Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pquerna
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
17 ms
·
121.
▲
by
pquerna
11y ago
While the FastMail shutting down XMPP is about low usage, the real cause is that Federated Chat failed to work. Federation is something that is rarely promoted in modern ecosystems. Before Twitter/Facebook, we had RSS/Atom, but th
122.
▲
Securing AWS Credentials on Engineer's Machines
(99designs.com)
3 points
by
pquerna
11y ago
|
0 comments
123.
▲
by
pquerna
11y ago
Using the OpenSSH Certificate format, many of the common features from X.509, like intermediates, cross signing, key usage attributes or restricting access based on an attribute in the certificate are not part of the spec: https:/
124.
▲
by
pquerna
11y ago
Other comments are are good starts. Another method would be to add a headers to the response: Server-Push: /relative/url Then have an output filter pull them out and push them -- but AFAIK the APIs to do that don't y
125.
▲
by
pquerna
11y ago
As someone shipping proprietary applications on Linux, the lack of binary compat is still not fun at all. In a previous gig, we ended up with 20 odd build slaves ({x86, x86_64} * Common RHEL, Ubuntu, Debian), and making binaries for each, r
126.
▲
by
pquerna
11y ago
Another interesting implementation that is written by an apache http server, APR, and subversion developer is pocore: https://github.com/gstein/pocore/blob/master/src/memory.c https://git
127.
▲
by
pquerna
11y ago
Inter-process IPC is going to block the event loop for longer than a inline RSA operation.
128.
▲
by
pquerna
11y ago
The point is that it requires TLS handshakes to be done in a multi-threaded system for a server handling high concurrency. Many servers are multi-threaded, but many are not. Using the proposed technique in a Node.js process, or nginx, is g
129.
▲
by
pquerna
11y ago
(disclaimer, i'm the co-founder of ScaleFT, a startup building products in this space: https://www.scaleft.com ) I believe that "ephemeral" or "dynamic" credentials is a concept that is just starting to
130.
▲
by
pquerna
11y ago
Instruments: https://developer.apple.com/library/mac/documentation/Develo... Which for some features it just a fancy UI on top of dtrace, but still a good way to get started with these kinds of things.
131.
▲
by
pquerna
11y ago
Nacy Pelosi isn't attending 400 fundraisers for herself -- she is doing it for the Democratic party and other candidates. Holding a single 'safe' seat in the House is not that important, but electing a few dozen more party m
132.
▲
by
pquerna
11y ago
> Works for Neo4j, MongoDB, ownCloud and some others. None of these are abandonware. All three are VC-backed companies. An AGPLv3 license is extremely restrictive for what amounts to a code dump.
133.
▲
by
pquerna
11y ago
Yeah, in the FAQ of the article it becomes pretty clear how dead this code is: ------------ Do I have to sign a contributor agreement to modify the code? No. This is no longer an active project, we are providing the code for public t
134.
▲
by
pquerna
11y ago
Yes. Basically. I've seen similar attacks before, granted for lower amounts, but in many companies, finance departments sending out wires for many hundreds of thousands of dollars is a common operation -- suppliers, contracts signed,
135.
▲
by
pquerna
11y ago
https://www.atlassian.com/licensing/purchase-licensing Atlassian probably fits the bill more and has proven revenue on it, while Slack is more... "SaaS" in my mind, and really hasn't proven long term rev
136.
▲
by
pquerna
11y ago
Something I've been thinking about: > A perception of winner-take-all markets > Enterprise-oriented companies raise much less private capital; > The average enterprise-oriented company (where the primary customer is a business
137.
▲
by
pquerna
11y ago
While $40 per node might sound high, I think it is reasonable. I've worked on several products that are priced per node/server. Per-node a difficult proposition -- the price of "per server" of something varies wildly, f
138.
▲
by
pquerna
11y ago
https://github.com/awslabs/s2n/blob/master/docs/USAGE-GUIDE.... Looks like currently you must set a file descriptor (though the docs mention the possibility of using a pipe). Once an FD is set, you
139.
▲
by
pquerna
11y ago
"We", the royal hacker we, non-Oracle companies, tried, it failed: http://en.wikipedia.org/wiki/Apache_Harmony
140.
▲
by
pquerna
11y ago
Java was not free'ed by the GPL. Its a mirage. You've been deceived. The specific implementation of the OpenJDK is available under the GPL, but the TCK, which is basically all of the test cases, is essentially proprietary. Can y
141.
▲
by
pquerna
11y ago
I've been using https://groups.io/ for a few small things, feels much better than Google Groups.
142.
▲
by
pquerna
11y ago
Its not cost effective to use non E5-class Xeons, or go above 32GB DIMMs right now.... So you want a Dual-Processor setup, 16 DIMM slots, so 16x 32GB = 512GB w/ Dual Proc -- which you can do for about $10,000.
143.
▲
by
pquerna
11y ago
rackspace, onmetal-memory[1]: 512 GB, $1650/mo (3.22 $/gb/mo) softlayer, dual Xeon 2000 Series: 512GB, $1,823.00/mo (3.56 $/gb/mo) these are on-demand prices. pre-pay, or use a term discount, and its cheaper.
144.
▲
by
pquerna
11y ago
It seems this is pretty clear case of attributable theft -- it's good that it is being prosecuted. The challenges are with attribution though, in many electronic-only attacks, it "could be" anyone. Companies like CrowdStrike
145.
▲
by
pquerna
11y ago
Hi Jordan, We are essentially acting as an easy-to-use, "client focused", Certificate Authority for SSH and X.509. So, in the simplest threat model, yes, if our hosted SaaS version is compromised, your infrastructure is threatened
146.
▲
by
pquerna
11y ago
We are just announcing today[1], and I'm one of the co-founders, and happy to answer anyone's questions about ScaleFT [1] - http://venturebeat.com/2015/05/11/scaleft-launches-with-800k...
147.
▲
by
pquerna
11y ago
tarsnap is not open source: "While the Tarsnap code itself has not been released under an open source license, some of the "reusable components" have been published separately under a BSD license" http://www.t
148.
▲
by
pquerna
11y ago
One way to think about your fear is, shouldn't that just be a tarsnap feature? Add some metadata for a machine that tarsnap should expect a once a day/week/month backup from this machine, and if it doesn't get one, to s
149.
▲
by
pquerna
12y ago
Title is a little generous about "hidden", the exploit revolves around API & Framework used to power the parts of the control panel, and its authorization scheme being broken. I do think its too bad that setuid binaries don&#x
150.
▲
by
pquerna
12y ago
True; I think it is reasonable project to take on if you are willing to staff developers... if you are trying to build a "bare metal" public cloud, having developers on staff is going to be a prerequisite for quite some time goin
More ›