Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
raesene4
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
raesene4
10y ago
Good article even though I don't agree with all the conclusions. I find a good way to think about things is that every single dependency you have adds another set of people you have to trust. You're trusting the competence of the
2.
▲
by
raesene4
10y ago
This is v.cool, although for the Windows version it'd be great if it became possible to swap out the virtualization back-end so it's not tied to Hyper-V. At the moment VMWare Workstation users will be a bit left out as Windows doe
3.
▲
by
raesene4
10y ago
for NPM? As far as I'm aware it's not even an available feature. None of rubygems/PyPi/NuGet require digital signatures... What repositories were you thinking of that do require that?
4.
▲
by
raesene4
10y ago
A big problem with Software repositories that don't allow for /enforce cryptographic signing by the developer is that this can happen... Ideally the developer would sign before publishing and the consumer could check the signature
5.
▲
by
raesene4
10y ago
Most of the programming language Package managers that I've seen either don't have the facility or it's not widely used.
6.
▲
by
raesene4
11y ago
Yep, at the moment, with raw docker engine, if a user has access to create containers, they're basically able to get root on the box, as the docker daemon runs as root and there isn't any authorization control by default, so it do
7.
▲
by
raesene4
11y ago
With 1.10 you can just enable User namespaces, which allows for root in a container to map to a non-privileged user outside the container, that way it's a one-time (per instance) change.
8.
▲
by
raesene4
11y ago
I'd say that it's a trade-off whether you think the enhanced isolation provided by containerization/virtualization is more of a security benefit than the risks posed by the increased attack surface of another layer in the sta
9.
▲
by
raesene4
11y ago
Good presentation. One thing I'd mention is that they talk about the CIS security guide, but it's currently pretty out of date as it covers 1.6 and therefore misses a lot of Docker features like Content Trust, User Namespaces and
10.
▲
by
raesene4
11y ago
Interestingly that's not the cases everywhere in the UK. for example Dumfries and Galloway saw a 10% drop in property prices last year...
11.
▲
by
raesene4
11y ago
Whilst other areas are expensive London it totally in a league of it's own. Edinburgh (most expensive part of scotland) average property price £234k. London, average property price £642k Also people in Scotland and areas like Manchest
12.
▲
by
raesene4
11y ago
have you tried using something like https://gethttpsforfree.com/ as a front-end to the Lets encrypt process?
13.
▲
by
raesene4
11y ago
well whilst hardware tokens are not always the right answer, there are good reasons to resist their replacement with things like "SMS 2FA" which isn't really 2FA at all ,as you have no control over the receiving device, leadi
14.
▲
by
raesene4
11y ago
FWIW, I saw that ad. Looks very interesting, but I think you may have a challenge getting someone who is a Vuln researcher/pen tester type (who most commonly have CVEs, PoCs to their name) who also has a decent knowledge of banking se
15.
▲
by
raesene4
11y ago
Yep the customer fraud guarantee is a thing in the UK as well (at the moment), and to an extent that minimizes the loss where it's one customer's app. that gets compromised. Where I was thinking that a lot of their security challe
16.
▲
by
raesene4
11y ago
I wonder why you got downvoted for this, for me security is a key concern for the challenger banks. What Mondo is (from my reading) trying to do is very cool but quite ambitious. A new bank in 2016 will be a serious target for quite sophis
17.
▲
by
raesene4
11y ago
you are kidding right? the commands needed are right there on the docker hub page https://hub.docker.com/_/postgres/
18.
▲
by
raesene4
11y ago
any particular reasons you don't trust Docker security?
19.
▲
by
raesene4
11y ago
Your comment relates more, I think, to the general Docker project than subuser specifically. The answer to your question is that it all depends on your definition of "easier". docker/docker hub hide a lot of complexity in lin
20.
▲
by
raesene4
11y ago
FWIW I think this is pretty cool. The main docker use-case is not desktop software, and some of it's choices are unlikely to suit that use-case well. So, good to see a project look at that aspect. I would quite like to be able to run
21.
▲
by
raesene4
11y ago
That's essentially what Docker hub already is. you can do docker pull postgres and get a postgres service which runs in a container.
22.
▲
by
raesene4
11y ago
You may be thinking of the lack of user namespacing in Docker. Until v1.10 root in a container was the same user as root outside the container. This did not automatically lead to allow a contained user to breakout, but made it easier. In 1
23.
▲
by
raesene4
11y ago
yeah it's super useful, nice interface and all the docs are hosted on S3 which is interesting...
24.
▲
by
raesene4
11y ago
there are two excerpts from their financial accounts in there if that makes you any happier (and justifies my use of the plural :) one from the P&L and one from the staffing section The article is working on what's publicly availab
25.
▲
by
raesene4
11y ago
from http://www.musicbusinessworldwide.com/ouch-soundcloud-losses... definitely not profitable at the time of those accounts
26.
▲
by
raesene4
11y ago
I'm not sure I'd agree there's no other facts. links from the article include excerpts from their financial accounts which don't look good (losing 39M on a 17M turnover is not healthy). And the quote from the auditor is
27.
▲
by
raesene4
11y ago
that chimes with my experience. I've got a MotoG 3rd Gen which has a pretty good battery life. I installed Instagram and it was draining much faster and looking at the battery information it had drained about 20-30% of the charge and
28.
▲
by
raesene4
11y ago
Surely the decision about what response to make lay with the government (the receiver of the letter) and not Prince Charles (the sender of the letter)? i.e. They had the choice not to respond or to have a aide respond, but the prime ministe
29.
▲
by
raesene4
11y ago
Errr, if the government don't like anyone's opinions, they are entitled to ignore them, but in general I'd say that people are entitled to express their opinions as Prince Charles did. In terms of "tolerated" the on
30.
▲
by
raesene4
11y ago
A very interesting post. To me this illustrates a couple of points very well. 1) VMWare likely have no idea what they lost when they cut this team. Once teams just look like just a number of people to be re-located to save costs, there te
More ›