These “baseline rules” come from NIST SP 800-63B, Appendix A, which is a surprisingly digestible document: https://pages.nist.gov/800-63-3/sp800-63b.html#appA
HN user
Artemis2
Founder of ProcessOut (https://processout.com).
l@processout.com
Xerox PARC!
You’d still have to handle the complete flow for the case where the exemption has been used multiple times since the last authentication though.
Very serious handling of the issue!
CockroachDB is made up of several layers to implement SQL and transactions on top of a distributed key-value store: https://www.cockroachlabs.com/docs/stable/architecture/overv...
TiDB has a similar architecture: https://www.pingcap.com/docs/architecture/
Unfortunately, with trackers such as the Like button embedded in every web page and shadow profiles, social media is definitely not opt-in.
“Coordinated Inauthentic Behavior” is a nice euphemism!
There is also a series of posts regarding the design of Aurora on the AWS blog, although about everything is described in the original paper:
https://aws.amazon.com/blogs/database/amazon-aurora-under-th...
https://aws.amazon.com/blogs/database/amazon-aurora-under-th...
https://aws.amazon.com/blogs/database/amazon-aurora-under-th...
https://aws.amazon.com/blogs/database/amazon-aurora-under-th...
DynamoDB with strong consistency turned on works pretty nicely for us.
This is powering CloudKit. Very cool!
Most payment gateways offer a card fingerprinting feature. Here’s Stripe’s: https://stripe.com/docs/api/cards/object#card_object-fingerp....
It’s fine with PCI DSS as long as it is not reversible.
The confetti thrown at midnight is made from recycled material that would otherwise be discarded, and all of it is biodegradable.
⌘+F “performance” or “memory” does not show anything :-/
Quorum reads will always be much faster in the same AZ :-(
The global reservation is divided to multiple partitions, each no more than 10TB in size.
I think this should be 10GB partitions.
By the way, maybe it’s worth mentioning adaptive capacity? https://aws.amazon.com/blogs/database/how-amazon-dynamodb-ad...
Caused by a bad BGP route announcement [1]; this is outside of the control of Google. However, they do seem to have global incidents more often than the competition (for example [2] last July)
1: https://status.cloud.google.com/incident/cloud-networking/18...
2: https://status.cloud.google.com/incident/cloud-networking/18...
That’s not it, but I really like Whimsical (https://whimsical.co) to produce great-looking diagrams.
Good addition! Here are some more:
https://peter.bourgon.org/blog
https://engineering.linkedin.com/blog
http://blog.pentestbegins.com (seems down right now?)
http://blog.stephenwolfram.com
I guess I could go on forever…
Some favorites of mine I haven’t seen mentioned:
plus an endless amount of newsletters…
Do you mean OpenShift?
99% Invisible, Planet Money are good.
I learned a new word today!
I cannot overstate how much I despise these “helpful” cloud agents. They are useful for experimentation to update user accounts (SSH keys, etc. — GCP uses for its web shell as well), but they are a nightmare for production use. They are a very straightforward path from cloud account compromise to instance takeover.
Azure pulls the same trick. AWS seems fine.
Thanks for the detailed reply! There is indeed a lot to do with authentication/authorization (and things like audit logging…). I’ll look more at EnvKey later to understand the cryptography better.
Stripe/other gateways do abstract most of PCI DSS from you, and will not return card data via API calls, so that somewhat sidesteps the compliance issue.
Looks cool! I can very much appreciate progress in this space. I haven’t been able to find this info by skimming the website: while I understand that the user ultimately holds the keys that can decrypt the secret, how do you prevent this key from becoming the weakest link? Assuming the worst, users could just store their key where they used to store their secrets before EnvKey (like app environment)?
Something I appreciate very much about running in the cloud is being able to use the control plane’s APIs to authenticate requesters (e.g. Kubernetes API + Service Accounts or AWS IAM + Instance Roles). Does EnvKey have anything in the way of that?
Regarding PCI compliance: if card data is encrypted, the scope of compliance simply moves over to the keys :-)
AFAIK a lot of Google’s HTTPS traffic is also routed using anycast. They also offer this to GCP customers under GCLB (https://cloud.google.com/load-balancing/).
I don’t know how they deal with changes in routes.
Recommended read: https://www.apple.com/business/docs/iOS_Security_Guide.pdf
If you bank in Europe, look up PSD2 :-)
Planet Money as well: https://www.npr.org/templates/transcript/transcript.php?stor...
They don’t seem to ship the actual items but random junk instead (to get a tracking number?).