Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
different_sort
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
1.
▲
by
different_sort
4y ago
That is indeed the case.
2.
▲
by
different_sort
4y ago
Untrue, any valid access key pair set can call “GetSignInToken” and access the aws console.
3.
▲
by
different_sort
4y ago
Maybe I’m just an unimpressed security professional but I’ve still not seen evidence I’d call a breach. At least not a significant one if you want to argue sublantics. Workers at organizations get compromised all the time. This doesn’t mean
4.
▲
by
different_sort
4y ago
The screenshots on the linked tweet make it look like okta dog foods their own product for access to various services and someone has access to one of their admin accounts. Which is bad, but that could mean “we phished this one person who w
5.
▲
by
different_sort
5y ago
AWS Backup does exist.
6.
▲
by
different_sort
6y ago
Implicit grant is depecrated, in the forthcoming OAuth 2.1 [1] standard this is solidified. We start using the language "public client" and "private client", where a public client is an OAuth client like a mobile app or
7.
▲
by
different_sort
6y ago
I'm glad adblockers are back. I'm not sure if it ever truly left, but the moment there was a bit of resistance I was happy to jump ship to FF.
8.
▲
by
different_sort
6y ago
That is definitely not lost on me. Life imitates art.
9.
▲
by
different_sort
6y ago
Job Role/Further details are risky to discuss because this forum is read by my colleagues and likely the nerdier execs. I could leave it at I am someone very senior and actively involved in trying to tackle our problem, so I see the ef
10.
▲
by
different_sort
6y ago
I think it represented poorly. It's more than just code in one system. It's systems built upon systems built upon systems. It encompasses our network, our software deployment stack, our proprietary extensions to standards and much
11.
▲
by
different_sort
6y ago
I work in an huge enterprise. We have incredibly customized software and stacks that have not changed much for 30 years, because they did not need to. Now the people who wrote those stacks and who understand them are retiring/quitting.
12.
▲
by
different_sort
6y ago
That's a great example, thank you for sharing it.
13.
▲
by
different_sort
6y ago
I actually have never seen it's kubernetes security platform. If it's using RQL for that I would take that as a redflag that it won't support much customization or logic that would allow you to tailor it to your organization.
14.
▲
by
different_sort
6y ago
Prisma cloud (the cloud monitoring part) is not a great product. It lags pretty far behind cloud provider capabilities. I also got the email that orca probably sent to everyone in their CRM about this, and while I didn’t need any reason to
15.
▲
by
different_sort
6y ago
You're responsible for managing the server in beanstalk, but it's not far off. I suppose it's just an earlier generation of the same idea. WHat I mean is, beanstalk runs on EC2 instances that you are responsible to make sure
16.
▲
by
different_sort
6y ago
"You Can't Run Entire Applications". I mean, what are we really calling serverless. Many serverless platforms, like fargate allow you to bring a container image, and whatever happens in that container image is non of fargate&
17.
▲
by
different_sort
6y ago
Bit, bite? I see what you did there
18.
▲
by
different_sort
6y ago
This was a great read, thank you for sharing. I deal with identity and federation problems all day at work because I am one of those annoying enterprise customers. We’re just getting our external openid connect capability enabled and I’m ex
19.
▲
by
different_sort
6y ago
Where in Canada is socializing banned?
20.
▲
by
different_sort
6y ago
I love how you're using workers there. I've been on workers for years (only for static content mind you) and it's super cool.
21.
▲
by
different_sort
6y ago
Hashicorp vault? You probably have more secrets than SSH to protect. If you’re on AWS also consider high value add built ins like EC2 instance connect or ssm session manager so you can manage host access via IAM.
22.
▲
by
different_sort
6y ago
I saw ssh keys and was ready to get on my moral high horse about ssh certs, only to read the article to be talked down. Nice guide!
23.
▲
by
different_sort
6y ago
This is neat, thank you for sharing. I'm using the publii default theme on my website and it ranks quite high. It said to get an even higher ranking I should consider denser content, which makes sense given I just moved to publii and i
24.
▲
by
different_sort
6y ago
Thank you for your replies and insight, it's really appreciated. The way I see it with SPA and tokens in JS accessible space is that you're exposing your users to the possibility of token theft and user impersonation if someone is
25.
▲
by
different_sort
6y ago
Storing tokens in cookies would be against the spec wouldn’t it? I’m not putting rfc6749 on some sort of pedestal, but it clearly states that the tokens are in the response body and not set in cookies. Do you have any examples of Authorizat
26.
▲
by
different_sort
6y ago
Could you indulge me with any details? Not AWS or someone who works on k8s, I'm just always interested in war stories, and cloud providers "not working" is an interest too.
27.
▲
by
different_sort
6y ago
Reminder it's time to get off 1.16 now. Only 3 versions (current-2) are supported upstream. https://kubernetes.io/docs/setup/release/version-skew-policy...
28.
▲
by
different_sort
6y ago
What are the 'obvious privacy reasons' to not use google DNS/NTP? I am being 100% serious when I ask: What bad does someone expect to happen as a result of this.
29.
▲
by
different_sort
6y ago
big exhale Woah.
30.
▲
by
different_sort
6y ago
Thank you for your reply!
More ›