We love our quirky, slow 1993 Mitsubishi JB500 campervan (https://www.instagram.com/finnthejb500/), but the experience is not for everyone. We were able to register it in Washington without too much hassle. It definitely pays to do some research and try to find a local-ish mechanic willing to work on them before you make the purchase.
HN user
chair6
She'll be right, mate.
Projects:
Is your site IPv6 ready? -- https://ready.chair6.net
Personal blog -- https://chair6.net
Social:
https://twitter.com/finnigja
https://www.strava.com/athletes/finnigja
Notes, photos, and maps from a few days exploring around and over Mount Ngauruhoe, Tongariro, and Ruapehu.
Nope, not missing something.. it has been a problem for GitHub (https://news.ycombinator.com/item?id=30348980) and others (https://portswigger.net/daily-swig/urlscan-io-api-unwittingl...).
https://chair6.net - occasional blog posts on various topics, powered by Pelican on an ARP Networks VPS
Mmm, Kenji's really good scrambled eggs are really good (and really quick) .. https://youtube.com/watch?v=CXTnq7srJRs.
Check out SafeStack, https://academy.safestack.io/safestack-courses/security-awar... .. they're one of the less-cringey, more-modern awareness options I've seen recently.
Just replace console.table with JSON.stringify for the quick-and-easy dump of exactly the same data as is in the table...
JSON.stringify([...document.querySelectorAll('.fatitem table .athing')].map(el => [el.textContent.trim(), el.nextSibling.textContent.trim()]).sort(([,a], [,b]) => parseInt(b) - parseInt(a)))
For a different angle on cloud infrastructure visualization, check out Abridge (https://abridge.io). I'd love to get any feedback on the idea / site and even a trial, if you're interested!
Abridge collects data across your configured set of AWS accounts & regions. It doesn't draw architecture diagrams, but instead will give you x-vs-y visualizations for a number of different relationships .. IAM users vs. groups, Lambda functions vs. runtimes, EC2 instances vs. keypair, etc.
It'll also provide inventory tables / CSV dumps of the different resource types, and simple free search across all resources.
Security-wise, Abridge collects data via cross-account trusts with the SecurityAudit role, and expires all collected data after 48 hours - more at https://abridge.io/security/.
Haha, you're predicting the .. now. GitHub Advanced Security brings in code scanning (CodeQL), secret scanning, and more.
https://github.blog/changelog/2020-05-06-github-advanced-sec...
Have spent some time with the beta, definitely worth a look.
waves, original Bandit author here. It could've done more, but pretty cool to see how useful it's been and where it's got to.. OSS is fun.
Physical products are so very different to virtual. Life is relatively easy when you can just ctrl-z, quit-without-saving, git checkout --, or redeploy. A friend has been working on this idea for the last couple of years.. it's been interesting watching him work through the process.
The game is pretty fun too!
Thanks! It's nice to get that feedback.
It's proactive, but I've been working in various security-oriented IT roles for ~15 years now, and I'm trying to take my own advice [1], so I'd hope I can do it justice. :)
[1] https://chair6.net/startups-and-security-questionnaires.html
I've been building and using https://abridge.io/ for a while now, and it's getting to the point where it is hopefully useful to others. It essentially aggregates information about AWS deployments across multiple accounts and regions into a single visualization / inventory / search interface.
Security is of course a concern - I address that in more detail at https://abridge.io/security/ but the two main parts - 1) collect data from AWS accounts via read-only cross-role access (AWS-managed SecurityAudit policy) and 2) throw all that data away every 48 hours (S3 object expiration).
It still has rough edges, but I'd greatly appreciate a) any feedback on site/content and b) signups from folks who might be interested in testing it out...
HashiCorp | Product Security Engineer | US / UK / Canada / Netherlands / Germany | FULL-TIME | REMOTE
We are looking for Product Security Engineers to help scale our product security function, which works closely with engineering & product management to ensure that security is appropriately addressed across the HashiCorp product suite.
In this role, your responsibilities will include:
* Plan & execute security assessments (dynamic testing, static testing, code review, etc) and threat modeling of HashiCorp’s products, services, and associated cloud infrastructure.
* Build and implement security solutions across the product life-cycle, such as standalone security tools, CI/CD pipeline integrations, product security features/fixes, etc.
* Monitor threats and vulnerabilities impacting HashiCorp products and services, develop proof-of-concepts as appropriate, identify mitigations and assess/communicate associated risk.
We are looking for talented self-starters with 4+ years of security experience. We will consider experienced engineers with less security-specific experience but the desire to learn!
More information and application at https://www.hashicorp.com/jobs/1664419.
Suggestion - one-click navigation from one setup to the next would be nice, instead of having to click back, reload the list, and choose another...
For more insight re. Stripe, https://fs.blog/2018/05/patrick-collison/ was an excellent Knowledge Project episode talking to CEO & co-founder Patrick Collison.
I started skiing as a kid, switched to snowboarding as a teenager, then started skiing again now in my mid-30s. Picking up skiing again after ~20 years was a lot of fun; nice to feel like I'm learning something new again but still know how snow feels and mountains work.
From my own experience, and watching a number of other friends, the first 2-3 days of skiing is easier than the first 2-3 days of snowboarding.
These days I'll happily ski/board most places on most mountains (in-resort, at least) but if I'm getting into technical terrain will vastly prefer a snowboard.. much quicker recovery time if you fall, often you can just bounce back up w/out fully stopping. I'd argue that snowboards are more fun in the pow as well.. skis are great for the hard-and-fast groomer days!
If you're a nerd, and you like skiing / boarding, then check out ski touring / splitboarding. Add backcountry travel, navigation, skin track setting, & most importantly avalanche / snow safety, and you've got a sport that is almost endless in terms of things to learn & keep in mind while you're out and about. And it's excellent exercise while you're at it!
Yes! Last Week In AWS and Python Weekly are the only two weekly email newsletters I've found to be worth reading in their entirety every issue...
Yeah, don't use the web UI. An alternative to awslogs is saw, https://github.com/TylerBrock/saw. Me likey..
Just make sure you time it right. The problem with EFX was they announced on September 7, dipped, then announced additional badness on September 13, so double-dipped (https://s.yimg.com/uc/fin/chart/18/08/39d3a24.png) and you were out ~30% immediately.
The dude is a freakin' machine. There's a short film (13 mins) called 'Kilian' at https://www.youtube.com/watch?v=7eVBrMcflDE which made it into the Banff Film Festival last year. Worth a watch if you want get a better feel for how he travels and his thought process. Food for twenty hours in the mountains? Oh, I'll probably take 4 Snickers or something...
Speaking of challenges to a point of view:
Plenty of passengers ride the bus, but the bus is not redefined by this.
Smell, sickness, graffiti, background noise, and even the occasional pleasant conversation.. all things passengers bring to the bus that may not actually redefine it but do potentially have lasting impact on the bus itself and shape the experience for all parties involved.
Interesting philosophical questions on how oneself views oneself, especially if you go back to the source paper at http://journals.plos.org/plosbiology/article?id=10.1371/jour... rather than the linked extract. “[W]e have never been individuals...”
Microbiome is one of the things we're including in the Arivale program. Early days on the research front, but fascinating stuff - our clinical team have written up two less philosophical, more scientific articles re. correlations of microbiome to health at https://www.arivale.com/gut-microbiome-tmao-heart-heath/ and https://www.arivale.com/gut-microbiome-crohns/.
Used to have serious wrist/arm pain. Used to spend a lot of keyboard time, but also used to exercise a lot.
Anecdotal, but what worked for me was stopping walking around with my hands in my pockets. Seriously! Must've been something to do with body tension - once I figured out that letting my arms swing freely when I walked places, instead of keeping them rigidly in my pockets, the pain went away and hasn't come back.
Her category 'lost in transit' is perhaps the biggest cause of UDP drops. No matter how big your buffers on the send/receive side, if an intermediary carrier decides UDP is not important or a D/DoS threat to their network, bye bye packet... or in some cases of rate-limiting, see you in a while perhaps.
A few rabbit-holes to dive down:
https://www.us-cert.gov/ncas/alerts/TA14-017A
http://www.christian-rossow.de/articles/Amplification_DDoS.p...
https://tools.ietf.org/id/draft-byrne-opsec-udp-advisory-00....
With Gerrit you can chain up a series of dependent changes. The OpenStack Developer's Guide summarizes the workflow pretty well - http://docs.openstack.org/infra/manual/developers.html#addin....
The OpenStack community uses Gerrit pretty widely across our various projects. It might help to check out a busy project like Nova (https://review.openstack.org/#/q/project:openstack/nova,n,z) to get a feel for how Gerrit works in practice. Or a less-busy project like Bandit, which I'm involved in (https://review.openstack.org/#/q/project:openstack/bandit,n,...).
I've been doing some experimentation with Varnish Cache and wanted the ability see/modify/compare HTTP & HTTPS requests pre- and post-cache. Turned into a Vagrant environment and set of scripts that might be helpful to others with similar use cases...
Funny how a simple "what if AD user management looked different" discussion can lead fairly quickly to 700 lines of Powershell that makes ten people's jobs somewhat easier.
I can't exactly say I'm proud of this, but I was somewhat surprised by how relatively easy it was to pull a basic GUI together...
Yep, from the changelog - "Version 0.2 (2006-12-13)". I've been using this during pentest gigs and the like since it was first released on SourceForge.
Cool to see tools lasting / improving, but depressing that SQLi is still so pervasive...
Check out http://blockdiag.com/ and siblings (seqdiag, actdiag, nwdiag).
They have an interactive shell for it - experiment with http://interactive.blockdiag.com/nwdiag/.