HN user

old-gregg

9,827 karma

Protecting your infrastructure at https://goteleport.com Before that I delivered mail at https://mailgun.com

ev@kontsevoy.com

Posts103
Comments917
View on HN
goteleport.com 1y ago

Teleport Secures MCP

old-gregg
1pts0
www.thebricks.com 1y ago

Bricks

old-gregg
2pts0
goteleport.com 3y ago

Teleport Assist: Chat with your cloud server fleets

old-gregg
1pts0
goteleport.com 3y ago

How to Access Infrastructure Without Usernames and Passwords

old-gregg
1pts0
techcrunch.com 4y ago

Teleport nabs $110M to provide identity-based infrastructure access

old-gregg
10pts1
goteleport.com 4y ago

On Terminals and Sessions

old-gregg
7pts0
goteleport.com 4y ago

Using Z3 theorem prover to analyze role-based access permissions

old-gregg
7pts0
goteleport.com 4y ago

SSH Bastion Host Best Practices

old-gregg
358pts84
goteleport.com 4y ago

Best Practices for Securing SSH

old-gregg
172pts141
goteleport.com 4y ago

SSH keys are passwords too

old-gregg
3pts1
goteleport.com 4y ago

When a Startup Should Call the FBI?

old-gregg
1pts0
lenspire.zeiss.com 5y ago

How to Read MTF Curves [pdf]

old-gregg
1pts0
gravitational.com 5y ago

How to Set Up an SSH Jump Server

old-gregg
8pts0
coda.io 5y ago

Impact of COVID-19 on Startups (Kleiner Perkins Report)

old-gregg
5pts0
gravitational.com 5y ago

Celebrate Open Source Day on September 4th

old-gregg
3pts0
gravitational.com 5y ago

I Found Myself in a Command Line vs. GUI Meeting

old-gregg
3pts1
github.com 6y ago

Curl Wttr.in

old-gregg
461pts122
www.bbc.com 6y ago

Olympus quits camera business after 84 years

old-gregg
3pts1
gravitational.com 6y ago

Infrastructure Security Without Slowing Down Developers

old-gregg
37pts15
gravitational.com 6y ago

How to SSH Properly

old-gregg
584pts158
gravitational.com 6y ago

The Future of Women at Gravitational

old-gregg
5pts0
www.anandtech.com 6y ago

AMD launches 64-core EPYC server processor for liquid cooled systems

old-gregg
2pts0
www.cs.utexas.edu 6y ago

SMT Solving on an iPhone

old-gregg
1pts0
gravitational.com 7y ago

Goodbye AWS: Rolling Your Own Servers with Kubernetes, Part 2

old-gregg
38pts2
gravitational.com 7y ago

Rolling your own servers with Kubernetes

old-gregg
409pts203
motherboard.vice.com 7y ago

Why American Farmers Are Hacking Their Tractors with Ukrainian Firmware

old-gregg
6pts0
github.com 7y ago

curl wttr.in

old-gregg
2pts0
gravitational.com 7y ago

New superpowers for Helm: package Kubernetes apps as self-contained tarballs

old-gregg
8pts0
www.prosperops.com 7y ago

PropserOps: Autonomous Reserved Instance Management on AWS

old-gregg
3pts0
gravitational.com 7y ago

Microservices, Containers and Kubernetes in Ten Minutes

old-gregg
384pts85

Sam Harris often makes an argument that I both hate and kind of agree with. He says that exchanging arguments and having a debate only works when the two arguing parties share a foundation. The debate’s purpose is to reconcile a measurable difference of opinion.

In this case, I feel there’s no shared foundation. Half of the commenters here don’t seem to understand what money is or how it works. There's no soil in which to plant an argument, because there's no understanding of what a billion dollars represents. There’s no genuine desire to understand the counterparty either.

Very disturbing.

Fast 12 months ago

I don't get it. Wouldn't going from 1 second to 0 seconds add the same amount of money to the yearly profit as going from 2 seconds to 1 second did? Namely, $1M

Of course the joke was silly. But perhaps I should have provided some context. We were making industrial automation software. This stuff runs in factories. Every saved second shrinks the manufacturing time of a part, leading to increase of the total factory output. When extrapolating to abusrd levels, zero time to manufacture means infinite output per factory (sans raw materials).

Fast 12 months ago

Unfortunately, there wasn't a single bottleneck. A bunch of us, not just me, worked our asses off improving performance by a little bit in several places. The compounded improvement IIRC was satisfactory to the customer.

Fast 12 months ago

Fun story time!

Early in my career as a software engineer, I developed a reputation for speeding things up. This was back in the day where algorithm knowledge was just as important as the ability to examine the output of a compiler, every new Intel processor was met with a ton of anticipation, and Carmak and Abrash were rapidly becoming famous.

Anyway, the 22 year old me unexpectedly gets invited to a customer meeting with a large multinational. I go there not knowing what to expect. Turns out, they were not happy with the speed of our product.

Their VP of whatever said, quoting: "every saved second here adds $1M to our yearly profit". I was absolutely floored. Prior to that moment I couldn't even dream of someone placing a dollar amount on speed, and so directly. Now 20+ years later it still counts as one of the top 5 highlights of my career.

P.S. Mentioning as a reaction to the first sentence in the blog post. But the author is correct when she states that this happens rarely.

P.P.S. There was another engineer in the room, who had the nerve to jokingly ask the VP: "so if we make it execute in 0 seconds, does it mean you're going to make an infinite amount of money?". They didn't laugh, although I thought it was quite funny. Hey, Doug! :)

4-7-8 Breathing 1 year ago

I feel the opposite. Especially the part about NOT breathing for 7 (!) seconds, which doesn't feel naturall at all. Something like 4-2-5 would have been much closer to my natural. To me the benefit of this thread is the comments recommending other apps/methods.

Your "life hack" is not a good advice. There's plenty of well-written explanations for why perimeter based security doesn't work. What is strange is that you've started in the right place: by being "constantly worried about security implications of each app". Unfortunately it's annoying and time consuming, but that's the right way to keep your data private. And if that's too much hassle, it means it's worth it to pay others to do it.

When I'm thinking about a hypothetical situation when I need to save the world by hacking into a hypothetical villain, my best hope will be him using your approach to security.

Languages do not matter as much as you think. Ecosystems are everything. Twice in my life I started companies (the first one took all my life savings) and in both cases the right call was what you called an "inferior language".

I actually liked D very much, and WB had been a personal hero of mine when I was in college. But I am not betting my career on an ecosystem built around by a single brilliant guy. For high-stakes projects, a wise decision is building on a platform with several deep-pocketed backers.

And for toy/personal projects... do you even need a language anymore? Just ask your favorite LLM to generate you an executable which does what you want (partially joking here).

Hacker News delivers again. What an incredible example of quality feedback from a would-be customer. As one of Mailgun founders, I can also confirm/agree with all of the suggestions above.

Telling you now, someone will sign up with stolen credit card, spam like hell and you will be left with clean up. Been there, done that.

Ignoring this advice killed some companies in this space.

My take is that Elon is suing OpenAI because he left OpenAI before they opened a commercial venture, which means he doesn't benefit from the companies current valuation

According to the Isaacson book, Sam offered Elon equity in the for-profit arm of OpenAI but he declined. He is clearly motivated by the original mission, i.e. the Open part.

Why not, for example, celebrate the virtuous instead?

Because it's hard to celebrate the intangibles, that is why virtue signaling gets the spotlight instead. But action and achievement are tangible and can be celebrated (if they're good for society).

This is not a "bizarre false dichotomy". This is a perfect example of dichotomy: do you celebrate actions or intent?

I am not a pilot but I've been told by many that a large chunk of a new airplane price is the cost of certification which also provides a great incentive for manufacturers to design one product, get it certified, and sell it without major modifications for decades to avoid re-certifying it.

How did they manage to produce a $120K aircraft then? Is it not subject to the same certification requirements as the Cessna 172 which features similar specs but at 3x the price?

Remember, you're comparing Linux and FreeBSD in 2022 but BSD lost to Linux much earlier, many years ago. Back when I was looking into them (long time ago, excuse me for not remembering the details), BSD felt more pleasant and coherent. But at the same time it had limitations on scalability, performance and compatibility with hardware and also with userland software. In every benchmark, especially on multi-core, multi-socket systems, Linux was ahead.

My theory at the time was this: GNOME won on developers' desktops, so most software was developed on Linux natively, with BSD compatibility (and performance) as an afterthought. IIRC Linus made a similar point on the mailing list that developers love servers that resemble their programming environments. TDLR: BSDs got stuck in CLI-only mode for too long.

The more common explanation was that Linux got a head start by a few years by being a clean-sheet implementation, while the BSD had to spend its early years purging itself off the AT&T copyrighted code, so it was untouchable from a commercial use perspective.

Installing a 3rd party agent that in some way permits shell access to a server and (I assume) needs to run constantly is definitely going to raise a few eyebrows especially when the benefit of using is actually fairly low.

You're already running sshd. Teleport is a drop-in open source replacement, which offers some interesting features like certificate-only auth (removing the need for pubic/private keys), SSO integration, RBAC over SSH, support for protocols other than SSH (Kubernetes API and major OSS databases), and syscall level authorization and audit, so quite a few security teams have appreciated it lately.

Disclaimer: I work at Teleport and have been a maintainer for the first 3 years.

Part of me thinks that we have reached the tipping point where all cloud dev tooling needs to be thrown away and we need to start over.

I had the same feeling when we reached the pinnacle of complexity of Windows programming with COM/DCOM/ActiveX/.NET/WinForms/Silverlight/Visual Studio... All of that felt like necessary progress. Yet, a simple script piping text output into a browser via CGI felt like a breath of fresh air. We need this for web development now.

but things changed with the advent of microservices.

Microservices is just a marketing buzzword invented by container orchestration start-ups. Partitioning of large applications across multiple inter-connected processes has been around for decades. Your computer is packed with microservices.

On Linux, type `watch date` and enjoy two microservices running and interacting. On Windows, observe a dozen of svchost.exe processes in the Task Manager.

Maybe it's a result of wealth inequality and monopolization?

Well, the author did compare the current rate of innovation to the dawn of the 20th century, when (according to him) we had plenty of new ideas. But wealth inequality in 1900-1920 was comparable to, if not higher, than today. The raise of the middle class in the US didn't happen until after the WW2.

forget PAIP and look at Artificial Intelligence: A Modern Approach.

I've read and enjoyed that book 10+ years ago. Haven't been following AI/ML since then. Is it still a "modern approach"?

I care about owning my own data very much. This makes me conservative when it comes to these solutions, despite otherwise being an early adopter of everything tech.

For that reason I always recommend Synology NAS machines. They have been around forever, they work for years on autopilot and feel very similar to a microwave in terms of operational overhead. One-time purchase. No subscriptions. But most importantly, the ecosystem is stable and mature. And they are easy to understand and reason about and come with a slick UI with mobile apps. My favorite feature is having my massive photo collection always available on my phone, served from my own basement (with encrypted AWS Glacier backups).

[EDIT] This is Brandon Phillips of CoreOS fame sharing this! Maybe I should take a closer look then.

"Let them track me, I've got nothing to hide."

Interestingly, this attitude used to be default even here on Hacker News ~5 years ago. I am so glad to see it's changing. Why I'm finding this interesting? Because this audience always knew what's going on even without layman articles like this, but did not care for some reason. This shows how just knowing isn't enough sometimes. Public sentiment matters.

Disclaimer: I work at Teleport (but I am not the author of the article).

This work was done because the Teleport users who used it for SSH kept asking for the same access for their databases. The reasoning goes like:

1. Setting up a single proxy gives you the same benefits for N databases as they come online. No need to manage additional endpoints (public IPs, ports, etc).

2. You have the same centralized place to manage auth/authz for all users.

3. This allows to connect to databases on the edge, where there isn't an opportunity to have a permanent public IP and locations frequently go online/offline.

4. Finally, it's nice to have unified visibility into what's available (for users) and centralized logging/audit for the security team.

As always, all of this is possible with other tools. The world of open source is vast and full of options, but we were hoping to make it simpler, with less configuration and moving parts.

Intel Problems 6 years ago

Is it not at least somewhat possible that at least some of those Apple laptops will age out and be replaced with GNU/Linux laptops?

And I personally hope that by then, GNU/Linux will have an M1-like processor available to happily run on. The possibilities demonstrated by this chip (performance+silence+battery) are so compelling that it's inevitable we'll see them in non-Apple designs.

Also, as it usually happens with Apple hardware advancements, Linux experience will be gradually getting better on M1 Macbooks as well.