Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rmdoss
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
91.
▲
by
rmdoss
10y ago
We know we are doomed when someone needs to follow such a long document just to secure a server. I mean, that's a very long document with a lot of steps. No wonder people don't do it.
92.
▲
by
rmdoss
10y ago
Really cool tool. If he added a few more servers and set a max ping rt it would become a lot more accurate. And it doesn't really replace geoip, but implemented correctly can be used very affectively for latency based routing (similar
93.
▲
by
rmdoss
10y ago
The real competitors that offer similar features at reasonable prices are: Incapsula & Sucuri All others are old school services, highly expensive and more focused at Infrastructure DDoS protection, not website DDoS protection.
94.
▲
by
rmdoss
10y ago
They don't really say it has been hacked, just that being a target of an advanced password attack. It might mean attackers are using password lists from previous leaks (linkedin), so they decided to force a pass reset to everyone. Or m
95.
▲
by
rmdoss
10y ago
What the hate against CloudFlare? Most of these providers you listed have many issues, more expensive and do a terrible job protecting web sites. For websites, like the Internet Archive, you do not need a layer 3/4 mitigation only prov
96.
▲
by
rmdoss
10y ago
I see a lot of reasons not to use these providers, but privacy and integrity is not one (and I find it a bad argument against them). Every traffic passes through so many hops, routers and networks that adding a secure, well tested and priva
97.
▲
by
rmdoss
10y ago
True, good point. In their case, Sucuri actually offered to help for free via twitter, which is nice. CloudFlare has project Galileo, which they could apply for and get free DDoS help. The importance of the Internet Archive is such that we
98.
▲
by
rmdoss
10y ago
Surprised they are not using a DDoS mitigation provider yet. With companies like Sucuri and CloudFlare providing it at $20 per month, seems a non-brainer.
99.
▲
by
rmdoss
10y ago
Yes, AWS EC2 (Sydney) is completely offline from what we see. We have almost 10 servers there unaccessible for over an hour.
100.
▲
by
rmdoss
10y ago
Too complex for most large networks with many peers and client BGP announcements.
101.
▲
by
rmdoss
10y ago
Details here: http://www.openwall.com/lists/oss-security/2016/05/03/18
102.
▲
by
rmdoss
10y ago
Hard problem now: Find all places where ImageMagick is being used and no one knows about.
103.
▲
by
rmdoss
10y ago
It is a business decision for them. If they kick the booters off, they will DDoS each other to death and no one will be able to use the booters anymore. You may not agree, but financially makes sense for them. They need the booters to be al
104.
▲
by
rmdoss
10y ago
I remember years ago when every new PHP application would have "PHP" before its name. PHPNuke, PHPMyadmin, etc, etc. Seeing the same trend with Go now. Why add the language name to the software name? Real question...
105.
▲
by
rmdoss
10y ago
Would love to see CloudFlare added to the mix. In fact, I would love to see Incapsula, Sucuri and KeyCDN compared as well, to get all top players compared. I guess I might be asking too much :)
106.
▲
by
rmdoss
10y ago
I was going to say that :) When you are starting and have very few users, you should be fast. It is very hard to keep it very fast when you have millions of free users, like CloudFlare does. That is impressive.
107.
▲
by
rmdoss
11y ago
That's only speculation. All Wordfence found is that their site had a vulnerable plugin and they are magically linking that to the compromise. No real forensics there.
108.
▲
Beware of Unverified TLS Certificates in PHP and Python
(blog.sucuri.net)
2 points
by
rmdoss
11y ago
|
0 comments
109.
▲
by
rmdoss
11y ago
It is fine for a 1-man server, but if you have multiple users and you have to be on top of things, then you need a bit more than that. Specially to look at successful logins and audit where they come from. This is a good blog post on the su
110.
▲
by
rmdoss
11y ago
That's a common mistake of people that do not understand how AV's work and how virustotal work. From their own FAQ: At VirusTotal we are tired of repeating that the service was not designed as a tool to perform antivirus comparati
111.
▲
by
rmdoss
11y ago
Better yet, deploy OSSEC there. I would recommend it with the latest patches from here: https://dcid.me/ossec/
112.
▲
Darwinian company growth doesn’t always select the best companies
(blog.asmartbear.com)
3 points
by
rmdoss
11y ago
|
0 comments
113.
▲
Investigating a Compromised Server with Rootcheck
(blog.sucuri.net)
2 points
by
rmdoss
11y ago
|
0 comments
114.
▲
by
rmdoss
11y ago
SSL doesn't have much to do with securing your website. If you are worrying about security, I would recommend to try to find solutions to solve the: -integrity -availability and -confidentiality Of your server and app. For integrity, l
115.
▲
by
rmdoss
11y ago
Thanks! So it works on the post-cached content? If I choose the minification or CSS unification.. Or is that on the fly? Anyone familiar with that?
116.
▲
by
rmdoss
11y ago
Does anyone know if that works with sites behind a nginx proxy? I have Apache and Nginx and if that works for proxied content.
117.
▲
Linode is having a major outage in Atlanta
(status.linode.com)
3 points
by
rmdoss
11y ago
|
1 comments
118.
▲
by
rmdoss
11y ago
They don't use Linode for their DDoS service. I think only some of their blog is in there.
119.
▲
by
rmdoss
11y ago
Kinda... I used OVH in the past and they rely on TCP resets/disconnects for large syn floods, making your servers pretty much unusable while being attacked. I found it better to hide the server behind Sucuri or Incapsula if you are wor
120.
▲
by
rmdoss
11y ago
Take a look at Incapsula or Sucuri: https://incapsula.com https://sucuri.net/website-firewall/ Both a lot cheaper and do a great job protecting against ddos.
More ›