Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sullivanmatt
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
1.
▲
by
sullivanmatt
7d ago
Completely agree. My wife and I absolutely loved it. Tons of fun, and unexpectedly quite intelligent.
2.
▲
How we secure Figma's internal systems with agents
(figma.com)
4 points
by
sullivanmatt
2mo ago
|
0 comments
3.
▲
by
sullivanmatt
8mo ago
It's perfectly possible it's someone with deep domain experience, or someone who has product design or management skills. Regardless, dismissing these people out of pocket is not likely the best choice.
4.
▲
by
sullivanmatt
1y ago
I'm no longer living in Oregon but remain closely connected. I can't opine to the behavioral challenges, but in terms of the raw score drop I think there's also the one-two punch here of: 1) Schools were closed from Covid for
5.
▲
by
sullivanmatt
2y ago
You can tell when this deal started to come together by looking at the history of the website on Wayback Machine. In fall of 2024, the website had a checklist comparing SDF to dbt and claiming SDF had a better feature set than dbt Core (pag
6.
▲
by
sullivanmatt
3y ago
My first employer is now a decently well known B2B SaaS and we didn't build user interfaces to manage various settings for a very long time. For example, we supported custom fonts, but we would have to jack into production to upload th
7.
▲
by
sullivanmatt
3y ago
In all of these advisories there has never once been a mention of cloud being vulnerable. I think it's safe to assume cloud runs a similar, if not identical, codebase, and that these issues are simply patched there first before vulnera
8.
▲
by
sullivanmatt
3y ago
There must be a specific set of libs present on the victim (client), correct. Qualys claims that stock Ubuntu Desktop systems often have these libs, and that they haven't looked into whether other distros tend to. But yes, your point s
9.
▲
by
sullivanmatt
3y ago
This sounds way worse than it is. To be clear, the "remote" part of the code execution is that an attacker controlling your destination server can cause your client to run an attacker-controlled payload, if the client is forwa
10.
▲
by
sullivanmatt
3y ago
If I were a user or integrator, how do I know that the de-identification step is actually working? Is there a way to test (and/or continue testing) your regex patterns or whatever mechanism used continues to accurately strip my sensiti
11.
▲
by
sullivanmatt
3y ago
I'm not even a user of rhel but the difference is: security patches. Enterprise uses rhel because they fix or triage nearly every vuln, every time. If you work for a company with extremely stringent security requirements, or sell to go
12.
▲
by
sullivanmatt
3y ago
I would recommend reading both Inspired and Empowered by Marty Cagan to help you think about your product journey. Very relevant to what you'll be building, and personally I found Empowered challenged me in ways that both made me uncom
13.
▲
by
sullivanmatt
3y ago
I built this with AWS Lambda. Relevant info if someone else wanted to try my approach to build such a service: https://mattslifebytes.com/2023/04/14/from-rebuilds-to-reloa...
14.
▲
by
sullivanmatt
3y ago
My day job is security engineering, and I just keep encountering the same problem over and over again: the code is the easy part, it's all the other shit that sucks. I don't want to write a bunch of terraform, set up a CI pipeline
15.
▲
by
sullivanmatt
3y ago
I'm working on a product right now that targets this exact use case. I have contact information in my profile, I would love if you would be willing to reach out and just talk to me about your use cases. I already have a day job at a te
16.
▲
From rebuilds to reloads: hacking AWS Lambda to enable instant code updates
(mattslifebytes.com)
1 points
by
sullivanmatt
3y ago
|
0 comments
17.
▲
by
sullivanmatt
4y ago
If they had built this so they handled the SaaS part, but could persist the data in your organization's own AWS / GCP / Azure blob storage, would that be enough to get the solution past the line for acceptance? I'm in se
18.
▲
The missing piece: the need for product management in security teams
(mattslifebytes.com)
1 points
by
sullivanmatt
4y ago
|
1 comments
19.
▲
(removed)
(mattslifebytes.com)
1 points
by
sullivanmatt
4y ago
|
0 comments
20.
▲
(removed)
(mattslifebytes.com)
1 points
by
sullivanmatt
4y ago
|
0 comments
21.
▲
by
sullivanmatt
4y ago
Wowsa. Somebody didn't do their job right if it took anywhere near that amount of time to get logs back. Sorry it was so painful.
22.
▲
by
sullivanmatt
4y ago
For sure. Pull a dbt and get everybody hooked on your tool, then slap a SaaS platform ecosystem to the farthest right and watch the revenue flow.
23.
▲
by
sullivanmatt
4y ago
This issue exists to the right of your solution and is (for now) out of scope, but the biggest issue I have with security data lakes is the need to (easily) get both row-based data and visualizations. Back when I had access to a well-built
24.
▲
by
sullivanmatt
4y ago
None of it was news. As we learned during the Trump era, just because a narcissist claims that unjust things are happening doesn't make it true. I, for one, am glad that Twitter suppressed links to and media of Hunter Biden stolen and
25.
▲
by
sullivanmatt
4y ago
Don't confuse a trademark with a patent. Even if Google uses "go links" internally, the fact remains that the trademark is registered and in use by another entity.
26.
▲
by
sullivanmatt
4y ago
A trademark is not a patent, you don't need to prove you were first to have "the idea". [IANAL] It's the first to use the term in a commercial context, which Google has not.
27.
▲
by
sullivanmatt
4y ago
Typing go/wiki is faster than typing "wiki" in my search bar and hitting the down arrow 5 times for the correct autocomplete answer. I found the bigger (unexpected) value of something like this to be that when I don't kn
28.
▲
by
sullivanmatt
4y ago
The name is going to be quickly problematic if the trademark holder for golinks.io decides to get litigious: https://trademarks.justia.com/owners/zamora-jorge-3828689/
29.
▲
by
sullivanmatt
4y ago
Ubuntu 22.04 & RHEL 9 are the major distros impacted. Docker images built on ubuntu:latest will also be impacted. The latest releases of Alpine/Debian/AL2 are all not impacted, they use 1.1.x lineage.
30.
▲
by
sullivanmatt
4y ago
The email address listed in the blog post, securitykeys@cloudflare.com, appears to not be a valid mailbox.
More ›