Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pquerna
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
pquerna
6y ago
Yes! Subresource Integrity is the exact counter-measure to this kind of attack: https://developer.mozilla.org/en-US/docs/Web/Security/Subres... However, on Twilio's documentation site, they do not i
32.
▲
by
pquerna
6y ago
This allowed you to forge an attestation of user identity from Apple for any App that was setup to consume it. Apple is acting as an IdP for its consumer ecosystem. It's definitely their problem. Third-party applications really have n
33.
▲
by
pquerna
7y ago
Many of our customers use SSH jumpboxes - its a natively supported feature of Okta Advanced Server Access / ScaleFT. From a post awhile back about using Bastions with ScaleFT: > One of our values at ScaleFT is to do our best to supp
34.
▲
by
pquerna
7y ago
(disclaimer, I was a founder of ScaleFT - acquired by Okta) This is exactly why many customers use Okta's Advanced Server Access: https://www.okta.com/products/advanced-server-access/ It does certificates as
35.
▲
Understanding and Exploiting Go’s DSA Verify Vulnerability
(paul.querna.org)
2 points
by
pquerna
7y ago
|
0 comments
36.
▲
by
pquerna
7y ago
Actually, the origin is supposed to send a `Vary` header if it changes behavior based on any header. So, if a client sends a 20kb `X-Oversized-Header`, when the server responds with a 400 -- it might be conceivable that it should include `V
37.
▲
by
pquerna
7y ago
Uber owns ~20 to ~30 percent of Grab, JFYI. They specifically exited the Uber brand from Singapore, and pushed Grab.
38.
▲
by
pquerna
8y ago
This isn't true in Retail. As far as I know, most of the top national retail brands in the US all use Azure or GCP as a policy over AWS.
39.
▲
by
pquerna
8y ago
The point is not about the minimum conformance, but rather the lock-in provided by the maximum configuration / extensions of each vendor. Take AWS EKS as an example. Their feature page[1] does mention conformance. Then it mentions 20
40.
▲
Okta acquires ScaleFT
(scaleft.com)
7 points
by
pquerna
8y ago
|
1 comments
41.
▲
by
pquerna
8y ago
I thought an "interesting" part of the change was actually how they made a 50% chance work for the extra read. They select across a closed channel twice -- and it results in a mostly even distribution of chance. for i := 0;
42.
▲
by
pquerna
8y ago
Love this article, but one thing it skipped on was more in-depth on Leap Seconds. You see, UTC, is kinda like another human-made-up timezone. Humans made up some rules, and UTC is a 37 second offset from TAI / International Atomic Tim
43.
▲
by
pquerna
8y ago
(ffjson author here) The main feature that ffjson has that most of the non-stdlib JSON libraries is stdlib compatibility. Eg, the same struct-tags and interfaces used in stdlib are used by ffjson. It's just trying move most of the re
44.
▲
Carbon Black S-1
(sec.gov)
66 points
by
pquerna
8y ago
|
36 comments
45.
▲
Docker Founder Solomon Hykes Announces Exit from Docker Inc
(eweek.com)
3 points
by
pquerna
9y ago
|
0 comments
46.
▲
SAML for SaaS Engineers
(medium.com)
2 points
by
pquerna
9y ago
|
0 comments
47.
▲
by
pquerna
9y ago
Partially agree, but the world is a big place. Lots of random internal resources do exist, even at big companies. Internal resources are owned by many separate teams. They implement AuthN / AuthZ on their own. Resources might prompt
48.
▲
by
pquerna
9y ago
Why can't the "Uberproxy" (in Google terms) consume Authentication mechanisms like spiffe[1] certificates and allow access to protected resources via those? Theres no reason a BeyondCorp architecture needs to make automation
49.
▲
by
pquerna
9y ago
In a ByeondCorp-like architecture, BYOD is a policy decision. Google as a POLICY has generally said no to all unmanaged machines. Some resources might require a managed machine by policy, but others may not. Imagine your Corporate Cafe men
50.
▲
by
pquerna
9y ago
not quite an infographic, but this site lets you slice the projects by different attributes: https://projects.apache.org/
51.
▲
by
pquerna
9y ago
Intertwined with this announcement of an new instance type, is that it uses a non-Xen hypervisor. Has anyone booted one yet? Is it KVM or something from scratch that AWS wrote?
52.
▲
by
pquerna
9y ago
Huh? What is your bar for "done growing". Because the rest of the normal publicly traded market doesn't grow revenue at 50+ percent a year. The average for the S&P 500 is something more like 3-4 percent revenue growth pe
53.
▲
by
pquerna
9y ago
According to LinkedIn data, Slack has >950 employees. Not 50. They are going "big". Enterprise. Places Basecamp or hipchat never did or will.
54.
▲
$10k host header
(sites.google.com)
6 points
by
pquerna
9y ago
|
0 comments
55.
▲
by
pquerna
9y ago
> We need governments to consider the damage to civilians that comes from hoarding these vulnerabilities and the use of these exploits. This whole incident is really raising the profile of the creation of "cyber weapons". They
56.
▲
by
pquerna
9y ago
Many Xeon SKUs include the Management Engine, which at times has seemed to share many of the features of AMT/SBT/etc, but its unclear on the exact attack vector for this vulnerability. Having said that, the ME is so opaque, the sa
57.
▲
by
pquerna
9y ago
I love the transparency of having your source on Github, but the license ambiguity isn't ideal when revealing this to the world: We are currently working on a new license for Kryptonite. For now, the code is released under Al
58.
▲
by
pquerna
10y ago
Yes, at least the Docker images that use glibc as their libc. (eg, most Debian/Ubuntu images) It looks like musl, which is used on Alpine Linux images for example, will only read it once, and then cache it: https://github.co
59.
▲
by
pquerna
10y ago
Good blog post explaining the behavior of glibc, I also saw this first hand when profiling Apache awhile back too: http://mail-archives.apache.org/mod_mbox/httpd-dev/201111.mb... https://github.com/
60.
▲
by
pquerna
10y ago
one example i know of: http://scaleworks.com/ they bought Filestack (formerly Fileppicker), Chargify and a few more Lew wrote about basically the same thing as sama earlier this month: https://medium.com/@le
More ›