Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
remosi
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
remosi
10y ago
(I'm a Google SRE, I'm on the team that dealt with this outage) This did impact common infrastructure. Some (non-cloud) Google services were impacted. We've spent years working on making sure gigantic outages are not extern
2.
▲
by
remosi
12y ago
Nine days ago the data protection authority (DPA) in Hamburg, Germany asked to audit the WiFi data that our Street View cars collect for use in location-based products like Google Maps for mobile, which enables people to find local restaura
3.
▲
by
remosi
12y ago
> We don't correlate or combine information from our temporary or permanent logs with any personal information that you have provided Google for other services. -- https://developers.google.com/speed/public-dns&
4.
▲
by
remosi
12y ago
https://www.lorier.net/docs/tpm are my notes with experimenting with the TPM in my T530. The trick is that the TPM will protect itself fairly aggressively, so before you start turn off the laptop, unplug the power an
5.
▲
by
remosi
12y ago
Your content is often not in the webservers user, it's often stored in a SQL or NoSQL database somewhere. Various access controls can be applied there. But your right, unfortunately this isn't a 100% magic pixie dust solution to
6.
▲
by
remosi
12y ago
This would be ideal. One of the problems with heartbleed has been that while you can revoke your cert and mint a new one, browsers don't check CRLs so they'll continue to trust the old compromised cert. However, I don't thin
7.
▲
by
remosi
12y ago
But not out of user. If I can run code as your user, I can attempt to retrieve those keys, although I assume MacOS prevents you from attaching a debugger to the keychain. Linux has Gnome-keyring, which, amongst other interfaces, operates a
8.
▲
by
remosi
12y ago
Having looked at PKCS#11, I'm not sure what bits you could get away with not implementing. It does have functions for things like "get random bytes", which I guess you might not want, but that's just barely any code: (i
9.
▲
by
remosi
12y ago
Yup, that pretty much sums it up. I'm currently trying to figure out if dbus could be that serialisation since it takes care of a reasonable amount of the hard work for you. But I'm no expert on GObject, so slow going. (Also, I&
10.
▲
by
remosi
12y ago
Yup. But when you have a successful attack you should consider what alternatives you have to make sure that never happens again. You might dismiss them since their cost:benefit might not be favourable. If this works, I doubt many people
11.
▲
by
remosi
12y ago
The technique of not having the keys available to the process that's dealing in external bits works really well for DNSSEC. There's a program called opendnssec which takes care of keys, rotating them, and .... accesses them via P
12.
▲
by
remosi
12y ago
If I was running a bank, I'd hopefully use a proper HSM. You ask it to generate a private key, you then ask it for the public key, get it signed into a cert, and use that. The HSM promises to never give out the private key to anyone
13.
▲
by
remosi
12y ago
The major reason is that when your website becomes popular, and becomes more of a target, you can swap out the software hsm daemon with a more sophisticated hardware solution, if implemented properly, by just changing a pkcs11: url[1] to po
14.
▲
by
remosi
12y ago
It runs in process tho, so it would have had the exact same result with heartbleed. Its keys need to be readable to that user, so exploits like http://blog.detectify.com/post/82370846588/how-we-got-read-a... woul
15.
▲
by
remosi
12y ago
Yeah, I was aware of factotum when I wrote this post. GNOME uses p11-kit (which is a wrapper around PKCS#11) and gnome-keyring to kinda provide similar functionality.
16.
▲
by
remosi
12y ago
You're right, this doesn't solve 100% of the problem. If I could solve 100% I'd be creating a startup... Cookies are remarkably sensitive, but they can be far more easily rotated. I can make sure that every cookie is rotate
17.
▲
by
remosi
12y ago
There are several softhsm's, they just share the address space with your frontline daemon which (IMHO) defeats the purpose. While webserver's support for PKCS#11 is annoying, it's well supported by lots and lots of other stuf
18.
▲
Webservers shouldn't have direct access to keys
(plus.google.com)
86 points
by
remosi
12y ago
|
76 comments
19.
▲
by
remosi
13y ago
DNS can give you IPs for things close by, or far away. 8.8.8.8 uses EDNS0 Client Subnet to try and improve which IP address you get served back.
20.
▲
by
remosi
13y ago
Where in the world are you? Do you have a traceroute to 8.8.8.8?
21.
▲
by
remosi
13y ago
</dev/null openssl s_client -showcerts -connect www.google.com:443 Includes in the output: Server public key is 2048 bit ... Protocol : TLSv1.2 Cipher : ECDHE-RSA-AES128-GCM-SHA256 (ie: not RC4, as long as your cli
22.
▲
by
remosi
13y ago
So, reading many of the replies in this thread, they all cover good points, but I have a slightly different point: The current encryption libraries make the "easy" stuff hard. If we assume that all the hard work of actually doing
23.
▲
by
remosi
13y ago
That was why I wrote it yes. I wanted to know how I could ask android phones politely to avoid slamming the bandwidth on an AP that really didn't have the backhaul for everyone's photos and kept these notes in case I needed to do
24.
▲
by
remosi
13y ago
There are complications, some IP's might be free, some might be cheap (caches, local peering), some might be expensive (transit). The price might vary on time of day (a lot of eyeball networks are near idle when everyone's asleep
25.
▲
by
remosi
13y ago
Well, this scheme at least lets you announce "This is an (relatively) expensive connection, please avoid doing things you don't need to.".
26.
▲
by
remosi
13y ago
Having written the document that this links to, my goal of pointing out the surprising behaviour with android not requesting an attribute it cared about was to avoid other people banging their heads against this problem when they tried to i
27.
▲
by
remosi
13y ago
I assume because it's "metered" (ie, billed by byte). The TODO suggests that this should be figured out rather than always enabled. You can go to "Settings > Data usage > ⋮ > Mobile Hotspots" and maybe tha
28.
▲
by
remosi
13y ago
Yeah, it could. It doesn't tho. So you have to remember to force it if you want android to listen to you setting the attribute.
29.
▲
by
remosi
13y ago
Google has a little known service that does DDoS mitigation for you (amongst other things) called PageSpeed service[1], which is (currently) free[2]. They also do various optimisations for your site, and support things like caching, SPDY a
30.
▲
by
remosi
14y ago
homomorphic signatures?
More ›