Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
benblack
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
benblack
11y ago
Lattice is a more minimalist approach, for those who desire the production hardened core of Cloud Foundry but prefer to bring their own PaaS components or simply experiment. http://lattice.cf/
2.
▲
by
benblack
13y ago
I make complete AMIs with packer, configure them entirely using environment variables in userdata, configuration data in etcd, and shell scripts, and run all services in docker containers, which I also build using packer. With all services
3.
▲
by
benblack
13y ago
Another possible explanation is that she is intelligent and motivated and you are an asshole.
4.
▲
by
benblack
13y ago
I made a shirt for all you guys who think the rape, erm, PICK UP ARTISTE, book is totes cool and nbd http://www.cafepress.com/mf/79293678/i-am-rape-culture_tshir...
5.
▲
by
benblack
14y ago
NIST has weighed in on how to use TLS: http://tools.ietf.org/html/rfc6460 I am not aware of any proposed attacks on the approved cipher suites that are anywhere near feasible. TLS deployment is far behind known best practice. We should do
6.
▲
by
benblack
14y ago
They've known for some time http://dictionary.reference.com/browse/ism .
7.
▲
by
benblack
14y ago
That you are unable to distinguish between an instance of sexual discrimination (called sexual discrimination) and systemic sexual discrimination (called sexism) does not mean anything political or Orwellian is afoot. Words have meanings. I
8.
▲
by
benblack
14y ago
Asserting all members of a group of people are subhuman sure does sound like something that happened in Europe in the 30s and 40s. What point were you trying to make? Immanentize your personal eschaton, Lil 'B
9.
▲
by
benblack
15y ago
Seems like a lot of folks missed the section of the post explaining their implementation and use of _ECDHE_ not _EDH_. The performance impact of ECDHE is surprisingly small.
10.
▲
by
benblack
15y ago
Correct!
11.
▲
by
benblack
15y ago
More great work from Google legitimizing and advocating for strong HTTPS defaults. I'm looking forward to this being broadly adopted. Securely Yours, Lil' B
12.
▲
Ex-Amazon EC2 wizard pinpoints where your cloud is crap
(channelregister.co.uk)
12 points
by
benblack
15y ago
|
0 comments
13.
▲
by
benblack
15y ago
We have no plans to support Thrift.
14.
▲
by
benblack
15y ago
Much like our engineers, our software is extremely opinionated. Ordasity, Scalang, and Overlock are all small, extremely focused libraries to solve a single problem in a single way. This is quite similar to the Unix philosophy and we have
15.
▲
by
benblack
15y ago
Well said, sir.
16.
▲
by
benblack
15y ago
What does he charge to just shut up already?
17.
▲
Characterizing the Scalability of Erlang VM on Many-core Processors
(kth.diva-portal.org)
8 points
by
benblack
15y ago
|
0 comments
18.
▲
by
benblack
15y ago
The formatting tool in question defaults to _not_ doing this, specifically to comply with the Scala Style Guide which does _not_ do this. The tool had to be explicitly configured to make this unfortunate change.
19.
▲
by
benblack
15y ago
You've got it backwards: I haven't seen anyone, including Chas, argue for disallowing Unicode. As you say, replacing a simple, common, 2 character operator with the unusual Unicode version is an odd and inconvenient decision. At present,
20.
▲
by
benblack
15y ago
Ask and ye shall receive: https://github.com/bumptech/stud/pull/6 stunnel DH code inserted into stud.
21.
▲
by
benblack
15y ago
Banks are unfortunately poster children for what not to do in this space, generally. The default cipher for google.com is RC4-SHA, and I can, if so inclined, force negotiation of AES-based ciphers by client config. Not so with Citibank (R
22.
▲
by
benblack
15y ago
While I would certainly prefer to see the major players leading the way in adoption of AES by default, RC4-MD5 persists for at least 2 reasons: 1) Habit 2) As implemented/deployed in SSL, it still provides some security RC4 has gotten a bad
23.
▲
by
benblack
15y ago
I am recommending that people who do not understand the trade-offs and do not have the traffic for it to matter should probably leave those safe defaults alone. What the banks choose to do is unfortunate, but should not dictate behavior.
24.
▲
by
benblack
15y ago
Correct, disagreeing with you implies trolling. You are one astute dude, Tom. Keep up the good work!
25.
▲
by
benblack
15y ago
On a related topic, these are both your comments on this post: "The win here is that losing the RSA key now only allows you to MITM future SSL/TLS connections. This is still a disaster, but it does not allow you to retroactively unwind prev
26.
▲
by
benblack
15y ago
Adam's post is rather more thorough and nuanced, which makes sense since he actually understands SSL and benchmarking. While you might summarize them both as "DHE is expensive", I don't know why you would. Here is each post on DHE: Adam -
27.
▲
by
benblack
15y ago
An article about configuring SSL that doesn't 1) discuss trade-offs of security vs. resource consumption, 2) how to figure out your performance requirements, and 3) indicate the author really understands implications of decisions about cryp
28.
▲
Geological Survey of Japan - Catalogue of Geologic Maps
(gsj.jp)
2 points
by
benblack
15y ago
|
0 comments
29.
▲
by
benblack
15y ago
POST to /add to create a resource? Strange, redundant, and the sort of thing I thought died with old versions of Rails. Riak/Webmachine and CouchDB get this right. Because knowledge is power, here is the section on methods in the HTTP 1.
30.
▲
Breaking GSM with Rainbow Tables
(arxiv.org)
2 points
by
benblack
15y ago
|
0 comments
More ›