of Secrets Manager is a great addition for AWS and will definitely help people get better control over their secrets
41.
▲
by
ppierald
9y ago
Go nearly anywhere in Argentina and you will find mate. People walk around with a thermos of hot water and sip all day. It is a shared cultural experience too like saying hello. You see a friend, greet them, then offer them some mate. Our S
42.
▲
by
ppierald
9y ago
> Finally, we’d like to assure our customers and partners that we take security at Mailgun very seriously. So very seriously that they don't even use https for their blog...
43.
▲
by
ppierald
10y ago
"Between 7:20 AM and 8:04 AM PST we observed connectivity issues with an external provider outside of our network that impacted internet connectivity between some customer networks and the US-EAST-1 Region. Connectivity within the Regi
44.
▲
by
ppierald
10y ago
Are people reporting issues coming from the US or from other parts of the world. We are not seeing any issues from the US, but other customers and monitoring points are reporting sporadic blips.
45.
▲
by
ppierald
10y ago
$58 in 2014, $120 today? Follow the money.
46.
▲
by
ppierald
10y ago
My anecdotal evidence shows a dramatic shift of my 20-something and 30-something year old co-workers to Oakland from SF due to affordability. Oakland is close, cheaper (though rising), diverse, and close by BART. This is probably putting a
47.
▲
by
ppierald
10y ago
Thanks! That was a super helpful response!
48.
▲
by
ppierald
10y ago
I always thought the term Tofu was "mojibake": https://en.wikipedia.org/wiki/Mojibake Wikipedia disambiguation page: for "Tofu" mentions: Slang for the empty boxes shown in place of undisplayable c
49.
▲
by
ppierald
10y ago
I would be interested in the details of the storage mechanism of the global pepper. Is this in an HSM? For AWS customers, something like KMS? There are then huge operational and redundancy issues to think about. Failovers for your HSM. Hand
50.
▲
by
ppierald
10y ago
The u= parameter in the OPs article also is vulnerable (even if http/https are whitelisted, file:// blacklisted, etc) to the #10 vulnerability on the OWASP Top Ten 2013 list, namely Unvalidated Rediredcts and Forwards. https
51.
▲
by
ppierald
10y ago
Developer productivity increases by an order of magnitude.
52.
▲
by
ppierald
10y ago
Sue Decker, ex-Yahoo CFO & President sits on the Board of Directors for Birkshire Hathaway. I'm sure she has plenty of insight to the value of the company, and the complexities of its business.
53.
▲
by
ppierald
11y ago
My undertanding was that the Customer Master Key was stored in an HSM, but your customer-generated keys were not. I might be wrong about that. So if true, AWS employees would not have access to your root key material, but the definitely the
54.
▲
by
ppierald
11y ago
I totally bought a password and it was the best $2 I spent all weekend. I have no intention of using it, but more of a pat on the back telling her to "keep it up" and that people approve. Last thing she needs is telling her she&#x
55.
▲
by
ppierald
11y ago
<script src="..." is very dangerous. At best, you can vet the src and check to see if it's benign or not. Often times, that vendor and their "1-line of javascript to get our whiz-bang service" in turn loads other
56.
▲
by
ppierald
11y ago
Another good article on git-signing: http://mikegerwitz.com/papers/git-horror-story
57.
▲
by
ppierald
11y ago
I can imagine a scenario where a malicious employee is intentionally injecting malicious code (backdoor, whatever) and wants that commit tied back to someone else (their enemy, boss).
58.
▲
by
ppierald
11y ago
The one thing that is appealing to an "AWS shop" and something that GitHub and other services have a harder time emulating is the integration with IAM (user authentication and provisioning) and the CloudTrail (audit trails). For a
59.
▲
by
ppierald
12y ago
Agreed. Just want to point it out to those that jump in head first without understanding the consequences of that action. You might get fired from your job for doing this or severly reprimanded. You might unwittingly cause a production data
60.
▲
by
ppierald
12y ago
It's important to know that your content, intellectual property, and possibly confidential user data including full http request/responses are being proxied by this service. Their privacy policy is vague about what they will do wi
More ›