Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pquerna
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
91.
▲
Fixing US Goverment Vulnerability Management Policies
(scaleft.com)
3 points
by
pquerna
10y ago
|
0 comments
92.
▲
Frederick Funston
(en.wikipedia.org)
1 points
by
pquerna
10y ago
|
0 comments
93.
▲
Letter of Resignation from the Palo Alto Planning and Transportation Commission
(medium.com)
23 points
by
pquerna
10y ago
|
2 comments
94.
▲
Sharing Servers for International Friendship Day
(coreos.com)
10 points
by
pquerna
10y ago
|
0 comments
95.
▲
China National Highway 110 traffic jam
(en.wikipedia.org)
1 points
by
pquerna
10y ago
|
0 comments
96.
▲
Betting on BeyondCorp and Chromebooks
(scaleft.com)
6 points
by
pquerna
10y ago
|
2 comments
97.
▲
FAA announces a new set of blanket UAS regulations
(airware.com)
1 points
by
pquerna
10y ago
|
0 comments
98.
▲
by
pquerna
10y ago
As deployed, most OpenStack SDNs will use OVS or similar software on top of a (xen,kvm) Hypervisor, connected to some kind of central controller, which just maybe would look kinda like OpenFlow. But all of this is running as an overlay on
99.
▲
by
pquerna
10y ago
Neat project. What we've been doing is using provider (software) firewalls for whitelisting IPs at the bastion level. In AWS we have a security group just for the Bastion inbound, and adding/removing IPs to that on-demand to allow
100.
▲
by
pquerna
10y ago
From Wikipedia: >> The 9/11 Commission stated in their final report that the "9/11 plotters eventually spent somewhere between $400,000 and $500,000 to plan and conduct their attack" Still a non-trivial amount of f
101.
▲
by
pquerna
10y ago
That is a massively simplification and frankly very wrong. Several of the 9/11 Hijackers enrolled in flight schools: https://en.wikipedia.org/wiki/Hijackers_in_the_September_11_... https://en.wikipedia.
102.
▲
by
pquerna
10y ago
co-founder here, happy to answer any questions! We've been working on making ephemeral client certificates easy to use, and bridging SSH & RDP to things like Google Apps authentication is an example of what you can do once you get
103.
▲
Show HN: ScaleFT, Login to Servers Using Google Apps Auth
(scaleft.com)
25 points
by
pquerna
10y ago
|
1 comments
104.
▲
by
pquerna
10y ago
sshd and apache2 for example both support systemd socket activation -- whether distributions actually do that is up to the distros. CoreOS for example runs sshd via socket activation.
105.
▲
by
pquerna
10y ago
I don't expect a candidate to have STAR response out of the box at all. I would ask each part of STAR, directly to the candidate. The goal is to actually understand what the candidate did, less what "we" did. - Tell me about
106.
▲
by
pquerna
10y ago
I wrote this article in 2014, but left Rackspace a year ago. The STAR answering format is the single clearest thing I'll take with me as a good interview practice. It keeps both the interviewer and interviewee honest and on track. I f
107.
▲
by
pquerna
11y ago
It depends on the CDN, but for example Fastly calls what the op was suggesting "origin shield": https://docs.fastly.com/guides/performance-tuning/shielding
108.
▲
by
pquerna
11y ago
Just happened to us this weekend, exact same situation. I wonder if it is because USPS Weekend delivery isn't the normal "route" person, and they just don't try to get into multi-unit mailrooms?
109.
▲
by
pquerna
11y ago
If you are building a new app, I'd really suggest checking out gRPC: http://www.grpc.io/ The combination of an HTTP/2 stack w/ protocol buffers and libraries in everything you'd write a mobile app in is
110.
▲
by
pquerna
11y ago
Aassuming this was real, Apple would store the private key in Keychain[1]. Keychain is encrypted with your login password generally, and can have an ACL to only allow iTunes.app as an allowed application without further user prompting. [1]
111.
▲
by
pquerna
11y ago
For example, Node.js still has test case failures when running on musl on Alpine Linux: https://github.com/nodejs/docker-iojs/issues/44#issuecomment... Most apps will work out of the box, but you can see in t
112.
▲
by
pquerna
11y ago
David Sacks joined Zenefits about 13 months ago, so I presume while as COO he is somewhat responsible, it seems far more likely his opinions being different from Conrad is what led to Conrard's removal.
113.
▲
NSA's Hacker-In-Chief: We Don't Need Zero-Days to Get Inside Your Network
(motherboard.vice.com)
15 points
by
pquerna
11y ago
|
2 comments
114.
▲
by
pquerna
11y ago
Right, the ability for an attacker to change an XML file like this could be considered two separate issues. Things like this is why The Update Framework (TUF) Specification was created: https://theupdateframework.github.io/
115.
▲
by
pquerna
11y ago
(disclaimer, I'm a co-founder of ScaleFT) If you are interested in a commercial solution in this space, check out ScaleFT. Besides the dynamic SSH certificates, we also track both SSH keys used and access events, which you can then pu
116.
▲
by
pquerna
11y ago
I think the right initial metric is “do any users love our product so much they spontaneously tell other people to use it?” Many larger companies use "Net Promoter Score", as a way of telling this: https://en.wikipedi
117.
▲
by
pquerna
11y ago
The main issue identified by Qualys is a more generic memory disclosure bug: https://www.qualys.com/2016/01/14/cve-2016-0777-cve-2016-077... This means they are basically able to dump the memory of just the r
118.
▲
by
pquerna
11y ago
A SSH private key is just some bytes. Once you have access to it, you have access to it forever in the future. RSA doesn't care if you are an "authorized employee". A static SSH key for a single human is already risky over a
119.
▲
by
pquerna
11y ago
Hi, I'm one of the main authors (along with others, it is a community driven project) of the Event MPM for Apache. On Benchmarks and timelines: I agree that 2.2+ was not widely available for many years due to the update cycle of linux
120.
▲
by
pquerna
11y ago
This is very different than the Target hack -- we have become numb to credit card focused hacks -- we all know the drill, we just get a new card in the mail a few days later, and the banks are pretty good at detecting fraud: http:/&#x
More ›