HN user

bdesimone

271 karma

Always happy to hear from folks bdd @ ${pomerium's website domain as you'd expect}

Posts6
Comments84
View on HN

Posting a coworker’s deep dive on the nuance of health checks that actually represent readiness. If you’ve had pods say "ready" while still failing traffic during rollouts, this will resonate.

Happy to answer any questions about the finer points of readiness checks in Pomerium, Envoy, and in general for systems running in systems like k8s, systemd, and so on.

FWIW, I'm very happy to see this announcement. Full MCP support was the only thing holding me back from using GPT5 as my daily driver as it has been my "go to" for hard problems and development since it was released.

Calling out ChatGPT specifically here feels a bit unfair. The real story is "full MCP client access," and others have shipped that already.

I’m glad MCP is becoming the common standard, but its current security posture leans heavily on two hard things:

(1) agent/UI‑level controls (which are brittle for all the reasons you've written about, wonderfully I might add), and

(2) perfectly tuned OAuth scopes across a fleet of MCP servers. Scopes are static and coarse by nature; prompts and context are dynamic. That mismatch is where trouble creeps in.

Genuinely, didn't take it that way at all! I don't expect you to be an expert on Pomerium.

Funnily enough, Octelium started as a sidecar ext_authz svc for Envoy instances to operate as an IaP but I ended up creating my own Golang-based IaP, Vigil, from scratch because Envoy was just nothing but pain outside HTTP-based resources.

That's really funny... we went the opposite direction as the original versions were based on a custom Go proxy. Of course there are tradeoffs either way. Envoy is blazing fast, and does great with HTTP naturally, but has a giant configuration surface area (both pro and con), but we are now having to write some pretty low level filters /protocol capabilities in envoy for the other protocols we support (SSH, MCP, and so on) in C++ which does not spark joy. So I totally feel what you are saying.

Thanks for the kind words, though I am one of the contributors my colleague did the heavy lifting on the WebAuthN side.

Genuinely happy to see the release and where you are headed on the AI/MCP side. If you (or others) are interested, I am trying to bring more light to this model in the spec if you (or others) would like to weigh in: https://github.com/modelcontextprotocol/modelcontextprotocol...

Quick note since it was mentioned. Pomerium does support Kubernetes at pretty much every level you mentioned (although I'm not entirely sure what a "a complete Kubernetes-tier platform" means) including:

- "remote access" : https://www.pomerium.com/docs/capabilities/kubernetes-access

- "access control" https://www.pomerium.com/docs/capabilities/authorization

- "visibility and auditing" : https://www.pomerium.com/docs/capabilities/audit-logs

- "user and identtiy management" https://www.pomerium.com/docs/capabilities/authentication to which I'd add device identity as well.

- "centralized policy management": https://www.pomerium.com/docs/capabilities/authorization & https://www.pomerium.com/docs/internals/ppl

- deployments using Ingress Controller or GatewayAPI https://www.pomerium.com/docs/deploy/k8s/ingress, https://www.pomerium.com/docs/deploy/k8s/gateway-api

- "for an arbitrary number of resources" not sure what to link to but there's no limit here

Congrats on the release. I saw your thread on MCP and completely agree with the approach. Happy to trade notes :)

I agree that both can be used safely. And, yes to be clear, NMR here means "less likely to happen" not "better able to handle failure." Unfortunately, AES-GCM-SIV (or AEZ) aren't yet in Go's standard lib.

But, why not use XChaCha20-Poly1305 over AES-GCM in Go? Both are "implemented through the crypto/aead" and -- to my eyes -- seem equally user-proof. Why not take the bigger nonce size?

I see where this is coming and agree in spirit, but GCM is actually idiomatic Go and implemented through the crypto/aead interface, which does about as good a job as any library at being user-proof.

Good point, and I appreciate the (updated) Kubernetes docs do a pretty good job of telling you what the implications of using aesgcm vs secretbox are.

However, I was surprised that XChaCha20-Poly1305 wasn't recommended. XChaCha appears to check all the boxes you mentioned and is nonce-misuse resistant.

Passports for sale 12 years ago

Citizenship is already weird. My wife and I both being born in the US, we are tri-citizens and our descendants will also have tri-citizenship in perpetuity.

It would have been quad-citizenship if Norway allowed for multiple passports.

In the very same doc you quote, they also say of iMessage:

"Apple does not log messages or attachments, and their contents are protected by end-to-end encryption so no one but the sender and receiver can access them. Apple cannot decrypt the data."

Which has been refuted several times.

Go In Action 12 years ago

I am happy to vouch for William who has been driving the Miami meet ups. He knows his Go and is able to deconstruct rather tricky subjects and present them in a way that's easy to understand. You should check out his blog to see what I mean. Better yet, if you are in Miami, come to the meet-up.

It's less complicated than what I'm reading here.

* Use a passphrase of at least five random words.[1]

* Keep that passphrases secret.[2]

* Use a password manager like 1Password or Keepass to generate and manage all other passwords.[3]

[1]: Good passwords have high entropy and are easy to remember. For that reason, passphrases are preferred to passwords.

[2]: It's ok to write down your passphrase, but keep it somewhere safe -- like your wallet.

[3]: Password managers prevent password reuse and make life easier. Sync passwords across devices.

for more: http://bdd.io/security , with linked justifications.

What are you talking about?

My #3 point was not that dietary health isn't important. It IS important. It's as important as cardiology, renal, etc in the curriculum. That it's "only" one week is shouldn't be taken (and is repeatedly put forth as, as the OP did) proof of how physicians don't care/ aren't trained in diet.

What does your rant about saying the hippocratic oath have to do with anything? What does that have to do with the amount of emphasis the modern medical education puts on health through diet? Of course food should be your medicine. Natural plants are also the base for some ~70% of our drugs. It's just not the only tool in the toolbox.

Then you accidentally support my earlier point that the average joe is godawful self-treating/diagnosing based on their own research. Thanks.

EB as a term is new, the specialization is not.

Most here are engineers with a BS/BA. Maybe a MA. And fewer still with a PhD. Not that education is everything, but it's certainly "years specializing."

Compare that to the track of a typical specialist md:

After your undergrad degree you've got.... 4 years in med school. 4-6 years in residency. Plus a 1-3 year fellowship.

Long story short, what's the credible alternative to relying on multiple expert opinions? Are educated (engineers/lawyers/etc) ordering tests based on research they really don't understand on themselves a better? By what evidence?

It's sound if you assume both aren't part of the job description. Change the occupation in the poorly constructed analogy and we have...

Suppose a pilot has a choice of two activities:

1. Read FAA safety report, unpaid 2. Fly plane, paid

Doctors, especially at academic institutions, are required not only to be up to date in the latest research, but contribute to it. If a doctor treats a patient in a way not up to par with current practices in research, he will be sued and lose his licensure.

Why would your doctor read the latest research on preventing disease when he can make a tidy profit from treating your disease?

Woah woah woah there. Are you really saying doctors don't read the latest research so that they can make a greater profit? Really?

You could have at least picked a more realistic example of misaligned incentives in medicine... e.g. using a more expensive drill bit during a surgery because you know that the surgical rep will take you out to a nice dinner every time he's in town.

There's a huge population of doctors. Some ethical. Some unethical. But I believe the profession does a pretty admirable job of stamping out immoral behavior when it finds it.

1. Doctors are people like any other. But they've spent years specializing in evidence based medicine. They aren't perfect. No. But they are the best we have.

2. The far bigger problem is doctors order tests that wouldn't change treatment but rather help avoid malpractice.

3. The quote -- every time I read it -- makes me laugh because it's so disingenuous. My wife had a week of dietary training in med school. You know what else she had a week of? Renal. Cardiology. etc. If you think diet and exercise are the only--or even the most effective--means of lowering morbidity for chd (which is what OP is worried about) you'd also be wrong. So I'm not really sure why OP should be looking for a dietary specialist vs a cardiologist.

Am I missing other major downsides to taking a more proactive approach to managing my own health? Are there other things I should consider looking at to get a complete picture of my health?

A potential downside is the tendency is to shift from being proactive about your health to diagnosing (or worse -- treating) yourself based on independent research. I get that it's tempting to fire up google scholar, pubmed, uptodate etc to get a better understanding of what's going on -- just don't go the next step and start diagnosing and treating yourself.

See a specialist. See a domain specialist if you can. Get another opinion. Ask questions and air your concerns. If your doctor doesn't adequately answer your questions and concerns, see another doctor. Your greatest asset -- and the one you should be focused on-- is the ability to get multiple opinions from people who have trained for decades on a topic.

It seems like you need to see a new doctor -- not order your own tests.

I didn't know about either places. Thanks! As for Downtown being a ghost town... that's probably exactly the wrong way to describe it! I just mean that many of the restaurants, and stores that cater to the work day crowd close up.

FWIW, I'm happy in Miami and glad I'm here. I just wanted to air some of the warts I wish I knew about before coming.