HN user

chair6

616 karma

She'll be right, mate.

Projects:

Is your site IPv6 ready? -- https://ready.chair6.net

Personal blog -- https://chair6.net

Social:

https://twitter.com/finnigja

https://www.strava.com/athletes/finnigja

Posts27
Comments70
View on HN
chair6.net 3y ago

Mangatepopo to Waihohonu to Whangaehu to Iwikau

chair6
1pts1
chair6.net 4y ago

Terraform configs, Semgrep's autofix, and an example of OSS contribution

chair6
2pts0
chair6.net 5y ago

Simulated phishing is not so great

chair6
2pts0
juggleslam.com 6y ago

Show HN: JuggleSlam

chair6
1pts1
abridge.io 6y ago

Show HN: Abridge – Cloud Visibility

chair6
2pts4
www.nejm.org 6y ago

First Case of 2019 Novel Coronavirus in the United States

chair6
1pts0
publicity-stunt.tuple.app 6y ago

We're Giving Away an Apple Pro Display XDR ...Stand

chair6
2pts1
www.hashicorp.com 6y ago

Announcing Terraform Cloud

chair6
8pts1
chair6.net 7y ago

Security, CI/CD, and Continuous Assurance

chair6
1pts0
github.com 7y ago

Show HN: Python/boto3 script to rotate|reboot EC2 instances in an ECS cluster

chair6
1pts0
chair6.net 7y ago

Post-build DOM manipulation with pyquery

chair6
1pts0
chair6.net 7y ago

Show HN: Generating weekly O365-hosted mailbox statistics

chair6
2pts0
www.youtube.com 7y ago

Every TED talk ever [video]

chair6
1pts4
oversight.house.gov 7y ago

House Oversight Committee Report on Equifax Breach [pdf]

chair6
238pts139
chair6.net 7y ago

Productivity inside 13 inches

chair6
1pts0
github.com 8y ago

Requests-HTML: HTML Parsing for Humans

chair6
1pts0
www.ppig.org 9y ago

The Subtle Effect of Hidden Dependencies on the UX of Version Control [pdf]

chair6
1pts0
www.arivale.com 9y ago

How Do Hundreds of Your Genetic Variants Impact Your Heart Health?

chair6
1pts0
github.com 10y ago

Show HN: Wrapping Varnish Cache with mitmproxy

chair6
4pts3
github.com 10y ago

Show HN: Madness, a Powershell GUI for Managment of Active Directory Accounts

chair6
9pts3
wiki.openstack.org 11y ago

Introducing Bandit, a Python code security analyzer

chair6
2pts1
www.kickstarter.com 12y ago

COVR Photo* – An iPhone Case with a Built In Prism Lens

chair6
1pts3
breachnotifications.spreadshirt.com 12y ago

Breach Notifications

chair6
1pts0
github.com 13y ago

Hiccup - a Python extension framework for Burp Suite

chair6
1pts1
www.npr.org 14y ago

Duck Duck Go gets a mention on NPR

chair6
2pts0
poetryofworldwarone.tumblr.com 14y ago

Show HN: My simple project for Remembrance Day

chair6
12pts2
ready.chair6.net 15y ago

Is your site IPv6 ready?

chair6
2pts2

Just replace console.table with JSON.stringify for the quick-and-easy dump of exactly the same data as is in the table...

JSON.stringify([...document.querySelectorAll('.fatitem table .athing')].map(el => [el.textContent.trim(), el.nextSibling.textContent.trim()]).sort(([,a], [,b]) => parseInt(b) - parseInt(a)))

For a different angle on cloud infrastructure visualization, check out Abridge (https://abridge.io). I'd love to get any feedback on the idea / site and even a trial, if you're interested!

Abridge collects data across your configured set of AWS accounts & regions. It doesn't draw architecture diagrams, but instead will give you x-vs-y visualizations for a number of different relationships .. IAM users vs. groups, Lambda functions vs. runtimes, EC2 instances vs. keypair, etc.

It'll also provide inventory tables / CSV dumps of the different resource types, and simple free search across all resources.

Security-wise, Abridge collects data via cross-account trusts with the SecurityAudit role, and expires all collected data after 48 hours - more at https://abridge.io/security/.

waves, original Bandit author here. It could've done more, but pretty cool to see how useful it's been and where it's got to.. OSS is fun.

Physical products are so very different to virtual. Life is relatively easy when you can just ctrl-z, quit-without-saving, git checkout --, or redeploy. A friend has been working on this idea for the last couple of years.. it's been interesting watching him work through the process.

The game is pretty fun too!

I've been building and using https://abridge.io/ for a while now, and it's getting to the point where it is hopefully useful to others. It essentially aggregates information about AWS deployments across multiple accounts and regions into a single visualization / inventory / search interface.

Security is of course a concern - I address that in more detail at https://abridge.io/security/ but the two main parts - 1) collect data from AWS accounts via read-only cross-role access (AWS-managed SecurityAudit policy) and 2) throw all that data away every 48 hours (S3 object expiration).

It still has rough edges, but I'd greatly appreciate a) any feedback on site/content and b) signups from folks who might be interested in testing it out...

HashiCorp | Product Security Engineer | US / UK / Canada / Netherlands / Germany | FULL-TIME | REMOTE

We are looking for Product Security Engineers to help scale our product security function, which works closely with engineering & product management to ensure that security is appropriately addressed across the HashiCorp product suite.

In this role, your responsibilities will include:

* Plan & execute security assessments (dynamic testing, static testing, code review, etc) and threat modeling of HashiCorp’s products, services, and associated cloud infrastructure.

* Build and implement security solutions across the product life-cycle, such as standalone security tools, CI/CD pipeline integrations, product security features/fixes, etc.

* Monitor threats and vulnerabilities impacting HashiCorp products and services, develop proof-of-concepts as appropriate, identify mitigations and assess/communicate associated risk.

We are looking for talented self-starters with 4+ years of security experience. We will consider experienced engineers with less security-specific experience but the desire to learn!

More information and application at https://www.hashicorp.com/jobs/1664419.

I started skiing as a kid, switched to snowboarding as a teenager, then started skiing again now in my mid-30s. Picking up skiing again after ~20 years was a lot of fun; nice to feel like I'm learning something new again but still know how snow feels and mountains work.

From my own experience, and watching a number of other friends, the first 2-3 days of skiing is easier than the first 2-3 days of snowboarding.

These days I'll happily ski/board most places on most mountains (in-resort, at least) but if I'm getting into technical terrain will vastly prefer a snowboard.. much quicker recovery time if you fall, often you can just bounce back up w/out fully stopping. I'd argue that snowboards are more fun in the pow as well.. skis are great for the hard-and-fast groomer days!

If you're a nerd, and you like skiing / boarding, then check out ski touring / splitboarding. Add backcountry travel, navigation, skin track setting, & most importantly avalanche / snow safety, and you've got a sport that is almost endless in terms of things to learn & keep in mind while you're out and about. And it's excellent exercise while you're at it!

Speaking of challenges to a point of view:

Plenty of passengers ride the bus, but the bus is not redefined by this.

Smell, sickness, graffiti, background noise, and even the occasional pleasant conversation.. all things passengers bring to the bus that may not actually redefine it but do potentially have lasting impact on the bus itself and shape the experience for all parties involved.

Interesting philosophical questions on how oneself views oneself, especially if you go back to the source paper at http://journals.plos.org/plosbiology/article?id=10.1371/jour... rather than the linked extract. “[W]e have never been individuals...”

Microbiome is one of the things we're including in the Arivale program. Early days on the research front, but fascinating stuff - our clinical team have written up two less philosophical, more scientific articles re. correlations of microbiome to health at https://www.arivale.com/gut-microbiome-tmao-heart-heath/ and https://www.arivale.com/gut-microbiome-crohns/.

Used to have serious wrist/arm pain. Used to spend a lot of keyboard time, but also used to exercise a lot.

Anecdotal, but what worked for me was stopping walking around with my hands in my pockets. Seriously! Must've been something to do with body tension - once I figured out that letting my arms swing freely when I walked places, instead of keeping them rigidly in my pockets, the pain went away and hasn't come back.

Her category 'lost in transit' is perhaps the biggest cause of UDP drops. No matter how big your buffers on the send/receive side, if an intermediary carrier decides UDP is not important or a D/DoS threat to their network, bye bye packet... or in some cases of rate-limiting, see you in a while perhaps.

A few rabbit-holes to dive down:

https://www.us-cert.gov/ncas/alerts/TA14-017A

http://www.christian-rossow.de/articles/Amplification_DDoS.p...

https://tools.ietf.org/id/draft-byrne-opsec-udp-advisory-00....

https://datatracker.ietf.org/wg/taps/charter/

With Gerrit you can chain up a series of dependent changes. The OpenStack Developer's Guide summarizes the workflow pretty well - http://docs.openstack.org/infra/manual/developers.html#addin....

The OpenStack community uses Gerrit pretty widely across our various projects. It might help to check out a busy project like Nova (https://review.openstack.org/#/q/project:openstack/nova,n,z) to get a feel for how Gerrit works in practice. Or a less-busy project like Bandit, which I'm involved in (https://review.openstack.org/#/q/project:openstack/bandit,n,...).

I've been doing some experimentation with Varnish Cache and wanted the ability see/modify/compare HTTP & HTTPS requests pre- and post-cache. Turned into a Vagrant environment and set of scripts that might be helpful to others with similar use cases...