Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bdesimone
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
It's always DNS part ∞: tracking down a use-after-free bug in Envoy's DNS
(pomerium.com)
5 points
by
bdesimone
9mo ago
|
0 comments
2.
▲
by
bdesimone
11mo ago
Posting a coworker’s deep dive on the nuance of health checks that actually represent readiness. If you’ve had pods say "ready" while still failing traffic during rollouts, this will resonate. Happy to answer any questions about t
3.
▲
Designing Smarter Health Checks for Pomerium
(pomerium.com)
6 points
by
bdesimone
11mo ago
|
4 comments
4.
▲
by
bdesimone
1y ago
FWIW, I'm very happy to see this announcement. Full MCP support was the only thing holding me back from using GPT5 as my daily driver as it has been my "go to" for hard problems and development since it was released. Calling
5.
▲
When AI Has Root: Lessons from the Supabase MCP Data Leak
(pomerium.com)
8 points
by
bdesimone
1y ago
|
1 comments
6.
▲
Employees Are Already Dumping Company Data to LLMs and What to Do About It
(pomerium.com)
10 points
by
bdesimone
1y ago
|
1 comments
7.
▲
by
bdesimone
1y ago
Genuinely, didn't take it that way at all! I don't expect you to be an expert on Pomerium. > Funnily enough, Octelium started as a sidecar ext_authz svc for Envoy instances to operate as an IaP but I ended up creating my own Go
8.
▲
by
bdesimone
1y ago
Quick note since it was mentioned. Pomerium does support Kubernetes at pretty much every level you mentioned (although I'm not entirely sure what a "a complete Kubernetes-tier platform" means) including: - "remote acce
9.
▲
Show HN: Pomerium Agentic Access Gateway – dynamic auth for AI agents
10 points
by
bdesimone
1y ago
|
0 comments
10.
▲
by
bdesimone
6y ago
Here's a collection of resources you might find helpful. https://github.com/pomerium/awesome-zero-trust/ Contributions/PRs very welcome.
11.
▲
by
bdesimone
7y ago
If you are interested in BeyondCorp-style access, I put together a collection of curated resources. https://github.com/pomerium/awesome-zero-trust PRs welcome.
12.
▲
by
bdesimone
7y ago
I agree that both can be used safely. And, yes to be clear, NMR here means "less likely to happen" not "better able to handle failure." Unfortunately, AES-GCM-SIV (or AEZ) aren't yet in Go's standard lib. But,
13.
▲
by
bdesimone
7y ago
In the document they say that AES-CBC is vulnerable to padding oracle attacks, and AES-GCM uses random nonces and requires key rotation after so many iterations.
14.
▲
by
bdesimone
7y ago
> I see where this is coming and agree in spirit, but GCM is actually idiomatic Go and implemented through the crypto/aead interface, which does about as good a job as any library at being user-proof. Good point, and I appreciate th
15.
▲
by
bdesimone
12y ago
Citizenship is already weird. My wife and I both being born in the US, we are tri-citizens and our descendants will also have tri-citizenship in perpetuity. It would have been quad-citizenship if Norway allowed for multiple passports.
16.
▲
by
bdesimone
12y ago
Yes. And you should probably assume that their claims of end-to-end encryption are about as solid as they were for iMessage. http://blog.cryptographyengineering.com/2013/06/can-apple-re... http://arstec
17.
▲
by
bdesimone
12y ago
In the very same doc you quote, they also say of iMessage: "Apple does not log messages or attachments, and their contents are protected by end-to-end encryption so no one but the sender and receiver can access them. Apple cannot decr
18.
▲
by
bdesimone
12y ago
"Reopened on Novebmer 6" Is this an early draft?
19.
▲
by
bdesimone
12y ago
I am happy to vouch for William who has been driving the Miami meet ups. He knows his Go and is able to deconstruct rather tricky subjects and present them in a way that's easy to understand. You should check out his blog to see what I
20.
▲
by
bdesimone
13y ago
I'm not suggesting prefixing.
21.
▲
by
bdesimone
13y ago
It's less complicated than what I'm reading here. * Use a passphrase of at least five random words.[1] * Keep that passphrases secret.[2] * Use a password manager like 1Password or Keepass to generate and manage all other password
22.
▲
by
bdesimone
13y ago
Agreed. Adds a bit of peer review to the mix.
23.
▲
by
bdesimone
13y ago
Edit2 = Damage control.
24.
▲
by
bdesimone
13y ago
Skettios. What is coinbase doing to prevent this from happening in the future? Both from a customer service perspective, and from a technical one. I want to assume good faith, but I'd also like to verify before doing business with you.
25.
▲
by
bdesimone
13y ago
/thread
26.
▲
by
bdesimone
13y ago
Dual citizenship does not need to be kept secret in the US.
27.
▲
by
bdesimone
13y ago
Unless you are published, a page is enough. Seriously.
28.
▲
by
bdesimone
13y ago
The pushback from tech community in the form of these reports has been encouraging. That said, a little part of me dies when I realize the USA has become a government that censors something like the reporting of the quantity of requests. Wh
29.
▲
by
bdesimone
13y ago
What are you talking about? My #3 point was not that dietary health isn't important. It IS important. It's as important as cardiology, renal, etc in the curriculum. That it's "only" one week is shouldn't be t
30.
▲
by
bdesimone
13y ago
EB as a term is new, the specialization is not. Most here are engineers with a BS/BA. Maybe a MA. And fewer still with a PhD. Not that education is everything, but it's certainly "years specializing." Compare that to the
More ›