Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
this-dang-guy
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
this-dang-guy
10y ago
I think it would an interesting exercise to attempt to build a reasonably modern device that's truly audited and secure head-to-toe. If it could be done with proper 'design by contract', inspections, and at a cost that folks
62.
▲
by
this-dang-guy
10y ago
The thing that really scares me , as a fortunately ex-security guy, is the fact that everywhere I've worked for the last 10 years people are super casual about keyboards and mobiles. Mobile phones are an amazing platform to do... well
63.
▲
by
this-dang-guy
10y ago
Even the aerospace/defense companies I work with use almost 100% off-the-shelf hardware pre-installed with OS and software by the vendors, or at least with some minimal IT work (often offshore). I'm happy to hear that there are so
64.
▲
by
this-dang-guy
10y ago
Yes - if we're going to include ultra-sonics, air-gap spanning networks, things of that nature... yeah, it gets very quickly into the range of nearly impossible to catch. Especially if it's intermittent or simply passive. Then you
65.
▲
by
this-dang-guy
10y ago
You are correct, I should have been more clear in my phrasing.
66.
▲
by
this-dang-guy
10y ago
I've not seen that, but I have seen one where the root password was the vendor who supported it - like capgem123 ibm123 etc. Not quite as bad, but still pretty weak.
67.
▲
by
this-dang-guy
10y ago
And your point is? It's not a hard problem. You either trust your fabricator and tools, or you don't . End of freaking story. If you don't, and/or you can't throw a fab plant at it, your options are limited. You
68.
▲
by
this-dang-guy
10y ago
Unlikely to be much unless there's a prevailing need. I think it's easier to do deep packet inspection if you're that concerned, honestly.
69.
▲
by
this-dang-guy
10y ago
Must be. No, I'm not. I'm based in AZ.
70.
▲
Some Say it's the best car show ever. All I know is it's not the Stig
(arstechnica.com)
2 points
by
this-dang-guy
10y ago
|
0 comments
71.
▲
by
this-dang-guy
10y ago
Must say I'm a bit jealous - when I started my company, I didn't have any need to decline VC coffee invites... it was all I could do to get enough interested parties to even get moving. Good tips on time mgmt though, I guess
72.
▲
by
this-dang-guy
10y ago
Exactly - sorry, was busy :)
73.
▲
by
this-dang-guy
10y ago
I don't believe they have in any way violated the letter or even spirit of the BSD license. It's extremely liberal, and should be. However, they used to really flaunt their BSD roots on OSX, but seem to do very little to give back
74.
▲
by
this-dang-guy
10y ago
A VM to virtualize other software. In this case, my desktop has to support some clients who have very specific VM images of Win7 to access them. VirtualBox and VMware are fine, but for QEMU it's just way too slow (for me, at the moment
75.
▲
by
this-dang-guy
10y ago
That's a big book right there! I was really disappointed in how Apple treated BSD, but I am stupid and naive. I would have expected that from IBM though.
76.
▲
by
this-dang-guy
10y ago
Digital Ocean supports FreeBSD, but not OpenBSD. Which is close, but not quite the same. Perhaps with a little persuasion, they could be talked into it
77.
▲
by
this-dang-guy
10y ago
Sadly yes. For several specific clients I have to run their Win7 VM in an emulator, and it can't quite manage on my (rather old) hardware right now. Due for a hardware refresh soon, and I will obviously be trying it again :)
78.
▲
by
this-dang-guy
10y ago
A very valid point. IBM contributes a TON of code to Linux. They could easily have worked to improve security if they cared. Or, improved BSD, and avoided all that GPL stuff if they wanted.
79.
▲
by
this-dang-guy
10y ago
I also use OpenBSD (and donate to it, since I have more money than time right now)... but damn, they do need a VM that I can use, so that it can be my regular desktop.
80.
▲
by
this-dang-guy
10y ago
Absolutely. I would actually argue that security doesn't depend on any one product, but instead a mindset, methodology, and toolbox. Defense in depth, etc.
81.
▲
by
this-dang-guy
10y ago
Sure, but comments like: "Security people are often the black-and-white kind of people that I can't stand. I think the OpenBSD crowd is a bunch of masturbating monkeys, in that they make such a big deal about concentrating on secu
82.
▲
by
this-dang-guy
10y ago
Exactly. That's ridiculous thinking far beyond what the OS designer is responsible for.
83.
▲
by
this-dang-guy
10y ago
Yeah, I went down that rabbit hole a bit. The point is - it's about the only way to do a real actual code audit on what your processor is doing.
84.
▲
by
this-dang-guy
10y ago
I really do need to put more effort into using OpenBSD for my daily stuff. I use it for my router, but my desktop is Linux (Steam. It's because of Steam. I'll be totally honest :D )
85.
▲
by
this-dang-guy
10y ago
Ahem http://rationalviews.com/t/presentation-on-fully-open-source... You could go into that rabbit hole. I'd recommend against it... I lost days reading all the docs and playing with this
86.
▲
by
this-dang-guy
10y ago
Yes, but the quality of oracle means that a backdoor is your least concern ;)
87.
▲
by
this-dang-guy
10y ago
Very "Secrets from the future" of him :D
88.
▲
by
this-dang-guy
10y ago
Let's not forget the great OpenBSD code audit caused when someone from the FBI claimed to have planted a backdoor. http://arstechnica.com/information-technology/2010/12/openbs...
89.
▲
by
this-dang-guy
10y ago
The biggest issue with Windows isn't its inherent security, it's the way it's used. Most users run everything with super admin rights. Most developers require that for installs. OSX is right behind it, with a culture of lax
90.
▲
by
this-dang-guy
10y ago
There's plenty of great quotes from Torvalds about why it's like that. He places functionality over security, and assumes security will just 'happen' with code quality. I tend to disagree - but I am typing this from
More ›