Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sullivanmatt
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
sullivanmatt
7y ago
Basically. Since we are focusing on SSH in this post (and keep in mind that SSH is its own protocol, separate from TLS), it's conceptually the same: client has a certificate and a key, signed by a trusted certificate authority, and the
62.
▲
by
sullivanmatt
7y ago
I have no way to prove to you that I am not some paid shill :) , but I have no relationship with Okta outside of being a customer through my employer, and I was not compensated or gifted anything for the creation of my post. I blog about th
63.
▲
by
sullivanmatt
7y ago
A great point. It does depend on your use case, and your dependence on manual operations. For our organization, almost all database interactions and maintenance are performed in code; if somebody is connecting manually, something pretty bad
64.
▲
by
sullivanmatt
7y ago
I wish you had come into this discussion with constructive criticism, instead of simply swinging a hammer. I, for one, am happy to learn from somebody with a number of years of experience. However showing up on a thread and spewing negativi
65.
▲
by
sullivanmatt
7y ago
> The whole point of a VPN or SSH jumpbox is to airgap critical infrastructure with unknown vulnerabilities behind a hardened point of access Yes, I completely agree. This post is literally an endorsement of that idea, with enterprise po
66.
▲
by
sullivanmatt
7y ago
I want to be clear about the use case that the enterprise port knocking solution is trying to solve: it's an additional control that would not normally even be in place. In most setups, you are exposing some sort of relay to the intern
67.
▲
by
sullivanmatt
7y ago
There is one network entry point per deployment of our app infrastructure (eg. US and EU deploys), so the lambda does go and update both security groups simultaneously to allow the requestor's IP to hit either if they would like. If y
68.
▲
by
sullivanmatt
7y ago
Most people in industry I have talked to just do VPN for all traffic, even though that seems crazy to me to route your Hacker News traffic through your prod servers' networks (gross). Normally a compensating control would be appropria
69.
▲
by
sullivanmatt
7y ago
The control I listed, NIST 800-53 SC-7(7) [which is a part of the FedRAMP Moderate suite of controls], specifically requires you implement a technical control such that your users cannot split tunnel.
70.
▲
by
sullivanmatt
7y ago
As I alluded to in the post, it's a legacy viewpoint. These customers hand you a 300+ security questionnaire that hasn't been updated in 10 years. When you tick the 'VPN' boxes, alarms sound, but they are thinking abou
71.
▲
by
sullivanmatt
7y ago
Thanks all for your feedback. I have removed the images to improve readability, especially for mobile users. The post was originally written for an internal blog where we have a GIF-heavy communication culture, and I probably should have cl
72.
▲
Remote access to production infrastructure (death to the VPN)
(mattslifebytes.com)
236 points
by
sullivanmatt
7y ago
|
117 comments
73.
▲
by
sullivanmatt
7y ago
Here's the scoping doc: https://iowacourts.gov/static/media/cms/Rules_of_Engag_E9D80... Some highlights include authorization to attempt entry by tail gating, lock picking, place devices once access has
74.
▲
by
sullivanmatt
8y ago
Enterprise customers want the ability to pull their keys and walk away from a platform, sometimes with very little notice. A made-up example: assuming Brexit occurs, EU customers of a London-based SaaS chat service may no longer wish to kee
75.
▲
Cattle not pets: infrastructure, containers and security in a cloud native world
(mattslifebytes.com)
3 points
by
sullivanmatt
8y ago
|
0 comments
76.
▲
Protecting internal applications with a SAML-aware reverse-proxy (a tutorial)
(mattslifebytes.com)
1 points
by
sullivanmatt
8y ago
|
0 comments
77.
▲
by
sullivanmatt
8y ago
Yeah, I got the same. Might need to built some sentiment analysis in there too.
78.
▲
by
sullivanmatt
9y ago
I work for one of the companies mentioned, and we don't / did not pay for the name drop. Maybe one of the others did, but we did not.
79.
▲
by
sullivanmatt
9y ago
This is the EDGAR system that was breached: https://www.edgarfiling.sec.gov/Welcome/EDGARLogin.htm Up until two years ago, that page used to recommend a minimum browser of either IE 5 or Netscape Navigator 3. If you lo
80.
▲
by
sullivanmatt
9y ago
You are correct, but if you actually have the source and can compile a binary from that, it is much easier to evade detection. As you might imagine, the gnarly things you have to do to add malware to existing software often trigger detecti
81.
▲
by
sullivanmatt
10y ago
I see 16 bytes of hex after the anchor slug for the encryption feature, e.g. for ' https://nofile.io/f/86JiUNYM6QK#5827800f46cef978' , the key is '5827800f46cef978'. The key is absolutely does not con
82.
▲
by
sullivanmatt
10y ago
Where we could, we certainly tried to avoid it. The bigger problem is just the opportunity cost with regards to resources involved with the transition.
83.
▲
by
sullivanmatt
10y ago
Well, the codebase existed long before HTML5 was supported by pretty much any major browser (remember, HTML5 didn't really stabilize to the point an enterprise could use it until 2012). So you have to continue adding to it while you wa
84.
▲
by
sullivanmatt
10y ago
Yes, and we have been for a while. But as you can imagine, you can't stop adding features to your existing product and expect to survive. 1M lines of code isn't something you can port quickly.
85.
▲
by
sullivanmatt
10y ago
I work appsec for a company that provides a (primarily) flash-based web platform - Apache Flex, specifically. What people don't realize is the extreme cost of porting things like this to HTML5. We have nearly 1M lines of ActionScript.
86.
▲
by
sullivanmatt
10y ago
Cousin. Elon is the chairman of the board.
87.
▲
by
sullivanmatt
10y ago
OP did not read the article correctly. Untrue.
88.
▲
by
sullivanmatt
11y ago
The documentary is "Inside North Korea", for the curious: https://www.youtube.com/watch?v=mxLBywKrTf4
89.
▲
by
sullivanmatt
11y ago
The author of this article posted a follow-up a few days later, and more or less acknowledged that he should have done a bit more vetting of this "research" before going to press. The follow-up worth the read: http://w
90.
▲
by
sullivanmatt
11y ago
The Microsoft of today is not the Microsoft of 15 years ago. Nadella has a long history of embracing openness, especially with the Cloud Services division he was heading until his appointment as CEO. I think the open-sourcing of the .NET
More ›