One person's (not my) take on why to skip this: https://the.unknown-universe.co.uk/privacy-security/little-s...
TL;DR it's closed source and there's open source alternatives.
HN user
One person's (not my) take on why to skip this: https://the.unknown-universe.co.uk/privacy-security/little-s...
TL;DR it's closed source and there's open source alternatives.
It's like the Swiss Cheese model where every system has "holes" or vulnerabilities, several layers, and a major incident only occurs when a hole aligns through all the layers.
I certainly don't get that cert. I'm seeing a LetsEncrypt cert for idtech.space with various SANs.
# host code.idtech.space
code.idtech.space is an alias for idtech.space.
idtech.space has address 192.99.32.215
idtech.space has IPv6 address 2607:5300:60:47d7::Dvorak support/autodetection would be nice.
Love this, absolutely looking forward to some results.
https://leehite.org/Chimes.htm is the best source of information I've found on chime design and length. They go into great length about the lower octaves and how you can hear them (or not).
I recently created https://immich.pro to partially address this problem. I've got spare compute and storage that I'd like to turn into MRR. While the privacy angle isn't _fantastic_ maybe some people won't care. Could be better than trusting Google/Apple.
Thank you for providing this. In my firefox this article rendered as only the first paragraph then went straight to the comment section and I was very confused about why this was worthy of HN unless to talk about such a short content section!
How much does it cost? Would love to buy one with the HOA and run our own micro-grid while exporting electricity to the local utility.
[2001]
Agreed. They're one of the few media sources I go out of my way to support with a membership.
I was thinking something similar. Participate online without feeding models via a self-selected DNT-like tag...
I too greatly enjoyed the article. Love those deep troubleshooting write-ups!
49% here. Maybe I'm missing the point? Something other than playing snake I suppose.
Would love to see a "use X days off between now and the end of the year" feature. Putting in the amount of PTO I've currently got gets shown for the whole year instead of just through EOY
and iTerm, Zoom, WebEx, Teams, talosctl... All kinds of prompts like that only to find everything enabled.
Is that the KH0J transmitter? I've driven past that countless times and it seems so run-down I've often wondered if it was still transmitting. So many times I've wanted to park in the lot and take a gander... Probably for the better that I haven't!
Amazing you say? I have the opposite opinion and think they're quite trash. The ones I visit almost always have a long wait, multiple display TVs with non-stop advertising on them, the employees are frequently cantankerous, and being a for-profit entity, the amenities are always as sparse as possible or in need of repair.
Overall a rather soul-sucking example of a captive market optimizing for profit.
Did you match colors too?
I used FIPS 186-5 in an argument with my InfoSec team to get ed25519 added to the list of accepted SSH key types on SSH servers running in FIPS mode. What a fun day :P
This is pretty spot-on.
Oooo for once, my time to shine! Or maybe, my time to shine???
Is it typically expected of entry-level engineers, senior engineers, principals, tech leads, and/or project managers?
Working at a company that provides FedRAMP-approved services, the knowledge of FIPS within the company is a bit sparse. InfoSec definitely needed to understand it in order to explain to developers that they have to use BouncyCastle over the default java crypto provider, etc, but it took someone else to _really_ understand it and tell InfoSec that they were initially asking for the wrong thing.
Entry-level? No. Senior? At least minimal understanding of how cryptography works in their language of choice and the impact of FIPS. Principal? Same Tech leads? Not a well-defined role. Probably. Project managers? No.
Have you ever needed to immerse yourself in a FIPS or ISO standard?
Yes. Multiple times. I argue with third-party auditors and the FedRAMP Joint Advisory Board about interpretation of these standards.
Was it out of necessity for a project (just-in-time learning), or do some of you explore these standards in your spare time?
Necessity. See FedRAMP. However I can say ISO8601 was just for fun. ISO8601 gang represent!
These standards are complex and mastering them is no small feat. It's interesting that people don't often brag about this expertise on their resumes.
I've seen a couple people who listed those standards or similar (FedRAMP again). Given the choice between two identical candidates while one has FedRAMP/FIPS/ISO experience I'll pick the one listing the standards.
Have you ever listed such standards as part of your skill set? Why or why not?
I've not updated my resume since acquiring skills in the relevant standards but will probably include them when I do update my resume. They're a specialization that commands a premium when it comes to salary, if you're willing to work in the industries / companies that play in that space. Some people wouldn't include it because they truly hate working with rigorous standards.
How has your understanding of these standards impacted your career or projects?
Understanding them has certainly proved to be a benefit to my career given how closely I work with them.
It was a picture of a Canadian farm.
Beware density/heat maps that mostly just match population maps. Of course, xkcd has been there before: https://xkcd.com/1138/
I checked out the page you linked and it doesn't load very well. FYI
* No http -> https redirect
* Broken layout when forced to https
* Play store link 404's
* Icon on the download button is broken
Bitwarden because it has the "Teams" feature and can hsare passwords with multiple people. No sync issues like passing around a keypass file and worrying about having the latest version of it.
Apptio | Infrastructure Engineer II | Full-time | Bellevue WA or Remote | US Citizen | $130k DOE
Apptio is the business management system of record for hybrid IT. We transform the way IT runs its business and makes decisions. With our cloud-based applications, IT leaders manage, plan, and optimize their technology investments across on-premises and cloud.
You will be a member of our globally distributed public sector operations team splitting your time between unplanned incident or internal support work and planned projects from our the current sprint. Typical work involves troubleshooting application instances, resizing containers, improving automation for deployments, patching, security compliance, and much more. We work with technologies like Puppet, AWS, and terraform. Our environment consists of cloud deployments.
Contact me: gwalters [at] [thecompany].com if interested or apply via the link[1].
[1] https://www.apptio.com/company/careers/job-openings?gh_jid=1...
I use it to take up space in my drawer of useless electronic stuff because I can never find a combination of power supply and SD card that doesn't eventually end up corrupt and unbootable.
What are people using them for?
In my case, keepalived VRRP floating addresses.