Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
terom
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
23 ms
·
181.
▲
by
terom
5y ago
I assume you mean the original article from De Volkskrant [1]? Unfortunately it's a) paywalled b) in dutch, so I won't be reading it :( The original Capgemini report would definitely be interesting reading, but I don't expect
182.
▲
by
terom
5y ago
The title is misleading... my interpretation of the contents is that KPN outsourced the maintenance of their mobile core network to Huawei, and that Huawei personnel as a result had full technical access to the network. There is no evidence
183.
▲
by
terom
6y ago
Apart from the NTP tangent, this sounds like a Linux XFS / ServeRAID M5210 firmware issue. Your XFS filesystems created using the incorrect block/io sizes reported by the RAID controller would have been unmountable on the newer Li
184.
▲
by
terom
6y ago
Missed? https://twitter.com/EU_SST/status/1380601898164744199 > UPDATE: #EUSST’s network of sensors has only detected a single object or echo at passes over three radars after close approach. Most likely, the c
185.
▲
by
terom
6y ago
Anyone looking for Apache Mesos in the list of Apache Attic projects, news of its demise appears to have been greatly exaggerated: The decision to retire the project seems to have been canceled: [1] [1] https://lists.apache.org&#
186.
▲
by
terom
6y ago
See the Transport Fever / Transport Fever 2 series for what I would consider the "modern" 3D equivalent... apart from the fancy graphics you also have individually simulated passengers and more freedoms in terms of track/
187.
▲
by
terom
6y ago
A big :+1: for running Docker containers with `--read-only`, forcing you to use explicit writeable volume/bind mounts for all writable data... it's not just the security benefits, you can also avoid entire classes of problems like
188.
▲
by
terom
6y ago
https://www.google.com/search?q=site%3Ahttp%3A%2F%2Ftravaux.... there's quite a few of these http://travaux.ovh.net/?do=details&id=47840 earliest one that I found was back in December
189.
▲
by
terom
6y ago
This looks like the attacker is just using a publicly exposed Docker API honeypot to run a new Docker container with `privileged: true`. I don't see why that's particularly interesting given that they could just bind-mount the hos
190.
▲
by
terom
6y ago
CVE-2021-26937 assigned. [1] Apparently XTerm is also affected. [2] Reachable via irssi. [3] [1] https://www.openwall.com/lists/oss-security/2021/02/09/8 > Got CVE-2021-26937 assigned for this. [
191.
▲
by
terom
6y ago
Unsurprising to see such outages also tickling bugs/issues in the fallback behavior of dependent services that were intended to tolerate outages. There must be some classic law of cascading failures caused by error handling code :) >
192.
▲
by
terom
6y ago
If 0-100 is a percent, then wouldn't 0-1 be a perun(something)? I don't know latin, but perun, perune, peruni?
193.
▲
by
terom
6y ago
Is that going to actually help with the manifest-based rate limits? It sounds like it only caches the layers, the manifest metadata for a tag is not cached. https://docs.docker.com/registry/recipes/mirror/#wha
194.
▲
by
terom
6y ago
Easily with CI. Every pull request on the GitHub project will build a dozen Docker images whenever a PR is opened, updated or merged. Granted, there's only a couple base images involved, so CI pipelines will need updating to be more ef
195.
▲
by
terom
6y ago
Curious about the container capabilities that enabled them to attack the host network: per the docs [1] containers do not get `CAP_NET_ADMIN` by default, but they do get `CAP_NET_RAW`. I assume that's what allowed them to inspect/
196.
▲
by
terom
6y ago
There are multiple methods for automating AWS EC2 instance recovery for instances in the "system status check failed" or "scheduled for retirement event" cases. Yet to figure out how to test any of those cloudwatch alert
197.
▲
by
terom
6y ago
This. Worst-case you end up being forced to use some terribly implemented private cloud solution which ends up being even more expensive and time consuming than deploying your own hardware.
198.
▲
by
terom
6y ago
The idea would be to align the commercial interests of US cloud service providers with the privacy interests of EU customers. From the EU citizens perspective, the ideal outcome would be for US cloud service providers to pressure US authori
199.
▲
by
terom
6y ago
Quoting from the press release, the data exporter must take into account both the contractual clauses AND the surveillance laws of the target country. It is not sufficient to rely on a contract with a US data processor where the US surveill
200.
▲
by
terom
6y ago
That interpretation depends heavily on how much trust you place in the regional concept of data processing. AWS claims compliance with e.g. CISPE [1] which explicitly certifies specific cloud services such as to "Enable(s) data storage
201.
▲
by
terom
6y ago
I think this statement is saying that the US surveillance laws grant the US authorities unlimited access to the personal data of non-US citizens being processed in the US, and those surveillance programs do not respect the privacy rights of
202.
▲
by
terom
6y ago
That's the picture you can get from their recent blogs: * https://github.blog/2020-03-26-february-service-disruptions-... * https://github.blog/2020-07-08-introducing-the-github-availa...
203.
▲
by
terom
6y ago
It's just slightly disappointing that the CAs and browsers have agreed to operate under a policy that requires the CAs to revoke mis-issued subordinate CAs within 7 days (CA/B Forum BR 4.9.1.2), but that's not actually feasib
204.
▲
by
terom
6y ago
There's some related technical background in this 2014 bug report on Firefox rejecting a TLS server certificate issued by such an intermediate CA with the problematic 'OCSP Signing' EKU: https://bugzilla.mozilla.or
205.
▲
by
terom
6y ago
There's a reply from Ben Wilson (Mozilla) further down in the thread / the next day stating that Firefox as a client is not affected by the security issue (OCSP responses signed by these intermediate CAs would be rejected), and th
206.
▲
by
terom
6y ago
Meanwhile the Finnish President heads outside for a beer after the massive Trump and Putin motorcades have driven off (shutting down half the city in the process). https://www.hs.fi/politiikka/art-2000005762136.html
207.
▲
by
terom
6y ago
As someone with very limited Microsoft/Windows background, I would be curious to somehow better understand how these lessons would apply to the Linux world. What are the Linux equivalents of pass-the-hash, TAM/PAM/PAWs etc?
208.
▲
by
terom
6y ago
If each dedicated IP address is associated with a single hostname/certificate, then wouldn't it be relatively straightforward to map connections to a specific IP address back to a known hostname? You can probably just probe the IP
209.
▲
by
terom
6y ago
OpenSSL has licensing issues when linking with GPL applications (without an explicit exception in the GPL-licensed application, which is not uncommon). [1] Debian in particular does not allow distributing such packages, and the common worka
210.
▲
by
terom
7y ago
The collab_2.png screenshot shows `User-Agent: ... Slack/4.1.2 ... Electron/6.0.10 ...`, so it's their own desktop app doing the https://slackb.com/.. . HTTP 301 -> https://*.burpcollaborator.com
More ›