HN user

ppierald

252 karma

[ my public key: https://keybase.io/pmp; my proof: https://keybase.io/pmp/sigs/Na7q4IldbG1X6Og-9ODRl8srLYjqHO2QyBomjUVnEkk ]

Posts2
Comments79
View on HN

Respectively, yes. The ability to create venvs so fast, that it becomes a silent operation that the end user never thinks about anymore. The dependency management and installation is lightning quick. It deals with all of the python versioning

and I think a killer feature is the ability to inline dependencies in your Python source code, then use: uv tool run <scriptname>

Your script code would like:

#!/usr/bin/env -S uv run --script # /// script # requires-python = ">=3.12" # dependencies = [ # "...", # "..." # ] # ///

Then uv will make a new venv, install the dependencies, and execute the script faster than you think. The first run is a bit slower due to downloads and etc, but the second and subsequent runs are a bunch of internal symlink shuffling.

It is really interesting. You should at least take a look at a YT or something. I think you will be impressed.

Good luck!

I like "Hi Team". I do use that in certain social circles, but I do get the point of the article.

Survivor, the US TV show, used to say "Come on in guys" until recently where they made a point to discuss the topic on camera with the contestants. There was a variety of opinions, but they ultimately settled on "Come on in." which conveys the point in a neutral tone.

I happened to get invited to friends of my in-laws who own a vacation property on the Oregon coast for the 2017 eclipse. Of course, the Pacific coast is dicey at best, so we were crossing our fingers. When the time came, the stars lined up and we had that magical moment, except right at that moment, the waste truck came through picking up the bins. If you have the opportunity, GO. The worst case is you don't see it. The best case is one of the most memorable experiences of your life.

A few points.

PCI-DSS does not mandate the use of a WAF. It is one of two ways you can fulfill requirement 6.5 or 6.6. WAF + OWASP Top Ten ruleset is typically easier to get evidence for your auditor, but you can show that continuous scanning using a DAST scanning engine to meet requirements.

I would have a WAF installed with very few highly tuned rules against mostly SQLi. Why? Because the damage of letting that through and praying that the developer or web-app framework does it right are significant. The rules for SQLi are pretty easy to get right and dropping that traffic before it gets to your web server is a reasonable thing.

I would have a WAF installed with no rules too. It is nice to have something there where you can drop in a Log4J rule and get protection relatively quickly for attacks of that nature. There have been a number of these over the years and a small performance penalty seems worth the big picture safety net.

I am against the pricey models that the cloud vendors push. WAF can get expensive. They typically are bundled with other cloud services, but hey, if you've gotten that far, you are probably outsourcing most things to the cloud provider anyway.

I do not like WAF pragmatically because it lets the developer off the hook in many ways. There is something there doing their work for them and another reason for some developers to not understand or care about the security of their applications. Something else will do it for me whether I know this or not.

If there is some legitimate reason (say performance) to keep a tighter form (inline assembly, Python 1-liner, whatever), then making the unfurled equivalency as a comment nearby to allow the next developer to have a fighting chance would be really helpful. Also, error handling tends to be not included in the 1-liners.

Diablo Canyon is in an absolutely beautiful part of the central coast of California. Definitely visit the greater San Luis Obispo area. Californians want it all (green and plentiful), but lack the basics to make that happen (coalfire supplemented with wind and solar plus overloaded grids -- see what happens this weekend with FlexAlerts already called).

Nuclear should be considered. I don't know how to make them perfectly safe and their have been incidents where unfortunate accidents occur, but newer technology and designs might make our society able to have their cake and eat it too.

The going to a ball game is an interesting example. I think there are financial disincentives at play, most notably, the price of beer. There are likely forces at play that will maximize the dollar intake while minimizing the amount consumed. This is not popcorn (still expensive) we are talking about. If beer were 1/2 as expensive, then people would drink 2x more and spend the same amount, but the effect on society would be much worse. We would have more fights in the stands, more drunk driving, and other negative effects. So by jacking up the price of a beer, fans can enjoy one or two, then realize they don't have the budget for a 3rd or 4th and cut it off there. They cut off sales in the 7th inning to prevent most of those effects I mentioned.

But that's just a theory ... a beer theory.

Not a huge deal in and of itself? Good key management processes would have you rotate every so often. However, we probably have a lot/most/all of us that use the same SSH key for many systems and loss of that private key would be compromise of your Github account.

Have a unique username / password combination for each website, right? Same is true for Github and all other SSH systems.

Also, Github provides Security Key support if you want to go that route. SSH keys are really not that different than passwords, but they seem more complicated, so maybe they are?

Get your colonoscopy. Period. Don't let people tell you fables about "the prep" or be afraid of something going up your butt.

"The prep" is a bit unpleasant for a couple of hours, but no big deal. The actual procedure is done under propofol. Consider that part the best nap you will ever get.

You will either get a clean bill of health, or the doctors will find something that is easily treated right then and there. The stigma (especially of men) about this procedure will lead to countless numbers of them to die from something that doesn't have to be.

Get the procedure when your doctor says. Just do it. Please.

My least favorite and most annoying Google nag is the not-so-helpful reminder of which google account I am logged-in as on every google doc I open through out the day. A dismiss click is needed for "You're currently signed in as xxxxx@whatever.com". No disable button. Just suffer.

Age 14, I worked 2 hours a day, 5 days a week at the local fish market doing clean up and end of day work. Nasty stuff. I worked the summer before college at a friend of my parent's warehouse basically relabeling overstock canned goods with a white label for use in restaurants. Hot, loud, and smelly job. During my sophomore year, I thought I wanted to drop out. My dad said he could probably get me into the plumber's union, and no disrespect to plumbers (they probably make more money than I do), but the memories of that work made me go back and give college one more shot. It all worked out in the end. I graduated, found work, and am still in the industry happily three decades later, but it all could have gone the other way if not for those hard manual work summer jobs.

I am definitely not an expert in these areas and I'm sure someone 100x smarter than I am has thought of this and discounted it already, but is there any ability to decompile the executable provided to Colonial and get to patterns of source code, then compel github to search their repositories for any patterns of that code? Not sure if that is even legal or whether a judge would authorize that fishing expedition, but it's an interesting thought exercise (in my head) assuming the code is even in GH.

One Year of TILs 5 years ago

As a former coworker with Simon, he is endless fascinated with learning and helping others gain knowledge. The fact that this page exists is not surprising to me in the slightest. It represents the high quality research and documentation he consistently provided. He is not with my company any more, but I am happy he continues this tradition and shares it with the internet as a whole.

In 1970 (shortly after my birth), my grandmother bought me my first Christmas ornament for the tree. It was a glass Michael Collins astronaut figure. Over the years, it has taken a couple tumbles, lost a leg and most of the helmet, but every year it goes up to the top of the tree in a prominent place. I was struck with a profound sense of sadness today when I heard of his passing mostly due to my connection to him via this simple ornament. He will continue on in that place of prominence and I hope to pass this on to my children and their children at some point.

Coinbase S-1 5 years ago

Argentina is a great example. I am an American and have been there many times. They have extreme inflation and regressive policies against USD or foreign currency. Take a look at https://bluedollar.net. Official rates are buy at 89.98 and sell at 94.98 (ARS). Unofficial rates are buy at 138 and sell at 143. That's a massive spread saying that the people on the street are willing to spend 35% more because they know the Peso will eventually blow up and the USD is more stable which they can sell down the line for more ARS. This is sketchy in country. You might be walking a slightly illegal line. Possessing cash makes you a target for theft. Owning bitcoin makes this money transfer and storage of equivalent money easier.

I was/am a software engineer who had a wonderful opportunity to join a central security team at a very large internet company focusing on security engineering.

My recommendation on switching is to latch onto any SMEs in your company who you look up to, go to their classes and brown bags, research topics and make presentations to the company, be sure to include security decisions in your architecture designs, then once there's an opportunity in their team, you will be a natural choice for the team.

If there is an opportunity for your current product development team to be a Security Champion (i.e the person primarily responsible for security in your team and liaison to your security team for issues that you are unsure of), then jump on that if possible. Security Champions are a great way to dip your toes into security without having to go all in and also for your company to build a "bench" of talent. They can use this as a career lattice rather than a strict career ladder in the engineering org. Many companies are embracing this model as they grow because security folks are hard to find, hard to retain, and hard to scale as the engineering team grows.

I've always advocated it (whether you call it security by obscurity or not) simply because most of the scanners will not choose to pick any other port but 22, then systems like DenyHosts will provide higher fidelity about threats and less volume to pour over. Of course, whether you are on 22, 24, 2222, or whatever, you need to properly harden your sshd with certificates, ciphers, removing the unneeded/unsafe configuration parameters, etc., otherwise it just won't matter what port you are on.

There is a fantastic book that covers all of these topics and goes straight to the heart of the "nothing to hide" arguments both pro and con.

In fact, the book is titled "Nothing to Hide: The False Tradeoff between Privacy and Security" by Daniel J. Solove. I would highly recommend for those who are security and privacy conscious.

Shamir Secret Splitting divides a secret into M pieces requiring N parts to reconstitute. This does not absolutely prevent this attack, but requires collusion between attackers who are presumably trusted insiders, but trusted insiders can be compromised by blackmail, coersion, greed, or other angles.

The KMS autounseal is especially convenient, but you have to know that there is no silver bullet in crypto. You are trading off the convenience of the auto-unseal (and frankly, the fact that this can happen automatically in the middle of the night when your server reboots) against the security of your root unseal key itself.

The only thing protecting the unseal key is access to your KMS. So one rogue SRE can unseal the vault rather than requiring collusion of 1+ SRE members.

Again, this comes down to your risk tolerances and what you are protecting. I think for most workloads, the value KMS autounseal brings is worth the risk, but if you want to have tightest control, then the Shamir Split (M of N) is the best option.

I was fascinated when I crossed this story. The mechanics of driving a car aren't that hard once you've done it a couple of times, but to get the car started, into reverse, back up, into drive, navigate surface streets, accelerate onto the freeway (ok, he was going slow), change lanes into the "fast lane" etc... Pretty impressed. I was theorizing that maybe he had played car racing video games (hence the Lambo) and had enough of an understanding of distance perception and braking time not to kill himself. While this is a cute feel good story, that kid is really lucky not to be injured or worse.