Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
DrRobinson
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
27 ms
·
1.
▲
by
DrRobinson
2y ago
See `command:`
2.
▲
by
DrRobinson
2y ago
This comment seems out of place to me. It brings up (claimed) political issues irrelevant to the topic at hand. The account is recently created and this is the first and only comment/post they've made on this site.
3.
▲
by
DrRobinson
2y ago
Personally I disagree, I think `--` is very intuitive. Maybe it isn't super common knowledge, but `--` is in line with the POSIX argument parsing convention[0] and is used by many (most?) GNU/BSD tools and many other tools such as
4.
▲
by
DrRobinson
2y ago
I think some of the information here is misleading and a bit unfair. > being too intrusive and affecting their workflow Kolide is a reporting tool, it doesn't for example remove files or put them in quarantine. You also cannot execu
5.
▲
by
DrRobinson
3y ago
It's news _from_ 2023, not news about things that happened only in 2023. Things might have improved starting years ago but the research to show it wasn't finished until this year, so it's also about celebrating seeing progres
6.
▲
Capslock: What is your code capable of?
(security.googleblog.com)
2 points
by
DrRobinson
3y ago
|
0 comments
7.
▲
by
DrRobinson
3y ago
> Terraform doesn't have a test suite- Grunt made Terratest They have experimental support: https://developer.hashicorp.com/terraform/language/modules/t...
8.
▲
by
DrRobinson
3y ago
Great to see your commitment but I'm also curious why you, unlike some other companies, have chosen not to support with any full time employees? It seems your business is largely based on Terraform and saying pretty much "we'
9.
▲
by
DrRobinson
3y ago
Trakt.tv is a good alternative to IMDb btw
10.
▲
Scarleteel: Operation leveraging Terraform, Kubernetes, and AWS for data theft
(sysdig.com)
2 points
by
DrRobinson
4y ago
|
0 comments
11.
▲
by
DrRobinson
4y ago
This comment seems overly harsh in my opinion. I don't think the author comes off as a self-involved twat and I generally found the website helpful. > Neither me nor my coworkers give a damn about being kind. I don't see this a
12.
▲
by
DrRobinson
4y ago
This is a scam rather than a phishing attack. They've set up fake stores to steal money, not a phishing site to steal credentials.
13.
▲
Russian Cyberattacks
(gov.pl)
2 points
by
DrRobinson
4y ago
|
0 comments
14.
▲
by
DrRobinson
4y ago
This would require you or the person in the data center to know which customer is using which disk. And data isn't stored on just one disk, it's spread out over multiple disks and many customers have shards of data stored on the s
15.
▲
by
DrRobinson
4y ago
> This is a different argument. Part of it, maybe. But the point about it reducing risk by very little is true. > Did you see other comments in this thread, for example someone bought a drive online and turned out it still had some ba
16.
▲
by
DrRobinson
4y ago
> Do you bother with Spectre mitigations since Amazon policy is to deny service to those who would attack you? I don't go out of my way to mitigate that, no. Have you seen any real attacks with this? They seem very rare and hard to
17.
▲
by
DrRobinson
4y ago
> Definitely not "close to useless". It lowers the risk a minimum amount (which makes it not useless, but close to it.) Your resources are limited, so you want to prioritize actions that have good cost:benefit ratio. Re-encrypt
18.
▲
by
DrRobinson
4y ago
I agree. The problem is mainly going from an infrastructure that's not setup like this, to an infrastructure that is. Usually you inherit an infrastructure, and it's usually not set up in this way (in my experience) and then there
19.
▲
by
DrRobinson
4y ago
> Saying that something is hard to clean up later isn't “close to useless and potentially harmful” The "close to useless" is based on it lowering any risk with very little, it's not a big payoff security wise in most
20.
▲
by
DrRobinson
4y ago
> And yes, default service KMS keys are unique per account (why would you expect otherwise?). I expect it to be unique per account, but I would be happy if it was possible to share it with other accounts so one could make cross account b
21.
▲
by
DrRobinson
4y ago
> It’s more that the author is arguing that their inexperience is universally applicable. “Why do banks have guards, I’ve never had someone break into my couch cushions?” That was not my intention and it's unfortunate that's ho
22.
▲
by
DrRobinson
4y ago
I agree calling it snake oil is a bit too much, because I know there are benefits. As I mention elsewhere in the thread, I use encryption, but I don't consider it to be of high value compared to other security mitigations one can spend
23.
▲
by
DrRobinson
4y ago
You put it really well, I think that's close to how I think about it. Compliance has good sides too though. For example, they force you to think about areas your intuition might otherwise not have gone, so I don't dismiss them but
24.
▲
by
DrRobinson
4y ago
> Hubris of an inexperienced engineer imho. This seems unnecessarily hostile. I've worked with cloud infrastructure and security for more than 10 years. If you have experience of unencrypted disks being stolen from AWS I'm very
25.
▲
by
DrRobinson
4y ago
I think this is a valid point, though I don't expect the people in the datacenter to know which customer stores data on which disks. There could of course still be someone working there that steals data from all customers and you end u
26.
▲
by
DrRobinson
4y ago
Hello, author here! What you describe is essentially what I currently do. But I've inherited an infrastructure that was not setup that way, and re-encrypting things has been very time consuming. The company I'm at now use multiple
27.
▲
Problems with disk encryption in AWS
(tmp.bearblog.dev)
44 points
by
DrRobinson
4y ago
|
95 comments
28.
▲
by
DrRobinson
4y ago
I think it's worth pointing out that this is an answer generated by ChatGPT. It seems a bit dishonest to hide that fact since OP asked what helped _you_.
29.
▲
by
DrRobinson
4y ago
That could be very costly if it's about nuclear weapons, for example.
30.
▲
Secure Filesystem in Docker
(tmp.bearblog.dev)
2 points
by
DrRobinson
4y ago
|
0 comments
More ›