Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sullivanmatt
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
sullivanmatt
4y ago
Not a complete nothing burger; a lot of people here work for companies that sell to the Feds or host FedRAMP-authorized SaaS solutions. There will definitely be private-sector impact from that risk framework, though I'm not saying that
32.
▲
by
sullivanmatt
4y ago
You have a very neat website ( https://sam.design ). Learned something new today.
33.
▲
(removed)
(mattslifebytes.com)
1 points
by
sullivanmatt
4y ago
|
0 comments
34.
▲
by
sullivanmatt
4y ago
I'm a security professional with a decade and a half of hands-on, real world experience. My most recent position being the product manager for Identity and Access Management for a leading B2B SaaS, dealing with real world attacks from
35.
▲
by
sullivanmatt
4y ago
[removed by author]
36.
▲
by
sullivanmatt
4y ago
A lot of people still have legacy Yubikeys floating around, and these are replayable. What you need now is something like the Google Titan FIDO2 key or one of the Yubikey FIDO2 keys. Transitioning an entire company to these, getting everyon
37.
▲
by
sullivanmatt
4y ago
I think it's worth repeating: at this point, MFA that is not based on Webauthn ( https://webauthn.guide/#about-webauthn ) should be considered dangerously insecure. Uber almost certainly enforces MFA for remote access; I
38.
▲
by
sullivanmatt
4y ago
In this case yes, it sounds like the pessimistic viewpoint may be the right one. However, for a while now HN has been going downhill with armchair analysis that inevitably concludes that any action taken by a business is wrong/harmful&
39.
▲
by
sullivanmatt
4y ago
Thanks Matt, not sure how I missed that. Glad to hear it!
40.
▲
by
sullivanmatt
4y ago
For any of the Cloudflare team that frequents HN, curious if you have an eventual plan to open-source Pingora? I recognize it may stay proprietary if you consider it to be a differentiator and competitive advantage, but this blog post almos
41.
▲
by
sullivanmatt
4y ago
I do wish this wasn't a sponsored ad masquerading as an engineering blog until the last paragraph, but yes, these things are extremely challenging. What people miss is that the big cost isn't building or integrating these things,
42.
▲
Getting your money’s worth: making runtime logging more valuable
(mattslifebytes.com)
3 points
by
sullivanmatt
4y ago
|
0 comments
43.
▲
Actively-exploited, unpatched, remote code execution in Atlassian Confluence
(bugalert.org)
9 points
by
sullivanmatt
4y ago
|
0 comments
44.
▲
by
sullivanmatt
4y ago
I also live in Ames, Iowa, where the author resides. I live less than a mile from the track segment he is talking about, owned and operated by Union Pacific. While I'm pretty skeptical of this author's individual concerns given th
45.
▲
by
sullivanmatt
5y ago
Mirror https://web.archive.org/web/20220223141210/https://mwi.usma....
46.
▲
by
sullivanmatt
5y ago
Personally, I already pay for Google One, run my phone lines on Google Fi, and only use YouTube for an average of 15-20 minutes of content per day. Google Fi aside, surely somebody, somewhere, at Google can just bundle these things up and I
47.
▲
by
sullivanmatt
5y ago
There's an entire market for this (and I own two for this express purpose): https://www.etsy.com/listing/1015753561/the-original-apple-a...
48.
▲
by
sullivanmatt
5y ago
I'm working on getting the documentation written for it, but Atom feeds per category are recently live! https://bugalert.org/feeds/software-frameworks-libraries-and... https://bugalert.org/feeds&#x
49.
▲
We desperately need a way to notify people of high-impact vulns, so I built one
(mattslifebytes.com)
2 points
by
sullivanmatt
5y ago
|
2 comments
50.
▲
(removed)
(mattslifebytes.com)
1 points
by
sullivanmatt
5y ago
|
0 comments
51.
▲
We desperately need a way to notify people of high-impact vulns, so I built one
(mattslifebytes.com)
12 points
by
sullivanmatt
5y ago
|
1 comments
52.
▲
by
sullivanmatt
5y ago
I've coordinated an NCC crypto audit, and I can assure you that is not the case.
53.
▲
Show HN: Tool for debugging client TLS version and cipher support issues
(tls.support)
5 points
by
sullivanmatt
5y ago
|
0 comments
54.
▲
by
sullivanmatt
5y ago
Pinterest voluntarily entered this agreement, which provides better pricing in exchange for committed use - an offer AWS provides to many of its customers. This is a highly sensationalized headline.
55.
▲
by
sullivanmatt
6y ago
Mongo adoption has risen at a rapid rate, and cloud services now make up nearly 40% of their revenue (which, in turn, allows the company to push those $$$ into the core product). Your statement, while a common view on HN, is not correct. Ju
56.
▲
by
sullivanmatt
6y ago
I can't go into details, but let me say that someone who would be in the know at AWS, very much off the record, told us not to use their hosted elastic because of how terrible it is. Some issues: scaling it is manual (a "managed s
57.
▲
by
sullivanmatt
7y ago
No, the IP whitelist is only to allow access to the network entry point. So if you had a VPN, it would open the port to the VPN server. In our case, it opens the port to the cordoned-off SSH-based network entry point. It's not the
58.
▲
by
sullivanmatt
7y ago
Yes, the RDP story is very painful. To the best of my ability, my goal was to make the post more about the network architecture (esp around the concept of SSH bastions) and less about the actual OASA product itself. I think there are a numb
59.
▲
by
sullivanmatt
7y ago
Not to be particularly combative to this top-level comment author, but I did not see a reason to reply because I did not feel they had read the post particularly closely. Obviously defense in depth can go as deep or shallow as you see fit,
60.
▲
by
sullivanmatt
7y ago
Sorry, the tens of millions of IP addresses is referencing the IP space of AWS (one of which these network access points occupies at any given point in time).
More ›