Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
terom
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
21 ms
·
211.
▲
by
terom
7y ago
LE just posted their own (excellent!) incident report of this on the mozilla bugtracker, including the discovery timeline, analysis of the bug, and follow-up steps: https://bugzilla.mozilla.org/show_bug.cgi?id=1619047#c1 Th
212.
▲
by
terom
7y ago
For even more context, this seems to have been on a Friday night (assuming US West coast) with production down: https://letsencrypt.status.io/pages/incident/55957a99e800baa... I'll cut the LE team some slack
213.
▲
by
terom
7y ago
For context in terms of what caused this, here's the PR which I assume fixed the bug in question: https://github.com/letsencrypt/boulder/pull/4690 It looks like a nasty and subtle pass-by-reference of a
214.
▲
by
terom
7y ago
Here's some quick&dirty stats from the list of revoked certificates: https://gist.github.com/SpComb/6338facd12e020ec4fe561ca91f32... There's 3M "missing CAA checking results" in total, of which
215.
▲
by
terom
7y ago
Here's some quick&dirty stats from the list of revoked certificates: https://gist.github.com/SpComb/6338facd12e020ec4fe561ca91f32... There's 3M "missing CAA checking results" in total, of which
216.
▲
by
terom
7y ago
I do a lot of ops-ish work, and in addition to all the nice declarative configuration-as-code things where infrastructure changes are reviewed and applied in pull-request form, there's a lot of ad-hoc debugging/diagnosing and one-
217.
▲
by
terom
7y ago
This is something I was trying to research at one point: > While there have been no reported isolation compromises in any major cloud platform, What about minor cloud platforms? I'm would be surprised if there hasn't been real
218.
▲
by
terom
7y ago
Re myself, it looks like they're using FreeBSD-based ZFS filers with iSCSI/NFS exports using a user-spce NFS server: * https://news.gandi.net/en/2019/09/exporters-detect-micro-inc... > Gandi’s st
219.
▲
by
terom
7y ago
From the incident timeline: > we have a problem to import zfs pool on the unit storage I really want to know what went wrong to a) break ZFS b) prevent recovery from backup.
220.
▲
by
terom
7y ago
>>> cb = bytes.fromhex('6968766f606e776c2d2d21262138475c5b5a475b545e475c6b6a776b646e776c6b6a772b646e776c6b6a776b646e776c6b6a776bbadf04036b6a776c616a846f') >>> pb = b'\x02\x02\x01\x04\x04\x00\x00\x00FG
221.
▲
by
terom
7y ago
While I've been happily using Slack's pseudo-markdown for a long time, a lot of the less technical users on our slack have never posted messages with any formatting, which makes things like copy-pasted error stacktraces a pain to
222.
▲
by
terom
7y ago
I just bought my rockstar 10x tester an office cat, and then accidently hit the home button on my browser instead of exiting the shop. RIP office cat :< Needs to use local storage to save and restore the game state.
223.
▲
by
terom
7y ago
> Encrypting Files > This really is a problem. If you’re/not/ [...] then there’s no one good tool that does this now. Filippo Valsorda is working on “age” for these use cases, and I’m super optimistic about it, but it’s not
224.
▲
by
terom
7y ago
Debian buster VM on an old CPU without RDRAND takes about 5 minutes for the kernel crng init to complete and for sshd to start accepting connections. Stracing the sshd process shows that it's indeed blocked on `getrandom()`. In some wa
225.
▲
by
terom
8y ago
This was back in December. I tried asking about it, but wasn't able to find any info about what kind of policy they intended to have on their network. Who knows, maybe I complained enough that they fixed it? :)
226.
▲
by
terom
8y ago
My first experience with Oodi was unfortunate: The only publicly available Wi-Fi network (Stadinetti) blocks all outgoing non-HTTP/HTTPS traffic (SSH, IMAP, etc). So much for trying to do any remote working or studying for things like
227.
▲
Show HN: CLI for testing Logstash grok patterns
(github.com)
2 points
by
terom
8y ago
|
0 comments
228.
▲
by
terom
8y ago
Reading this post-mortem and their MySQL HA post, this incident deserves a talk titled: "MySQL semi-synchronous replication with automatic inter-DC failover to a DR site: how to turn a 47s outage into a 24h outage requiring manual data
229.
▲
by
terom
9y ago
There's now a PoC exploiting this race, seemingly placing the 32-bit -l option value into the uninitialized part of the `struct input_event` to modify a shell script that runs as root: https://gist.github.com/fkt/5
230.
▲
by
terom
9y ago
My speculation on the race condition fixed in the patch: The while loop in `main` calls `play_beep` multiple times. Each call to `play_beep` opens the `--device` and sets the global `console_fd`, and then sets the global `console_type` ba
231.
▲
by
terom
9y ago
kubeadm seems to configure the kubelet with `--authorization-mode=Webhook`, which prevents the use of the exec API by unauthenticated users: $ curl -vk -X POST https://...:10250/exec/test ... < HTTP/1.1 4
232.
▲
by
terom
9y ago
I would indeed like to explicitly apologize, because I regret mentioning "cloudflare etc" as an example. That's exactly the kind of bad speculation that leads to harmful rumors based on misunderstandings. > When you say &q
233.
▲
by
terom
9y ago
Too late for me to edit this comment anymore, but in order to avoid spreading any false rumors, I'd like to explicitly state that I have no reason at all to believe that Cloudflare in particular would be affected by this, and I do not
234.
▲
by
terom
9y ago
Sorry, I just chose cloudflare as a random example when speculating, I don't have any information about what specific providers this would affect, and I'm not implying that cloudflare would be affected. Seems like my guess was rig
235.
▲
by
terom
9y ago
Do we get points for speculation based on these hints? My guess would be that some major public CDN (Cloudflare etc) will let the attacker deploy their TLS-SNI challenge certs, and thus validate for other victim domains using the same CDN s
236.
▲
by
terom
9y ago
There's also an INTEL-SA-00088 which implies that it's only addressing the meltdown vulnerabilities: https://security-center.intel.com/advisory.aspx?intelid=INTE... > Other variants of this side-channel analysi
237.
▲
by
terom
9y ago
Check out https://github.com/stretchr/testify for more convenient assertions, as well as mocking support for implementing interfaces within your tests. You cannot do ad-hoc mocking of arbitrary functions in Go. If you
238.
▲
by
terom
9y ago
The article discusses an actual partial prefix match. > we tested out a case in which only a portion of the correct response hash is sent to the AMT web server. To our surprise, authentication succeeded! > Next, we reduced the respons
239.
▲
by
terom
10y ago
Replication systems can break. They work working on fixing the broken db2 read replica when they accidentially nuked the primary db1 server. > db2.cluster refuses to replicate, /var/opt/gitlab/postgresql/data is
240.
▲
by
terom
10y ago
Are there exceptions to this rule, i.e. legit uses for deauth mechanisms? > Marriott admitted that the Wi-Fi users it blocked did not pose a security threat to the Marriott network. > Similarly, Smart City submitted no evidence that t
More ›