Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ptcrash
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
ptcrash
2y ago
Happy to see the effort! Fresh blood in the authn space is always welcomed. Without rehashing the other good points commenters have made already, I’ll just say that every project starts out immature. What makes a project great is how willin
2.
▲
by
ptcrash
2y ago
I think it's more of a logic problem. I suspect the engineers made a false assumption that bcrypt can hash a trivial amount of data like some other hashing algos.
3.
▲
by
ptcrash
2y ago
If you want to validate a username/password authn attempt against a cache, then yes the username and password have to be someone in the mix.
4.
▲
by
ptcrash
2y ago
Yes but PIV/CAC identity is not related to break-glass passwords. They both serve different purposes and it's safe to assume that the typical government worker will only ever need to use their smart card to authenticate into syste
5.
▲
by
ptcrash
3y ago
Ignoring obvious flame-bait, it sounds like the termination was an amicable feeling then, yeah?
6.
▲
by
ptcrash
3y ago
Would you care to share for those of us who haven’t written a grant application before?
7.
▲
by
ptcrash
3y ago
Both situations seem possible. I guess time will tell how Unity wants to move forward. Others mentioned it earlier but it looks like Godot had a big boost in users from this fiasco. Perhaps Unity is concerned about real financial damages do
8.
▲
by
ptcrash
3y ago
Well, the transition in leadership is uncommon but they don’t officially give us a reason, so we’re left to speculate until someone inside gives us more info. But from a purely speculative standpoint, it seems very possible that they were o
9.
▲
Texas Central and Amtrak Seek to Explore High-Speed Rail Service Opportunities
(media.amtrak.com)
2 points
by
ptcrash
3y ago
|
0 comments
10.
▲
Chemex Brew Perfect
(chemexthegame.com)
1 points
by
ptcrash
4y ago
|
0 comments
11.
▲
by
ptcrash
4y ago
Non-paywall link: https://web.archive.org/web/20221215195859/https://www.washi...
12.
▲
by
ptcrash
4y ago
Same here. I also switch to light mode when I'm in a very bright environment and it seems to have helped a lot with eye strain since last year. I feel like these studies are being a bit 1-dimensional... but then again, maybe that'
13.
▲
by
ptcrash
4y ago
I'd argue it's because the risk is not worth the reward. Pingback and Trackback is used to send a monsoon of spam and I'd wager site maintainers are not too keen on enabling the new version of an old problem.
14.
▲
by
ptcrash
4y ago
I've read through the spec along with the FAQ that epeus so graciously shared here. The idea of mentioning beyond the scope of one website's walled garden seems like a very natural progression of ActivityPub and the new-found hype
15.
▲
by
ptcrash
4y ago
Is this a new iteration in fail2ban? I gave it a cursory look and I couldn’t find any new features that make it a better tool than its predecessor
16.
▲
Slippery RansomExx Malware Moves to Rust, Evading VirusTotal
(darkreading.com)
2 points
by
ptcrash
4y ago
|
0 comments
17.
▲
OWASP Damn Vulnerable Web Sockets
(owasp.org)
28 points
by
ptcrash
4y ago
|
0 comments
18.
▲
by
ptcrash
4y ago
It's not just arcane it's a horrible idea from an infosec perspective. Thinking about all my wonderful developers having local trusted root CAs just sitting on their hard drives is making my blood pressure skyrocket.
19.
▲
by
ptcrash
4y ago
I didn’t know what NeRFs were so I had to look it up. This article seems like a good introduction for anyone else that’s out of the loop like me: https://www.matthewtancik.com/nerf
20.
▲
by
ptcrash
5y ago
I think it's neat to see company's like VMWare try to amalgamate containerization into their portfolio. Tanzu is like all the cons of on-prem like inelasticity applied to K8s
21.
▲
by
ptcrash
5y ago
I don't have an easy answer for you because I'm still struggling to find the "proper" solution myself. That's why I'd kill to have the agencies weigh in. I'm not a fan of SealedSecrets or managing secrets
22.
▲
by
ptcrash
5y ago
The guideline was updated this month but released last year. That dupe link probably has a lot of relevant discussion.
23.
▲
by
ptcrash
5y ago
One of the most common misconfigurations I've seen is improper secrets handling. I'm glad to see it called out but I wish they would go into a little deeper detail on detection and remediation. Overall looks pretty good! I'm
24.
▲
by
ptcrash
5y ago
Yes. While many agencies have a bad reputation post-Snowden, CISA and NSA have for many years - and will continue to release hardening guides that are invaluable to security engineers.
25.
▲
Ukrainian Numbers Stations S06s and E17z Go Silent
(numbers-stations.com)
50 points
by
ptcrash
5y ago
|
6 comments
26.
▲
by
ptcrash
5y ago
That's enlightening; thanks. Hopefully the steps forward for determining scope and affected objects is easy
27.
▲
by
ptcrash
5y ago
Okay, opinions up front: I don't think this is worthy of "declaring a security incident. Having some experience working behind the scenes, just because this policy was changes this way doesn't mean "All AWS Support perso
28.
▲
by
ptcrash
5y ago
Having some authority on the subject because I've seen how both GCP and AWS handle their public status pages internally. They are manually updated by hand and are the last step in raising a large-scale issue. Automated issue notificati
29.
▲
by
ptcrash
5y ago
When did AWS lie? On their status page? That's the last place to receive updates on service status. It sucks but it's also common knowledge. I'll give you a little insider knowledge: The SHD is updated manually. If it's
30.
▲
by
ptcrash
5y ago
Let's try to remember the guidelines, be kind, and have curious conversation. Hacker News isn't the place for baseless speculation and generalization. AWS publishes postmortems for major outages here: [1] This outage was significa
More ›