HN user

Igalze

129 karma

An obsessive gamer, award-winning novelist, and a techie with a loooong track record in IT and cybersecurity.

Posts56
Comments26
View on HN
opentofu.org 2y ago

OpenTofu Release Candidate Is Out, GA Set for Jan 10th

Igalze
4pts1
opentofu.org 2y ago

What We Learned While Working on OpenTofu's New Test Feature

Igalze
2pts0
status.hashicorp.com 2y ago

Terraform Cloud is down for nearly five hours, and counting

Igalze
63pts15
sternumiot.com 3y ago

‘NTP Textbox’ Vulnerability in Zyxel’s NAS326, NAS540, and NAS542 Devices

Igalze
1pts0
arstechnica.com 3y ago

Wemo won’t fix Smart Plug vulnerability allowing remote operation

Igalze
2pts1
sternumiot.com 3y ago

Security Advisory: Buffer Overflow Vulnerability in Wemo Smart Plug V2

Igalze
2pts0
old.reddit.com 4y ago

2022 Predictions: SRE Tools Will Start Speaking the Language of Developers

Igalze
4pts0
komodor.com 4y ago

The Complete Guide for Exit Codes in Containers and Kubernetes

Igalze
1pts0
hackernoon.com 4y ago

Moving from CircleCI to Buildkite: Everything You Need to Know

Igalze
2pts0
komodor.com 5y ago

Komodor Raised $25M to Redefine K8s Troubleshooting

Igalze
2pts0
www.incapsula.com 9y ago

How DDoS can be used to suppress voter turnout

Igalze
1pts0
www.incapsula.com 9y ago

How DDoS can interfere with the US election

Igalze
2pts0
www.incapsula.com 9y ago

Into the Abyss: DDoS Landscape Through a Social Graph

Igalze
2pts0
www.incapsula.com 9y ago

Mirai is programmed to kill other botnets

Igalze
3pts0
www.incapsula.com 9y ago

Traffic generator comparison: TRex vs. Avalanche

Igalze
1pts0
www.incapsula.com 10y ago

Internet traffic drops during Euros

Igalze
1pts0
www.incapsula.com 10y ago

How to keep calm and mitigate a 470 Gbps DDoS attack

Igalze
2pts0
www.incapsula.com 10y ago

Incapsula mitigates a 470Gbps DDoS attack

Igalze
1pts0
www.ddosbootcamp.com 10y ago

Crash course in DDoS mitigation

Igalze
5pts0
www.ddosbootcamp.com 10y ago

Cool quiz site offers in-depth training in DDoS protection

Igalze
1pts0
www.incapsula.com 10y ago

Unmasking DDoS for Hire on Fiverr

Igalze
3pts2
www.incapsula.com 10y ago

Forwarding vs. Throughput Rate. The DDoS Perspective

Igalze
3pts0
www.incapsula.com 10y ago

Understanding High Mpps DDoS Attacks

Igalze
3pts0
www.incapsula.com 10y ago

Can You Handle 300 Mpps? Perps Are Torching Switches with High Mpps Attacks

Igalze
3pts0
www.incapsula.com 10y ago

Freak DDoS attack spells BIG trouble for hybrid

Igalze
2pts0
www.incapsula.com 10y ago

Ginormous POST Flood Spells BIG Trouble for Hybrid DDoS Protection

Igalze
2pts0
www.pcworld.com 10y ago

Massive application-layer attacks could defeat hybrid DDoS protection

Igalze
1pts0
www.breakingnews.ie 10y ago

Here's what happened to web traffic during the first screenings of Star Wars VII

Igalze
1pts0
www.incapsula.com 10y ago

The Internet Falls Asleep as the Force Awakens

Igalze
7pts1
twitter.com 10y ago

Cyberwarrior selfie done right

Igalze
2pts0

Bad idea. I agree with others here saying that this is not enough to change minds at this point (either direction) but I think that SM platforms are in no position to censor news content from a trusted publication. They should focus their efforts elsewhere. All of this feels like a publicity play to help with their current situation, which is yet to be resolved.

I`m curious to see if anyone here actually uses in-door maps, when and how much.

I just don't fell like there is a strong enough use case here, but I couldn't wrong.

Couldn't agree more. One-size-fits-all approach to education, backed by "do as I say or else..." mentality, is outdated. We personalize everything, from cars to ads, we should be making the same effort to create options for kids to maximize their ability to get the most out of the education system.

Sorry but I have to disagree. I have no prior experience with them, but in this case they very extremely responsive and banned the accounts in less than 48 hours.

I wish other companies were as decisive when dealing with "stressers"...

This comment is better than 99% of the media coverage I've seen so far. Who announces a crucial SSL vulnerability that affects Twitter, AWS, Steam, Yahoo and Dropbox without notifying them first? They are making a name for themselves by exposing private information of millions of internet users. Also, I find it interesting that the vulnerability was discovered by Google's researcher and some of their main competitors weren't notified about it.

Your user agent 13 years ago

Love DDG but discovering your UA on SERP like that isn't very useful. If you're someone who needs to know your own UA, you`ll probably need it several times a day or more. Searching for "user agent" is the long way to do it, there are browser extension for that. Still, nice Easter Egg from the best Duck in town.

Very true. As far as headers concerned, we actually dig very deep. For instance, we will look at little encoding-related nuances, which can help identify spoofed headers (ua and IPs are fakeable, after all) :) Also, we look for abnormalities in header order while being aware of variants that can derive from using various devices, proxies, etc. Hence the 10M signature pool, which grows as new variants are spotted across our network.

You raise an excellent point.

We have a lot of application awareness configurations and our signature pool (which is one of the tools we use for traffic profiling) holds over 10M variant, sometime as much as ~20,000 per user-agent type, to cover all scenarios.

Hi, I actually work for Incapsula. For Layer 7 mitigation we use a multi-vector approach which' among other things, consists of:

Client Classification - comparing visitor's user-agent, IP, header parameters and etc to our pool of 10M signatures. Suspects will get CAPTCHA. (~0.01% false positives)

Visitor Reputation - we use crowd-sourcing to compile a list of suspected IPs. The list is updated in real time. Combined with other signals, this data allows us a better understanding of the incoming traffic.

Progressive Challenges - We check visitor's ability to retain cookies, execute JS and so on. In this case, the browser-based bots were able to evade those defenses. (These are also the most commonly used Layer 7 mitigation methods.)

Behavior Monitoring - We look at abnormal access rates, visiting patterns, etc. Here we also look for correctional of signals, to help us pinpoint suspicious behavior.

And so, by collecting and cross-referencing different types of data, the system is designed to distinguish between humans and bots. The process is mostly automated and is always seamless.

This is a very good explanation but there is another side to this issue. (I`m talking about HTTP DDOS)

Basically, DDoS Attacks can be (roughly) divided in 2 categories:

1. Attacks on your server (which usually target your server IP or some other part of your network infrastructure)

2. Attacks on your site (which use bots to flood your site with fake HTTP requests)

As explained above, Network attack can only be countered with strong and flexible infrastructure. The most common solution is a combination of several high-powered servers and load balancing capabilities.

HTTP DDoS attacks are trickier because they're best mitigated by visitor profiling, a technology that can help identify bots from humans and block them while still allowing providing full access to all legitimate visitors. Developing and maintaining such technology is arguably more complicated, simply because it's a software you need to create, not a hardware which you can buy.

Standard profiling solutions include CAPTCHAs and Delay Pages but these will also repel legitimate visitors. (because no one likes CAPTCHAs or waiting for 5-10 extra seconds for page load). Advanced profiling solutions use a combination of behavior and signature recognition, coupled with seamless challenges (i.e. checking for JS support).

CF and Incapsula (where I work) both handle Network DDoS in a similar manner but we have a somewhat different approach to HTTP DDoS.

And yes, while under DDoS (or even without it), dynamic resources can be the "weakest link". This is why WAFs are so important.

CloudFlare was down 13 years ago

This is what Juniper had to say:

“While we have not completed our investigation, we believe this incident was triggered by a product issue that Juniper identified last October, when a patch was also made available"

Good network engineers tend to apply newly release patches. This vulnerability was documented for almost half a year...

Hi, I work for Incapsula. Yesterday we've addressed this study in our blog. http://www.incapsula.com/the-incapsula-blog/item/699-incapsu...

To make a long story short, this detailed report helped us introduce several patches to our WAF - but we feel that some of the issues were mostly theoretical and patching them can lead to security eroding false positives.

ModSecurity is a great security solutionand we are happy to be compared to it. We feel that we perhaps offer a more complete package (bot filtering, acceleration, user friendly GUI and easy setup, support, etc).

Still, you can't beat Free and if you are looking for OS security solution, ModSecurity is defiantly a name you should consider.

On a personal note, I wish that more vendors would take security a bit more seriously - especially if they claim to provide it to thousands of clients.

Web evolution is motivated by consumer trust and if we loose this trust we will also loose the cash flow that keeps Internet evolving.

Providing faulty security will do just that.

This is a marketing spoof.

All CDNs offer DNS level DDOS protection by default. Not because they choose to, but because they have no other option. After all, the same IP ranges are used by all clients and this makes it impossible to pinpoint the original target. (thus no one to blame/bill)

Every CDN does it, but only CF claims it as a "feature".

Robots.txt 13 years ago

Very cool stuff but I have to disagree with the general idea.

I've been doing SEO for 8 years and I have to say that I came for the fun and money but I stayed for the challenge and algo changes.

I remember how, 8 years ago, it was all about "5% density" and link stuffing. Today is content quality, social signals, link profile (not just quantity), contextual co-relations and so much much more...

I think that I only truly fallen in love with SEO when Google started using rel=canonical. This is when it really became a game of poker and not a "hungy hungy hippos" with links in it.

I think you should release the social version first, let it find it's audience and then introduce additional features (like marketplace). I would suggest this even if you had the 2nd part finished. Also, I would inform users, in advance, of the upcoming features. I`m not sure what this app is, but generally speaking "surprising" monetizing related features can create user backlash. Be fair but not apologetic, show the value of your core product and of the upgrades to come.