HN user

ohlol

41 karma
Posts0
Comments33
View on HN
No posts found.
Cuddle Mattress 14 years ago

because all kickstarters are created by reputable people with legit "industry experience" who always produce.

...NOT!

[dead] 16 years ago

dude, i tweeted you three times. you should really check that stuff since you can't be DMed unless you follow back.

you should be hearing from someone soonish.

I once had the displeasure of using Fogbugz (hosted version). You could only reply to a bug if it was sent in via E-mail. Any other correspondence was to be performed via actually editing the ticket data, inline.

I called to ask if there was a way and the dude I talked to actually insinuated that I had not taken time to read the documentation. WTF?

Apparently that requirement was a "feature" -- they assumed that a bug entered manually did not require correspondence.

Yes, I was told that as well.

40 Years of Unix 17 years ago

Yeah really. I have a few thousand "consumer devices" running both Linux and actual UNIX.

D'oh, upvoted instead of clicking reply =(

What I mean is that in order to manage user accounts, the management tool (Puppet) will have to know what the encrypted password is so it can insert it into /etc/shadow. Otherwise you have no password and must rely on NOPASSWD in sudoers if you want to log into that managed machine and use sudo.

If the system doesn't have a password for you in /etc/shadow, sudo can't authenticate you via getpwent or whatever.

So your only two options are to write a tool for users to update their password in Puppet directly/indirectly, or allow NOPASSWD and religiously check for empty passphrases on SSH keypairs.

re: 1) sudo NO PASSWD...

So the problem I have with this is that it collides with using Puppet to manage your users--Puppet will have to know about the users' Unix passwords.

It should be fairly straightforward to write a script that tests for SSH keypairs with an empty passphrase, simply try to authenticate an SSH agent by loading the user's key.

I've never been a fan of changing SSH's port.

If you're going to firewall SSH, changing the port is redundant.. The only reason to change the port is to prevent brute force attacks, and the firewall will do that for you.

True, but the odds of that happening are probably similar to the lottery. I'm not trying to argue that college is worthless or of low value (I think the answer can only be subjective). But if one is to argue that it is valuable, they should probably base it on the learning opportunities.

Equivalent networking and social opportunities exist in plenty other areas of life that don't cost you tens or hundreds of thousands of dollars.

I see tourists doing Segway tours all the time here in SF. Personally, I prefer the Go Car tour. Instead of having to wear a lime green vest for protection and tool around a few blocks, you get to ride in a GPS-navigated car. You can take it where ever you please as well, but I digress.

I would buy a Segway if it looked like something from Mad Max.