HN user

fortyfivan

135 karma
Posts27
Comments22
View on HN
www.workinproduct.com 5y ago

Better Product Positioning: Systems over Statements

fortyfivan
2pts0
www.okta.com 6y ago

SSH Is Dead. Long Live SSH: One Million SSH Logins with Okta. Zero SSH Keys

fortyfivan
1pts0
circleci.com 6y ago

Maslow's hierarchy of remote worker needs

fortyfivan
18pts0
www.heavybit.com 7y ago

Developer Empathy with Jason Chan of Netflix on the Secure Developer

fortyfivan
4pts0
kloudless.com 7y ago

Cloud Integrations Made Easy: Unified APIs – How to Scale Your App Fast

fortyfivan
7pts0
circleci.com 7y ago

How to test software: mocking, stubbing, and contract testing

fortyfivan
2pts0
www.tonic.ai 7y ago

Things in life are free, including this CSV generation tool

fortyfivan
1pts0
www.heavybit.com 7y ago

The Evolution of Enterprise with Edith Harbaugh of LaunchDarkly

fortyfivan
5pts0
www.heavybit.com 7y ago

From 0 to 1, Hiring Your First Product Manager

fortyfivan
2pts0
blog.kloudless.com 7y ago

New UI Tool Featuring Kloudless Calendar API

fortyfivan
8pts0
www.heavybit.com 7y ago

The Secure Developer – Managing Security with the RealReal’s Julie Tsai

fortyfivan
4pts0
circleci.com 7y ago

Moving to DevOps: what tools do you *really* need?

fortyfivan
2pts0
launchdarkly.com 7y ago

Great GameDays: Thinking About Failure Holistically

fortyfivan
2pts0
circleci.com 8y ago

Testing Docker Images with CircleCI and Goss

fortyfivan
2pts0
www.heavybit.com 8y ago

Startup Founder Partnerships with Ellen Chisa and John Kodumal

fortyfivan
3pts0
circleci.com 8y ago

A Brief History of DevOps, Part II: Agile Development

fortyfivan
5pts0
medium.com 8y ago

Commit Go Code with Joy and Confidence

fortyfivan
5pts0
circleci.com 8y ago

From Code Cowboy to Infrastructure Architect

fortyfivan
56pts15
www.heavybit.com 8y ago

Transforming Microsoft into an Open Source Company

fortyfivan
5pts0
blog.launchdarkly.com 9y ago

[Podcast] to Be Continuous: When Toasters Broke the Internet

fortyfivan
13pts0
blogs.msdn.microsoft.com 9y ago

Building VSTS Extensions with feature flags

fortyfivan
11pts0
blog.takipi.com 9y ago

What Are the Most Common Words Developers Log?

fortyfivan
5pts0
www.scaleft.com 9y ago

Google's Infrastructure Security Design Revealed

fortyfivan
3pts0
blog.takipi.com 9y ago

Java 9 Will Change the Way You Traverse Stack Traces

fortyfivan
7pts0
www.iron.io 10y ago

E Is for Event. A Fresh Take on ETL

fortyfivan
2pts0
www.iron.io 10y ago

The Workloads of the Internet of Things

fortyfivan
2pts0
blog.iron.io 11y ago

Smart Endpoints. Smart Pipes. Smarter Microservices

fortyfivan
2pts0

Wild to think that Jazz in Silhouette was 1959, but to your point about transcending space and time...

My favorites are a bit later – Lanquidity (1978) and Sleeping Beauty (1979).

A good start might be the lone release on Savoy, The Futuristic Sounds of Sun Ra (1962) – China Gates is such a hypnotic jam.

Elis should be in every top 10 list!

Top 10s are always tough, but I'll give it a shot. I have a penchant for the obscure, but if I were to consider total output, my list would be (I know I'm leaving some out)...

- Arthur Verocai (anything he arranged) - Joyce Moreno - Jorge Ben - Milton Nascimento - Edu Lobo - Nara Leao - Elis Regina - Marcos Valle - Gal Costa - Joao Donato

And a bonus top 5 groups

- Tamba Trio - Novos Baianos - Azymuth - Quarteto Em Cy - Dom Salvador's groups (Rio 65, Salvador Trio, etc.)

For a deep dive into the obscure stuff, I used to do a podcast from my collection. Lots here to keep anyone busy.

https://novedos.com/

I can't upvote this enough! I've dedicated a good portion of my life to collecting Brazilian records from that era. Expensive, but rewarding hobby.

Love to see Sun Ra on HN! A prize in my record collection is an original Sleeping Beauty / Door of the Cosmos on Saturn with a hand pasted cover.

There’s a recent book compiling much of the original cover art. Recommended.

Sun Ra: Art on Saturn: The Album Cover Art of Sun Ra's Saturn Label https://a.co/d/7h3J9II

Cloud Identity 8 years ago

Disclaimer: I work at ScaleFT - we offer BeyondCorp-like access controls as a service for servers (SSH & RDP) and internal web apps.

Exactly right... BeyondCorp is more of a reference architecture than a product. Google's own internal implementation is what the research papers focus on, but we're seeing more companies adopt similar models by shifting access controls to the application layer, where a request can be independently authenticated (corporate IdP) and authorized (RBAC, policies) against more dynamic conditions - such as the security posture of the user's device.

The Identity piece is a critical component to the system as the user system of record, but really just one of the inputs in a BeyondCorp-like environment.

I'm from ScaleFT, thanks for the mention. True that our original focus was in SSH/RDP access, however we've recently introduced Web access as well.

https://www.scaleft.com/blog/how-to-deploy-a-beyondcorp-styl...

I agree with many commenters that it appears transformative, but that's only through the lens of Google. Centralized access controls at Layer 7 through a proxy service that can authenticate and authorize requests, while brokering encrypted sessions isn't that out of reach. Our goal at ScaleFT is to offer as much as a service as we can.

Where things do get tricky, though, is with the access policies and device attestation in a BYOD environment. Admittedly, we have work to do in this regard, but it may not require a full MDM layer. Really, you only need to query device state at a given time to make an authZ decision.

Love to see BeyondCorp get more coverage, and I hope to see further adoption outside of Google.

I'm with ScaleFT, thanks for the shoutout. We've been huge believers in BeyondCorp since the first paper was released, and have incorporated the concepts into our Web Access product - https://www.scaleft.com/product/web-access

Similarly, apps are placed behind a reverse proxy, which performs authN via your company's IDP, then authZ against the policies associated with the resource. These can be basic RBAC or more device oriented decisions such as whether the client disk is encrypted.

We also believe a SaaS model is the way to make BeyondCorp a reality for companies who aren't Google, but there's more to it than a proxy service. We've found the more challenging aspects of a complete system to be the policy engine and device bindings, and have spent the past couple years working to offer with our product.

Glad to see CloudFlare talking about BeyondCorp, the more who are providing solutions in this space, the easier it will be for companies who are not Google to get there.

< But as far as giving a sense of ownership and intimacy, vinyl wins

This. I've been a record collector for 20 years, mostly focused on rare Brazilian music - https://www.novedos.com.

I don't DJ anymore so it's primarily a collector thing for me. Aside from the master tapes, an original vinyl copy is as close as you can get to the original recording, which is special. I'm far from an audiophile, so it's not about the sound, it's about the feels.

Great question, and not off-topic at all ;)

Our first priority in developing our bastion product was to guarantee end-to-end privacy and verifiability, so the cleartext is not available on any bastion. We do have a roadmap item to support customers' desire for visibility into team activity, but we engineered for privacy first. Our current auditing is event-based - device enrolled, credential issued, ssh/rdp login, etc.

Happy to discuss our roadmap further - ivan.dwyer@scaleft.com

The point was that fundamentally the Internet is not safe, so companies will do the right things to secure their resources. So yes, in BeyondCorp this means running a proxy service that centralizes the auth workflow through policies that check the user and connecting device against the resource at the time of the request.

Very true... the "ditch your VPN" sure is a nice soundbite, but in reality it's the last thing you should be doing. I mean that literally... as in it's the last step. Better know what you're doing before getting there.

The first couple BeyondCorp papers talk a lot about how Google deployed this architecture side-by-side their traditional LAN, and slowly migrated applications over, only after closely inspecting and understanding the traffic.

But the real point they make is that Internet != safe = very much worry about security.

Great to see them continue this series, and glad that this one touches on what it takes for other companies to achieve something similar. I talk about BeyondCorp a lot as evidence that the Zero Trust model works, and that employees will love it.

The most common feedback I get is that it seems like too much of a stretch for companies that don’t operate at Google scale. That may be true if looking at the system as a whole, but the principles behind the architecture should attract anyone’s attention - remove trust from the network by authenticating and authorizing every request based on what’s known about the user and connecting device at the time of the request.

Disclaimer: I work for ScaleFT, a provider of Zero Trust access management solutions.

Edit: If folks are interested in hearing more about how other companies can achieve something similar, here's video of a talk I gave at Heavybit a few months ago on the subject: https://www.heavybit.com/library/blog/beyondcorp-meetup-goog...

Great work! Tough to tell if I would _really_ like it without spending some time in use, but the one thing that really jumped out at me was the various Clip types and states. Very nice.

I'm with Iron.io, thanks for the mention. Interesting to see the architecture/patterns so front and center all of a sudden, it's what we've been doing for a while now.

Very true that a key benefit of AWS Lambda is the ability to hook into the internals, but to the article's point, that's a pretty significant level of lock-in. We recommend to our customers who want a similar level of functionality hook up the internal events to SNS, at which point a job can be triggered on our end.

We operate across any cloud, standardizing through Docker images as the unit of code. It's "serverless" to the developer in that the only configuration is setting the event triggers. Of course there's compute involved, but it's outside of the development lifecycle.

Disclosure: I work for Iron.io

If you're open to a hosted solution, check out IronWorker: http://www.iron.io/worker

It's an async task processing service with a built-in job scheduler. You can upload your python scripts to Iron.io, then set schedules and other triggers to execute on-demand. We have a dashboard to manage tasks and schedules, see what ran and what failed, and you can visualize the characteristics you're looking for. We do distribute the workloads for you, but sounds like it could be a good fit.