Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sehrope
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
18 ms
·
121.
▲
by
sehrope
13y ago
This isn't new at all. For as far back as I can remember you could dial 555-1212 from any area code and get directory assistance for that area code. There's even a toll free 800 number (1-800-555-1212) which prompts you for the ci
122.
▲
by
sehrope
13y ago
We use CloudFront (without SSL) for our public site (static on S3) and this definitely looks cool. Our app itself has SSL (via an ELB) but not our static WWW site. The only thing we have on there I'd consider sensitive is our PGP key f
123.
▲
by
sehrope
13y ago
> Self-signed certificates don't work at all on the public Internet, but they're just fine for internal resources, as long as you can somehow pin them. Yes self-signed certificates don't work for web servers/browsers
124.
▲
by
sehrope
13y ago
If it were seized by the Feds it'll be interesting to see where it goes. You'd think the first action would be to transfer all of it to new address controlled by the Fed. Otherwise nothing stops a "man on the outside" fr
125.
▲
by
sehrope
13y ago
> "New" here refers to "past-2008" – the salt was changed from using user ID then ( https://mediawiki.org/wiki/Special:Code/MediaWiki/35923 ). > > Accoding to https://www
126.
▲
by
sehrope
13y ago
Not really familiar with the code base but I took a peek at the git repo for MediaWiki[1] (the code for Wikipedia itself). It looks like it's uses a salted md5[2]. Reading through the code a bit, apparently this is the "new"
127.
▲
by
sehrope
13y ago
To clarify, our free cloud version is a complete product. The only difference between it and the paid plans is the number of simultaneous connections and the organization, team, and audit management features.
128.
▲
by
sehrope
13y ago
We have a similar Html5/AJAX powered offering[1] as well though in addition to Postgres we also support a number of other database types (MySQL, Oracle, MS SQL Server). Looking forward to trying this out to see how it compares. [1]: h
129.
▲
by
sehrope
13y ago
> What we see is that somebody, some other VM(s) sharing the same underlying host, is stealing about 30% of the CPU that really belongs to us. That's not how it works. CPU steal time is when the hypervisor stalls your CPU because yo
130.
▲
by
sehrope
13y ago
My front door does not have a picture of my key on it. My phone has tons of fingerprints though. It's a touch screen phone. One of those words is "touch" which clearly implies your finger coming in contact with it. Even if
131.
▲
by
sehrope
13y ago
Considering that people generally don't wear gloves when they use their phones this is like having a picture of your key on your door. Combine that with what we know you can do with pictures of keys[1] and yes it's obviously not a
132.
▲
by
sehrope
13y ago
A lot of folks don't realize this but it's not just web browsers that you need to worry about. When your app connects over SSL to any service that it's consuming you need to be properly authenticating the remote server. For e
133.
▲
by
sehrope
13y ago
> A person with insider knowledge stole data including names, addresses, birth dates, and bank account information, the world’s second-biggest mobile-phone carrier said in a statement today. Am I correct in understanding that the data st
134.
▲
PostgreSQL Execution Plans In JackDB
(blog.jackdb.com)
1 points
by
sehrope
13y ago
|
0 comments
135.
▲
by
sehrope
13y ago
Yes even over SSL connections. You don't know if the other person's computer itself is compromised (e.g. key logger). Rather then instruct a not-so-tech-savvy person to make the decision of whether computer X is trustworthy the de
136.
▲
by
sehrope
13y ago
Passwords are not dead. Simple single factor authentication using short passwords is dead. That's not a new thing either and they're not going away either. Biometric implants are cool but it's a long ways away ( and I'm
137.
▲
by
sehrope
13y ago
AWS supports VPC (virtual private network). It lets you setup sub groups of VMs that are only network accessible to each other with explicit endpoints open (ex: just HTTP open to an ELB). It's recommended for all new deployments. We us
138.
▲
by
sehrope
13y ago
Mongo - Sure. I'm hardpressed to find genuine reasons to use MongoDB these days. Postgres provides everything I need in a persistent data store and has a ton of other stuff I didn't know I'd need (till you do!). Mongo was gre
139.
▲
by
sehrope
13y ago
Yeah I think we all do. In fact not too long after posting a link to our app in this thread I got another one: Sep 9 12:58:29 [41.66.xxx.xxx] GET /phpMyAdmin/translators.html [1 ms]
140.
▲
by
sehrope
13y ago
Well I'm biased since it's our product but I think JackDB[1] is both nice and efficient. It runs entirely in your browser so it's naturally cross platform. [1]: http://www.jackdb.com/
141.
▲
by
sehrope
13y ago
This is one of the (many) apps we looked at when we started working on JackDB[1]. It's a database client in your browser. Rather than just a table interface though, JackDB is a full featured query editor and even includes scrolling res
142.
▲
by
sehrope
13y ago
> So when the time comes to change the business logic you have stored in the database, do you have to ensure that every possible client that may use that business logic is updated at the same time? You could version your business logic i
143.
▲
by
sehrope
13y ago
Sometimes it makes sense to make a common library shared between apps that interacts with your database and sometimes it makes sense to put that code itself in the database (as a view or stored proc). The latter has the advantage of working
144.
▲
by
sehrope
13y ago
The big advantages for doing things "on the DB" are centralizing business logic and eliminating serialization/transport/deserialization. Having a view or stored proc with business logic lets it be shared across different
145.
▲
by
sehrope
13y ago
There's a specific type of a patent for that too[1]. Unfortunately unless your hypothetical saviour company filed it quite a while back I'm pretty sure there's too much "prior art" for this idea to work. [1]: http:
146.
▲
by
sehrope
13y ago
Yeah I'm not sure either about the down vote. By not storing passwords I meant delegating to an external authority for authentication services. Whether that's OpenID, Persona, Facebook login, direct OAuth integration with a limite
147.
▲
by
sehrope
13y ago
If you've ever been in a position to hire/fire employees and deal with managing a non trivial number of people then you'll appreciate taking the time to vet them (as best you can) before you hire them. Five hours interviewing
148.
▲
by
sehrope
13y ago
Or even better dont't even store them at all. If its an internal app use LDAP, Active Directory, or whatever other centralized ID system your company has. If it's a public app then consider using a federated approach like OpenID.
149.
▲
by
sehrope
13y ago
> None of them made the switch back to C++ and their "prototypes" became finished products. This is because the vast majority of the time people's claims of performance requirements are complete BS. If you're writin
150.
▲
by
sehrope
13y ago
Are the prekeys generated/saved per potential contact ( signed/encrypted with the contact's public key of course! ) or is it a general pool for everybody? If it's the latter than couldn't a malicious user flood you
More ›