HN user

rietta

2,546 karma

Building and breaking applications for 26+ years. MS in Cyber Security (formerly InfoSec, GaTech). Focused on practical security controls to prevent breaches. Lifetime OWASP.

Website: https://rietta.com/ Blog: https://rietta.com/blog/

[ my public key: https://keybase.io/rietta; my proof: https://keybase.io/rietta/sigs/uk2sEk4_TfZeNJ8ZwJN7VF1Ub-aLW_l8clAq-EbQ578 ]

Posts39
Comments654
View on HN
rietta.com 5mo ago

Protect Production SQL Databases from AI/LLM Agentic SQL Query Risks

rietta
1pts0
rietta.com 1y ago

Restoring Old Software for Child Learning Safety

rietta
85pts39
rietta.com 2y ago

The UniSuper/Google Lesson: Cloud Is Not a Backup

rietta
1pts0
rietta.com 5y ago

Development time is money, therefore I RAID

rietta
2pts0
news.ycombinator.com 5y ago

G Suite account recovery for cancer widow advice

rietta
15pts8
rietta.com 6y ago

AppSec as a Requirement in the Development Process

rietta
2pts0
rietta.com 6y ago

Ruby Gems Supply Chain Vulnerability

rietta
2pts0
rietta.com 6y ago

The Case for 2FA, Post Rest-Client Gem CVE

rietta
3pts2
rietta.com 7y ago

Git Protection from Repository Attacks in 15 Minutes

rietta
3pts0
rietta.com 7y ago

Are You Accidentally Storing Private Data in Plain Text?

rietta
4pts0
rietta.com 8y ago

Governor Deal, veto SB 315 - white hat researchers should be thanked not jailed!

rietta
2pts0
rietta.com 8y ago

Georgia SB 315, to Criminalize Security Threat Research, to Be Voted on Today

rietta
2pts0
rietta.com 8y ago

Georgia [US] Anti-Hacking Bill Dangerously Misses the Mark of Protecting People

rietta
1pts0
livestream.com 8y ago

Georgia House Committee Hearing on Computer Trespass Bill, SB 315 (56 Min Mark)

rietta
2pts1
politics.myajc.com 8y ago

Georgia bill might limit efforts to find internet security problems

rietta
3pts1
rietta.com 8y ago

Automate Security Scans with Continuous Integration

rietta
1pts0
rietta.com 8y ago

Equifax Missed Defense in Depth, Allowing a Massive Data Breach

rietta
2pts0
www.linkedin.com 9y ago

Why things cost what they cost

rietta
1pts0
rietta.com 9y ago

Troubling ISP Privacy Repeal: The Data Will Be Breached

rietta
1pts0
rietta.com 9y ago

Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

rietta
362pts134
www.inc.com 9y ago

How New York Is Pushing Companies to Do Much Better at Cybersecurity

rietta
4pts0
threatpost.com 9y ago

New Call to Regulate IoT Security by Design

rietta
2pts0
news.ycombinator.com 9y ago

Ask HN: How do you use the keyboard, including function keys, for real work?

rietta
2pts0
rietta.com 9y ago

28th Anniversary of the Morris Internet Worm

rietta
3pts0
www.youtube.com 9y ago

‘Thought Leader’ gives talk that will inspire your thoughts (2016)

rietta
1pts0
www.bbc.com 9y ago

Webcams used to attack Reddit and Twitter recalled

rietta
368pts239
gist.github.com 9y ago

Memorize the RSA algorithm as a song – mirrored as a Gist (circa 2000)

rietta
3pts2
rietta.com 10y ago

Calls to Ban Effective Encryption Continue Despite Data Breach Crisis

rietta
2pts0
rietta.com 10y ago

What Is an Abuser Story (Software)

rietta
7pts0
rietta.com 10y ago

U.S. Senate Bill Seeks to Ban Effective Encryption, Making Security Illegal

rietta
10pts0

I am so grateful that I bought my 128 GB ram kit in January of last year for my own 9950 upgrade. We just built my dad a 7000 series to replace his old AM4 (2017 build) and 32 gigs DDR five was nearly the same price at Micro Center that I paid last year. I was able to gift him an Nvidia 1060 discreet graphics card so that he could continue to run his two monitors. The newer motherboards have much less on board capability for that.

Little Free Library 5 months ago

We have one at the local park nearby. A neighbor also has one in her front yard. It's a really neat concept!

What is the best alternative that can run as a Docker image that mimics AWS S3 to enable local only testing without any external cloud connections?

For me, my only use for Minio was to simulate AWS S3 in docker compose so that my applications were fully testable locally. I never used it it production or as a middle ware. It has not sat well with me to use alternative strategies like Ruby on Rails' local file storage for testing as it behaves differently than when the app is deployed. And using actual cloud services creates its own hurdles of either credential sharing among developers and gets rid of the "docker magic" of being to run a single set up script and be up and running to change code and run the full test suite.

My use case is any developer on the team can do a Git clone and run the set up script and then be fully up and running within minutes locally without any special configuration on their part.

Anyone interested in keeping access should fork this open source repository now and make a local archived copy. That way when this organization deletes this repository there can still be access to this open source code.

In the Ruby on Rails space, we had this happen recently with the prawn_plus Gem where the original author yanked all published copies and deleted the GitHub repository.

On GitHub, when a private repo is deleted forks are deleted. But for public repos, the policy is different. See https://docs.github.com/en/pull-requests/collaborating-with-....

This is the latest of a sunset trap set for those of us who use Minio for local testing but not production use.

It was certainly popular enough to be included in the 4th-century Codex Sinaiticus, which is the oldest extant "complete" Bible (Genesis through Revelation) in a single bound volume. Interestingly, in that manuscript, The Shepherd of Hermas and the Epistle of Barnabas actually appear right after the New Testament. The library has published scanned copies online at https://www.codexsinaiticus.org/en/. It is an epic resource for anyone studying this history or textual criticism.

Spot on. The Criterion of Embarrassment is a powerful tool here; the fact that women were the primary witnesses to the resurrection is a classic example, given that a woman's testimony held little to no legal weight in 1st-century Roman or Jewish contexts. If you were inventing a myth to gain social traction, you simply wouldn't write it that way.

Your point about verisimilitude extends to Onomastics as well. Research shows that the New Testament Gospels accurately reflect the specific frequency of Jewish names in 1st-century Palestine. In contrast, Gnostic texts often use names that don't fit the era or geography, frequently showing 3rd-century Egyptian linguistic influences instead. It suggests the canonical authors had "boots on the ground" knowledge that the later Gnostic writers lacked.

This has been a source I’ve referred to on and off for years. It’s really interesting to read some things that don’t show up in our everyday Bible. Including things that were considered not canon by the early church. I enjoyed reading the translation of the Shepherds of Hermas. It was not the easiest to follow, but in a sense it was a very popular allegory like Pilgrim’s Progress was centuries later!

Demystifying DVDs 7 months ago

Extremely interesting read. I need to go back over it again in detail on my computer not just my phone while holding my baby.

A key theme in a future fiction I am writing (slowly) is that all digital data has been lost and the time we are in now is known as a digital dark age where little is known about our society and culture. Resurrecting an archeologically discovered DVD is a key plot point I am working through. That it will be the first insight into our time in over a millennium. Other conflicting interests will be finally succeeding at re-introducing corn at commercial scale after all hope had been lost and past attempts at re-germinating from the frozen seed bank had failed for hundreds of years. It's a work in progress.

We are loosing so many of the legends. I don't distinctly watching the Chronicles when it first aired - was too young, not in the right market - but as a computer history nerd watching the videos on the Internet has been eye opening. It is also a really good way to get a sense just how advancing things were in the 1980s and how in many ways we have gone backwards in many areas.

Very succinct, I agree.

I honestly have never heard anyone—even those executing it poorly—try to frame Servant Leadership the way the original author did here (the "curling parent" analogy).

I have certainly seen people fail badly at practicing this style, but that failure was invariably due to a lack of character, poor communication skills, or other individual execution matters, not an issue with the core concept of servant leadership itself.

I think the author is significantly straw-manning the concept of servant leadership.

The short take presented in the article doesn't match my lived experience with this style, both in secular and faith-based circles. The core idea is absolutely not that of a "curling parent." Instead, it embodies living the walk, walking the talk, and putting the team's needs before your own ego.

In fact, this profound concept goes all the way back to Jesus Christ, who modeled it by washing the feet of his disciples—a task reserved for the lowliest servant of the time. This act was deliberately shocking and context-defying. He effectively "turned the world upside down" by saying, "Anyone who wants to be first must be the very last, and the servant of all."

I'm not trying to proof-text, but this idea is ancient and deep. It's a profound leadership style that is unfortunately often executed poorly or misunderstood by modern practitioners. Poor execution doesn't invalidate the concept itself.

It was 2017 that I decided to go all in ensuring that my main work computers were built from parts sourced via the local Micro Center. The real eye-opening situation is even if I have a top line most expensive MacBook Pro or most expensive Dell laptop with full warranty, the truth is anytime there was a hardware issue which happened every 2 to 3 years it would destroy a day or more of work. you cannot have it fixed and returned to you the same day being able to have more redundancy in the ability to source individual parts locally is a gigantic financial benefit when you’re livelihood depends on a working high-performance systems as a high-end consultant. I also ensure that I have two laptops capable of running my work though neither perform as highly as my high-end gaming class workstation.

I too am very sad. This has been my brand of ram for a long time. I’m also more of a software guy than hardware, but I appreciate being able to have high-performance gaming class systems for my work. It runs circles around much of the stuff my colleagues run, including in deployment in various cloud environments.

This sucks! I know more about software than hardware. Crucial is the only ram I have bought for decades now. As a practical matter does this mean one needs to buy DDR5 ram now from MicroCenter for a build planned for next year? I just put 128gb into my latest Linux workstation. I had been planning to build a new NAS to replace my aging TrueNas (nee FreeNAS). I was just thinking about possibly building another dev box after being very happy with this AMD 9950x performance.

My informal use of private missed the mark in a strict legalistic sense. We are on the same page about email left on the server being subject to subpoena.

For everyone else, unless you use POP3 to download your email to your own personal device and remove it from the server, the email left on the server is not as protected under US law as emails that are fully downloaded to your device. The later requires a search warrant to acquire without your consent.

The practical short answer is yes, yes it will. It is not privileged communication. It is not considered private since you have left it on a third party server. It is discoverable via legal process to the third parties that retain the chat log.

The same goes for communications on any social media or public forum, including discussions here on HN.

I have started to come around to thinking that as a practical matter as an individuL, making sure things actually make it into an actual bona fide landfill and ate buried is the most ecologically friendly thing we can do. All the other alternatives seem to break down and end up with stuff either not being encapsulated and impacting the environment that way, or shipped off to other countries and ending up in the oceans.

We use grocery bags as trash bags for the small bathroom bins. Also to contain poopy diapers for sanitation purposes. The thicker plastic bags Kroger has uses for their pickup service are harder to use for this. Also are not being reused since they always use new bags with every order. I save the bags we don’t use and place them in the bin outside Publix or Home Depot. Ironically the Kroger drop off pin appears to have been removed.

I HATE short form videos with an abiding passion. As a user, my preference is long form YouTube videos I can listen to while my hands are busy with the dishes, dog walks, etc. I am ventured more into podcasts because even such videos are painfully annoying with ad interruptions that demand skip click. Under no circumstances do I want to interact with the device every 60-90 seconds. That totally defeats the purpose of listening while being productive in the day.

Purposeful animations 11 months ago

Yells at cloud with visions of Windows 98 menu slide out animations stuttering on the barely good enough for the new OS pc! ;-p