Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rhuber
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
Ask HN: AI models are built on all of us, should their weights act like patents?
7 points
by
rhuber
4mo ago
|
2 comments
2.
▲
by
rhuber
3y ago
That's totally reasonable, and I agree that using something hosted entirely by a 3rd party makes sense for some use cases. Our reason goes a bit beyond security concerns, in this case. We built Nebula for large scale deployments, and b
3.
▲
by
rhuber
3y ago
Thanks Harrison, hope you're well!
4.
▲
by
rhuber
3y ago
That's a great question! One of the things I enjoyed during my time at Slack was their willingness to contribute to open source projects. We had similar IP clauses, but asking permission to open source things was straightforward. The m
5.
▲
by
rhuber
3y ago
(*blog post author here) Thanks for sharing this on HN! I'll keep an eye on the comments and try to answer questions that come up.
6.
▲
by
rhuber
4y ago
We need to do a better job of this and I'm really sorry you had a not-great experience with expiration. Totally agree with your take.
7.
▲
by
rhuber
4y ago
We have an automated set of ansible scripts that spin up large groups of hosts for Nebula performance regression testing, and a while back I added zerotier, tailscale, wireguard-userspace, wireguard, tinc, ipsec, and openvpn to that automat
8.
▲
by
rhuber
4y ago
I mean... the title of the Tailscale blog post is "Tailscale raises $100M… to fix the Internet", and that's pretty massive scale. /s I don't have 100k hosts on a large network to test deploying Tailscale, but if I d
9.
▲
by
rhuber
4y ago
The Nebula CA we built at Slack was very specific to Slack's internal devops, and just wasn't generalizable. It is highly automated there, and is custom tooling, just as you describe. The open source version is somewhat bare bones
10.
▲
by
rhuber
4y ago
Another fair criticism. We will publish the benchmarks and make them repeatable (which most existing ones I've found don't bother to do). We hadn't done so because Tailscale isn't really seen as a direct competitor to wh
11.
▲
by
rhuber
4y ago
Fair enough. I am sure the key distribution is fast and all that, but not needing peer key distribution at all was a goal and the overhead associated is less scalable than just not doing it at all. Regardless, very cool that you can handle
12.
▲
by
rhuber
4y ago
It does! In fact replacing AWS security groups and making them cross region and cross platform was probably the first goal of the project. My coauthor, Nate, wrote Nebula's internal firewall code before we wrote a single line of the ac
13.
▲
by
rhuber
4y ago
(Nebula coauthor here) People sometimes ask me to describe the differences between Nebula and Tailscale. One of the most important relates to performance and scale. Nebula can handle the amount of internal network traffic and scalability of
14.
▲
by
rhuber
5y ago
(coauthor of Nebula) We briefly considered building something atop Wireguard in the early days of Nebula, but decided not to do so because of scaling. Wireguard's protocol necessitates that all nodes have existing keypairs for each oth
15.
▲
by
rhuber
5y ago
Actually it does do that, you can trust multiple CAs in a single instance and even write firewalls scoped to CAs.
16.
▲
by
rhuber
5y ago
"Hey guys, remember when freenode was taken over by one guy?" (It was, like, yesterday.) It's hard to overstate the dangers of over-centralisation like this, and I say it as a person who used freenode professionally. https:&
17.
▲
by
rhuber
6y ago
I wasn't commenting on the strength of RSA-1024, per se, but on the assumed age of that key. OpenSSH's ssh-keygen hasn't defaulted to 1024 bit RSA keys since before version 4.2, in 2005. (I had to look it up: https:/&#x
18.
▲
by
rhuber
6y ago
The author of this article should consider following their own advice, since they have a woefully outdated RSA-1024 ssh key securing their GitHub account. $ curl -s https://github.com/apenwarr.keys > blah $ ssh-keygen -l
19.
▲
by
rhuber
7y ago
It is, admittedly, impossible for me to be unbiased in this discussion (coauthor of Nebula, hi), but I strongly disagree that your client code is your most important component, from a trust perspective. Your coordination server tells every
20.
▲
by
rhuber
9y ago
Every aspiring programmer should learn C. They should also learn multiple dialects of ASM. Learning these things helps you better understand how computers fundamentally work, and knowing how computers work pushes you to write better code in
21.
▲
by
rhuber
10y ago
Hi - Ryan from the blog post here. eBPF is great, and we plan to support it as our collection mechanism, but not today and maybe not soon. When we wrote go-audit, there were few, (if any?), distros that had eBPF kernel support. Now Ubuntu 1
22.
▲
by
rhuber
12y ago
There are a few reasons for my comment about going against the spirit: 1) https://hackerone.com/disclosure-guidelines states: "If 180 days have elapsed with the Response Team being unable or unwilling to provide a disc
23.
▲
by
rhuber
12y ago
Notes on “a little note”. Hi, this is Ryan. I work at Slack. Bug bounties are great, but managing them can be a challenge. Like many companies that run a popular bounty program, we receive quite a few vague reports, invalid reports, and rep