Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
yrro
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
91.
▲
by
yrro
2y ago
AIUI this is still not user level authentication. It rather secures the communication between hosts, but you still have to choose between sec=sys ("trust me bro") or sec=krb5* at the upper layer.
92.
▲
by
yrro
2y ago
The only per-user authentication option is Kerberos. Username/password based authentication is not possible.
93.
▲
by
yrro
2y ago
No because you still have to trust the client. With Kerberos a hacked client where user 1 has authenticated can't impersonate user 2 unless that user has also authenticated on the client. With sec=sys the client is simply trusted witho
94.
▲
by
yrro
2y ago
We're not there with authentication yet (although I've no problem with Kerberos myself).
95.
▲
by
yrro
2y ago
To be precise, the prefixes advertised within an RA message have an 'autoconfig' flag; if you unset this flag then hosts won't do SLAAC. So if you set the M-flag on your RAs, and unset the A-flag then hosts will have to use D
96.
▲
by
yrro
2y ago
This is what happens when 100 monkeys write code instead of 1 intelligent developer.
97.
▲
by
yrro
2y ago
Couldnt have put it better myself. The sheer incompetence is staggering and frankly it's depressing that these giant corporations are so good at selling their steaming piles of shit to companies who should really know better. If PAN-OS
98.
▲
by
yrro
2y ago
Correction, Mikrotik might support this after all if I understand https://wu.renjie.im/blog/network/ros-dhcpv6/#enable-dhcpv6-... correctly!
99.
▲
by
yrro
2y ago
Not following the point for push notifications sorry. Securing VMs: if your hypervisor is now routing packets between your virtual networks and your physical network then you need a packet filter on the hypervisor AND a packet filter on the
100.
▲
by
yrro
2y ago
> Out of this, a customer router should advertise a /64 on each interface, for devices on networks that only want a single address, and hand out /56s or /60s via DHCPv6 IA_PD for devices that want more[...]. That said, sup
101.
▲
by
yrro
2y ago
Indeed, I believe most end-user devices should use RFC 8981 (Temporary Address Extensions for Stateless Address Autoconfiguration in IPv6) to avoid pervasive monitoring. However you must bear in mind that this does nothing to prevent web br
102.
▲
by
yrro
2y ago
Indeed, regulators need to take so-called ISPs to task and mandate provision of at least a /48 to each customer.
103.
▲
by
yrro
2y ago
> IPv6 has no subnet masks What? no... I _think_ I see where the author is coming from, but the assumption that your ISP will hand out a single /64 is evidence of IPv6/NAT-style thinking. The minimum an ISP _should_ hand out to
104.
▲
by
yrro
2y ago
Assuming anyone can send a DHCP request and the IPs handed out by the DHCP server are added to the allowlist, what does your audit data look like? Something like: 2024-04-16 12:15:01 ac:de:48:00:00:01 uses address 192.168.2.255 for th
105.
▲
by
yrro
3y ago
"A computer can never be held accountable, therefore a computer must never make a management decision" The IDF only read the first half of the classic IBM slide!
106.
▲
by
yrro
3y ago
The funny thing is that libsystemd _used_ to be split into several different libraries. I certainly remember libsystemd-journal (which is presumably the part of libsystemd that pulls in liblzma) being separate to libsystemd-daemon (which is
107.
▲
by
yrro
3y ago
I wonder what the point is, I don't remember GitHub warning me that I've used the se SSH key for years...
108.
▲
by
yrro
3y ago
After initially being keen on running qemu directly, I've really come to appreciate libvirt, even thought you do have to be willing to peer past all the XML...
109.
▲
by
yrro
3y ago
FYI, 'curl -sL -H "Accept: text/roff" https://jamesg.blog/2024/02/28/programming-projects/ | man -l /dev/stdin' works for me - no need to safe the roff file locally.
110.
▲
by
yrro
3y ago
If only there was some sort of system of named domains within which the products and services of various organizations could be located...
111.
▲
by
yrro
3y ago
A blocked xyz. in my DNS server configuration the day I learned about it and have yet to be pro en wrong.
112.
▲
by
yrro
3y ago
Here are some ones from MacOS 7: https://osxdaily.com/2018/01/01/classic-mac-os-tiling-wallpa...
113.
▲
by
yrro
3y ago
If your organization uses any Oracle software then I'm certain that the organization has agreed to let Oracle audit it for license compliance at any time.
114.
▲
by
yrro
3y ago
This is good, but runas already exists. Its interface is shit. Improve it to make it not shit please. Don't hijack the name of an existing command unless you're going to re-implement its interface 100% compatibly. This is like whe
115.
▲
by
yrro
3y ago
Already exists, read up about "Windows on Windows" and "WOW64" :)
116.
▲
by
yrro
3y ago
FYI that's a link to a now very old internet draft. The current draft can be found here: https://datatracker.ietf.org/doc/draft-ietf-uuidrev-rfc4122b...
117.
▲
by
yrro
3y ago
> Still, trying to open it up to basically anything that's highly immersive feels wrong to me. I can deeply immerse myself into a book, becoming unconscious of my surroundings and even completely loosing track of time. Nevertheless
118.
▲
by
yrro
3y ago
No one competent would ever have thought dev. was safe. It's quite simple: if you don't own the domain, or it hasn't been reserved (e.g., home.arpa.), don't use it!
119.
▲
by
yrro
3y ago
Would it relax you to know that it has been retconned into "Address Routing Paramater Area"?
120.
▲
by
yrro
3y ago
> informal standard FAFO, as they say.
More ›