HN user

notwedtm

381 karma

[ my public key: https://keybase.io/wedtm; my proof: https://keybase.io/wedtm/sigs/02PoVrnRXzLmOIRHPWk6yXMuFmdcHXtWhUWS9VMl9Q8 ]

Posts4
Comments160
View on HN

The disclaimer at the bottom is the icing:

"A smartphone or tablet with a recent version of iOS or Android is required to access our digital service. Read-only access will be provided to users age 11 to 16. Access to our digital service is at our discretion. To activate the service, we’ll need to hold an email address and mobile phone number. Face ID and fingerprint recognition available on selected devices. Payments made to new payees over a certain value will need to be made on the desktop version as an additional layer of security."

From my understanding CVV/CVCs are a function of the PAN, expiry, and some DES encryption. Does this mean that the target bank had a weak DES key or was some other vulnerability discovered?

You're probably thinking of SpaceX. While it's not Tesla, it is another multi-billion dollar company pioneering an industry so I can see how you might get them confused.

Musk is eccentric sure, but at the end of the day the two companies are building emmission-free vehicles and trying to make humanity an interplanetary species. Both of these are pretty worth-while goals, imho.

I would love to see a CEO who doesn't have flaws.

What if it was $20 billion? Maybe the idea is feasible if you go bigger? Still less than half of the current strategy of a hostile takeover.

HTTP Feeds 4 years ago

Less this and more that one should be cognizant of their own inherent communication biases.

[dead] 4 years ago

This shouldn't be made into a public spectacle. You should be getting a lawyer to help explain why those governmental bodies felt so secure in not answering you the way you had hoped, and if there is any other recourse you can take.

Regardless of your actual "rightness" on this issue, potential future employers will only see this as a liability. The willingness to air dirty laundry against a previous employer is not seen as a positive attribute in most hiring processes I've seen.

Lawyer up, delete the post, hit the gym. (or something like that)

I think K8S secrets get a bad wrap. They are not intended to be secret in the sense that they are "kept from prying eyes by default". The secret object is simply a first-class citizen that differentiates it from a ConfigMap in a way that allows distinct ACL's.

Most organizations I know will still use something like ExternalSecret for source control and then populate the Secret with the values once in cluster and to an object with very few access points.

I think the word "managed" is the clear differentiator here. There is a huge difference between setting up ElasticSearch on some EC2 instances yourself, and paying ElasticCo for a managed cluster.

I would expect the latter to be sure by default.

Yeah, I don't follow this line either. My doctors portal has my providers notes readily available to me without me asking.

Are you sure you aren't just expecting to have to request it, and are being surprised by the fact that you don't?

Why? What does Cue have that older, more production-tested systems do not?

I'm curious as to what problems I'm missing today that may come up in the future that Cue is solving.