Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
russjones
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
russjones
1y ago
Teleport (YC S15) | Backend and Fullstack Engineers | US, Toronto, London, Remote OK | https://goteleport.com Do you enjoy building security and deployment tools for other engineers? Join us to hack on https://github.
2.
▲
by
russjones
1y ago
Teleport (YC S15) | Backend and Fullstack Engineers | US, Toronto, London, Remote OK | https://goteleport.com Do you enjoy building security and deployment tools for other engineers? Join us to hack on https://github.
3.
▲
by
russjones
6y ago
You only need a browser if you are using SSO. If you are using local accounts it's all done in the CLI.
4.
▲
by
russjones
6y ago
Hi scarygliders, That's a good question and valid skepticism. The UI serves two purposes. The first is to manage your cluster. For example, you may want to change a users role (to change what servers they can access) or play back a ses
5.
▲
by
russjones
7y ago
We're trying to raise structured behavioral information about what is happening in a session to the cluster administrator. That means we don't just provide information about what's executing, but also what files are being ope
6.
▲
by
russjones
7y ago
Thank you Abe! The kind comments are appreciated! So far we have gotten positive feedback. While this feature does not protect against root doing something malicious, it does allow admins to capture what root was doing up until they did som
7.
▲
by
russjones
7y ago
Understandable confusion, I've seen it referred to both ways. We decided to go with BPF for this blog post since that appears to be the official abbreviation. From "BPF Performance Tools" by Brendan Gregg: "Extended BPF
8.
▲
by
russjones
7y ago
Author of the post here, happy to answer any questions.
9.
▲
by
russjones
7y ago
Noted.
10.
▲
by
russjones
7y ago
I ran an eBPF program called opensnoop [1] to capture what files were opened during login to a system and then re-launching bash. Looks like both are read during initial login but only .bashrc for non-login shells. Output is below. 2443
11.
▲
SSH Handshake Explained
(gravitational.com)
3 points
by
russjones
7y ago
|
0 comments
12.
▲
by
russjones
8y ago
Maybe I did not provide the best example, but the point I was driving at is that the restrictions here are at the application level and not at the system level. If you take the approach you are taking, similar to ForceCommand, you have to m
13.
▲
A Child’s Garden of Inter-Service Authentication Schemes
(latacora.singles)
92 points
by
russjones
8y ago
|
52 comments
14.
▲
Add hash verification to “curl | sh”
(git.zx2c4.com)
2 points
by
russjones
8y ago
|
1 comments
15.
▲
by
russjones
8y ago
Ha, nope, didn't realize this until everyone started mentioning it in the comments.
16.
▲
by
russjones
8y ago
Author here, happy to answer any questions about the post.
17.
▲
by
russjones
9y ago
We had a security audit of Teleport performed by Cure53 with the release of Teleport 2.2 which we released publicly. You can view the report here: https://cure53.de/pentest-report_teleport.pdf
18.
▲
by
russjones
9y ago
Hi walrus01, If exposing Teleport (or OpenSSH or any piece of software to be honest) to the internet is a significant concern, the solution I recommend is to put it behind spiped. Spiped has a very small and well written code base and well
19.
▲
by
russjones
9y ago
Hi Operyl, Russell from Gravitational here. We've made improvements in resource utilization for Teleport 2.0 and hunting down any further resource utilization issues is definitely one of my focus areas for Teleport 2.x. If you run into
20.
▲
by
russjones
9y ago
Hi nikolay, we don't have a CloudFormation template, but we do have a containerized version of Teleport that is fully configured with multiple clusters that you can use to test with. https://github.com/gravitational
21.
▲
by
russjones
9y ago
Hi atonse, Russell from Gravitational here. As far as configuring your VPC having the bastion (Proxy) as the only server with a public address is reasonable. One of the nice things about Teleport is that the Teleport Proxy itself doesn'
22.
▲
by
russjones
11y ago
Thanks, the DO's and DON'TS were heavily inspired by a talk given by Colin Percival called "Everything you need to know about cryptography in 1 hour". You can check it out here: https://www.bsdcan.org/201
23.
▲
by
russjones
11y ago
I don't mind the criticism constructive or otherwise. I have already sketched out where to take part 2 and filled in some of the sections. That being said the 80/20 rule applies here like everywhere else. That being said, if anyon
24.
▲
by
russjones
11y ago
Fixed that, thanks for pointing it out.
25.
▲
by
russjones
11y ago
Author of the guide here, don't worry, we will!
26.
▲
by
russjones
11y ago
Author of the post here, happy to answer any questions or provide more details about our recommendations.
27.
▲
by
russjones
11y ago
This is a good point. That's why we recommend either a robust CI/CD system (with good test coverage) or manually applying updates to a staging environment where you can test if the updates broke anything end-to-end before you roll
28.
▲
by
russjones
11y ago
Author here, happy to answer any questions/discuss the recommendations we provided.
29.
▲
by
russjones
12y ago
Russell from Mailgun here. From our perspective, most people start (or at least should start) with the premise that email is not secure. There are things that we can do to make email more secure, but as an email service provider, we have to
30.
▲
by
russjones
12y ago
Hi 0x0, Russell from Mailgun here. Do you have a self signed certificate by any chance? We typically downgrade a connection if we are presented with a self signed certificate. That might be what you are seeing. If you drop us an email at su
More ›