Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ptoomey3
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
ptoomey3
3y ago
https://tenderlovemaking.com/2016/02/05/i-am-a-puts-debugger... is ruby gold for this kind of stuff. As a Ruby developer, probably one of the most impactful "quick tips" I've ever picked up is
2.
▲
by
ptoomey3
5y ago
I think the zero-knowledge proof bit is how some password managers authenticate the users to their system. 1Password for example, uses the secure remote password protocol: https://en.wikipedia.org/wiki/Secure_Remote_Pas
3.
▲
by
ptoomey3
6y ago
Yeah, to match the dot pitch apple is designing for, the 4K monitor would have to be more like 22 inches instead of 27. We know this since the 4K iMac is a 21.5 inch screen.
4.
▲
by
ptoomey3
6y ago
For me the option key was always the one that threw everything else off..since failure to recognize it made me doubt all the others :-). One "pneumonic" that helps for the option key is that it looks a bit like a "fork in the
5.
▲
by
ptoomey3
6y ago
The verified device flow isn’t meant to be as strong as 2FA, but is a very strong mitigation against mass credential stuffing attacks for all users. In terms of client certs, see my response in https://news.ycombinator.com/i
6.
▲
by
ptoomey3
6y ago
One issue with HTTPS client cert auth is that it can be non-trivial to support at the application level when you have a multi-tier architecture where TLS termination happens at the edge of your infrastructure.
7.
▲
by
ptoomey3
6y ago
What isn’t stated in that post is that we are sending monthly email notifications to any user found using password authentication during the deprecation. As a result, we expect the vast majority of users will have been notified several time
8.
▲
by
ptoomey3
6y ago
GitHub Actions tokens are actually based off our newer “GitHub apps” system and not “OAuth apps”. GitHub app tokens support much more granular controls (both in terms of abilities and resources). OAuth doesn’t lend itself to super granular
9.
▲
by
ptoomey3
6y ago
Think of this deprecation as step one of a multi-step plan/roadmap .
10.
▲
by
ptoomey3
6y ago
It’s not at all about the security of delivering credentials over https, but more about the the complexity of trying to defend against weak passwords/credential stuffing with an api. For example, it’s more or less impossible to add a d
11.
▲
by
ptoomey3
7y ago
Rails actually did turn the HEAD into a GET back when this code was written - https://github.com/rails/rails/blob/e17e25cd23e8abd45b170646...
12.
▲
by
ptoomey3
7y ago
My experience with password managers is that they work great for me, because I understand every sharp edge and can work around them. My experience when advising family to use them is that they invariably fail them and they get frustrated. P
13.
▲
by
ptoomey3
7y ago
100% true. I personally wish the hardware-focused U2F bit didn't predate the WebAuthn spec. I feel, because of that, way too much focus is placed on the "hardware security" bit. I view the main benefit as replacing user selec
14.
▲
by
ptoomey3
7y ago
Yet another batteries included downside...a blackbox http implementation that is hard to debug.
15.
▲
by
ptoomey3
7y ago
This isn’t to say it happened on every response..it was a relatively small fraction. But, it was enough to tell _something_ was going on. Who knows, it could be something quirky on the network and not even a gRPC issue. But, because the run
16.
▲
by
ptoomey3
7y ago
One that we encountered in several services were gRPC ruby clients that semi-regularly blocked on responses for an indeterminate amount of time. We added lots of tracing data on the client and server to instrument where “slowness” was occu
17.
▲
by
ptoomey3
7y ago
Need or not need...a bigger issue is simply the technical reality of what you have now. If your non-trivial infrastructure doesn’t have great http2 support, it might be a pretty big lift to make that change first.
18.
▲
by
ptoomey3
7y ago
We were mostly using ruby (which uses their C bindings) and golang (which are native to golang).
19.
▲
by
ptoomey3
7y ago
Our main hinderance with gRPC was that several disparate teams had strange issues with the fairly opaque runtime. The “batteries included” approach made attempts to debug the root causes quite difficult. As a result of the above, we have be
20.
▲
by
ptoomey3
7y ago
While the tools themselves might not use the same key for both operations, I think the question was asking about whether it is problematic that a user’s SSH keys, used in SSH for signing, are also used by these tools for encrypting. In othe
21.
▲
by
ptoomey3
7y ago
The bit being referred to is how signing and encryption can be inverse operations of each other in some schemes. The canonical example is textbook RSA. Signing is the same operation/math as decryption. Likewise, verifying signatures an
22.
▲
by
ptoomey3
8y ago
I mostly agree, though I still think adding 2fa to whatever password manager you do use is vaguely worthwhile. Long term creds can get checked into repos, accidentally pasted somewhere, etc. May as well have 2fa to mitigate this edge case
23.
▲
by
ptoomey3
8y ago
SMS does still help to mitigate a common attack...folks trying out password dumps on other sites. But, I don’t disagree we need to move on when we have more options to choose from. Right now the best looking option is webauthn with platform
24.
▲
by
ptoomey3
8y ago
I think the trick is to push the trust up a level to the platform owner (you have to trust someone at some point) via webauthn or something. If you do that, then the browser itself can be the one the be trusted to show the actual public key
25.
▲
by
ptoomey3
8y ago
As noted elsewhere in this thread, I’m not advocating this homegrown solution. But, I will play devil’s advocate a bit. Yeah, sure, a Secure Enclave key per device is more secure than not. But, what is your threat model where this is the pr
26.
▲
by
ptoomey3
8y ago
I’m not advocating for this homegrown solution, but moving private keys around isn’t necessarily the worst idea ever. A unique key per device requires explicit registration on each device. That is “better security”, but also potentially far
27.
▲
by
ptoomey3
8y ago
This feels vaguely like a homegrown version of webauthn, but without any of the niceties of having the browser enforcing origin protections and ensuring the credential isn’t lost if cookies/local storage are cleared.
28.
▲
by
ptoomey3
8y ago
I’m not even convinced “don’t click links” is the best guidance. That message has been pushed so hard that people immediately think their machine has been compromised once they have clicked a shady link. That is nearly never the case. Click
29.
▲
by
ptoomey3
8y ago
Totally to each their own...there is no perfect solution for this. I do understand the the apprehension with google shutting down services, though google photos is so wildly popular it would almost be analogous to them shutting down gmail a
30.
▲
by
ptoomey3
8y ago
Here is a quick repo that has all the directions and hazel rules. I only spent all of 5 minutes pulling it together, so feel free to open an issue if you run into any problems. https://github.com/ptoomey3/family-photo-l
More ›