HN user

twakefield

5,502 karma
Posts214
Comments217
View on HN
sendbird.com 1y ago

How does Sendbird secure AWS?

twakefield
1pts0
www.reuters.com 2y ago

Microsoft engineer's account led to Chinese hack of US officials

twakefield
4pts0
goteleport.com 3y ago

Getting Rid of Shared Secrets: The Major Design Flaw of All CI Systems

twakefield
2pts0
goteleport.com 4y ago

What You Need to Know About X11 Forwarding

twakefield
9pts0
goteleport.com 4y ago

Secure Bots and Service Account Access with Ephemeral Certificates

twakefield
1pts0
goteleport.com 4y ago

On Terminals and Sessions

twakefield
1pts0
goteleport.com 4y ago

Machine ID: Certbot for infrastructure access management

twakefield
1pts0
goteleport.com 4y ago

Why The “Four Eyes” principle is critical for access

twakefield
2pts0
goteleport.com 4y ago

Teleport 9 – Introducing Machine ID

twakefield
5pts0
media.fidoalliance.org 4y ago

Fido Addresses a Full Range of Use Cases [pdf]

twakefield
5pts0
coder.com 4y ago

Secure developer infrastructure with Teleport and Coder

twakefield
4pts0
www.downtime.dev 4y ago

Downtime.dev: hard-hitting news for when your code is compiling

twakefield
3pts0
goteleport.com 4y ago

Using Z3 Theorem Prover to Analyze RBAC

twakefield
3pts0
goteleport.com 4y ago

Using Z3 Theorem Prover to Analyze RBAC

twakefield
2pts0
goteleport.com 4y ago

Leave SSL in the Dust, Turbocharge TLS with ALPN and SNI

twakefield
2pts0
goteleport.com 4y ago

Why we chose HTTPS instead of RDP for remote windows access

twakefield
1pts0
goteleport.com 4y ago

Getting Rid of Passwords for Infrastructure

twakefield
2pts0
goteleport.com 4y ago

It’s time to get rid of passwords in our infrastructure

twakefield
2pts0
goteleport.com 4y ago

SSH Tunneling Explained

twakefield
363pts60
goteleport.com 4y ago

Anatomy of a Cloud Infrastructure Attack via a Pull Request

twakefield
80pts14
goteleport.com 4y ago

Kubernetes API Access Security Hardening

twakefield
2pts0
goteleport.com 4y ago

Securing Access to Your MongoDB Database

twakefield
1pts0
blog.crunchydata.com 4y ago

Postgres Full-Text Search: A search engine in a database

twakefield
601pts137
goteleport.com 4y ago

Preventing Data Exfiltration with eBPF

twakefield
2pts0
goteleport.com 5y ago

Teleport 6.0 Brings Identity-Aware Access to Databases Behind Nat

twakefield
1pts0
goteleport.com 5y ago

In Search for a Perfect Access Control System

twakefield
2pts0
goteleport.com 5y ago

SSH Certificates Security Hardening

twakefield
4pts0
goteleport.com 5y ago

Giving third parties access to your supercomputers

twakefield
3pts0
goteleport.com 5y ago

We Using Fuzzing

twakefield
1pts0
goteleport.com 5y ago

The Pitfalls of Language Runtimes and Multi-Tenant Services

twakefield
3pts0

There is a correlation analysis in Jamin Ball's "Clouded Judgement" substack [1] which shows the correlation between next twelve month ("NTM") Revenue Multiples and Revenue Annual Growth Rates for public market tech / SaaS stocks.

The current Slope-Intercept is (NTM Revenue Multiple) = 36.677*(NTM Rev Growth Rate) + 2.0013. If Wiz is doubling revenue (100% Growth Rate) and they are at about $500M of revenue today [2], then the multiple according to that calculation is ~38.7 X Next Twelve Month Revenue ($1B) or $38.7B.

So, the price is in line with the market...or you could argue even a discount to it.

[1] https://cloudedjudgement.substack.com/p/clouded-judgement-31... [2] https://www.barrons.com/articles/google-stock-price-wiz-deal...

Congrats! Seems like a Retool competitor but focused more on developers? I'm not sure if that's the direction I would go since developers already have pretty good tooling for their level of expertise, IMO.

Although, I could see how building an app that uses data across the various SaaS tools a company uses without requiring that data to be dumped into another database could be useful. Maybe I'm missing the point.

As an aside, I'd love to see Retool but for less technical people. Specifically, a way to make Google Sheets available for multiple people in a company to use. We have multiple quick and dirty "calculators" (think pricing for sales, comp for recruiting) that we roll out across our company. Eventually they get operationalized and converted into proper applications (or we buy a SaaS product for it) but would be nice to have an interim solution. Some requirements:

- Ability to create a very simple CRUD web UI

- Authz/n with ability for IT to integrate into their SSO.

- Google Sheets backend and integration so financial analysts can update and manage.

The 409(a) valuation is the value of the common shares. They are generally valued at a discount to the preferred shares (or company valuation) due to the fact that the preferred shares have a pay back preference and the common are considered less liquid. The discount is generally higher (70-80%) during the early stages of a company when a liquidity event is less certain and the discount decreases over time.

Teleport | Sr. Recruiter | Remote or Oakland HQ

Teleport (https://goteleport.com) is an open core software company that enables engineers to quickly access any computing resource anywhere.

We are hiring our first in-house recruiter. We need a full cycle recruiter to manage 50 engineering hires next year across the stack of (Go / Rust, React, Linux and Cryptography engineering), along with helping with Sales/Marketing hires.

Full job description: https://jobs.lever.co/gravitational/15325c7f-9d13-4d29-9951-...

There is a pretty simple feature that would alleviate a lot of pain with Stripe’s billing service when invoicing enterprises - allow for attaching a pdf of the invoice in the automated email.

Many enterprise A/P departments require it. The lack of this feature has prevented us from moving off our existing invoicing system to Stripe. I’m guessing we are not unique.

Dislaimer: I work at the company that makes Teleport.

Just to clarify, this blog post was about the updates in this release which include a lot of UI changes (particularly in the Web UI).

However, Teleport works with whatever UI you would typically use SSH with[0]. The WebUI is an additional "feature"; it's not the only user interface.

[0] The use of SSO is another feature that does generally require a browser based auth.

Are there non-PEO solutions to alleviate the administrative burden of having employees in many states? Keeping up with employment and tax compliance requirements is not trivial. Most HR systems (for smaller companies) I’ve seen still require the employer to register with each state. Might be a good startup idea.

Disclaimer: I work at Gravitational.

We build an open source solution[1] to deploy autonomous Kubernetes clusters into on-prem or air-gapped environments but it's also useful for limiting cloud lock-in (even has its own "IAM" built in). Of course, you have to also limit your use of proprietary services (which definitely has its trade-offs) but might be worth poking around if you believe reducing lock-in is worth it.

[1] https://github.com/gravitational/gravity

Author here. As an intro, this is admittedly high level but hope to get more in the weeds on how the two models compare and overlap in the next few posts. Happy to discuss some of my (or your) thoughts here in advance of those. Thanks for reading!

Matt Levine's take is this is due to fact that "private markets are the new public markets"[0]. The lines between public and private markets are blurring so this is a prudent move by A16Z.

TLDR;

As companies stay private longer, and get bigger and raise more money while staying private:

* The secondary market for private shares becomes more important.

* VC's now may have more asymmetric information or more reasons to invest in public markets.

* Mutual funds are competing with VCs in later private rounds so why should VCs be able to compete with Mutual Funds in public markets.

* The obligatory crypto reference.

Another one he doesn't touch on is maybe it's difficult to efficiently deploy > $10 billion in just private markets?

[0] https://www.bloomberg.com/opinion/articles/2019-04-03/buying...

“Also, learn how to evaluate what people are great at, and put them in those roles. (This is the most important thing I have learned about management, and I haven’t read much about it.)”

Finding and accentuating strengths was a big focus of my previous employer, Rackspace. They used a program based on Strengths Finder [1] to determine your “strengths” and even had them displayed on your corporate ID badge. Their management philosophy was based on putting people in positions based on their strengths.

It seemed a bit hokey at first and it had its problems but it was pretty refreshing compared to the typical corporate environment that espouses working harder to overcome your weaknesses.

[1] https://www.gallupstrengthscenter.com/

Gravitational (YC S15) | Multiple Positions | Toronto, Oakland | ONSITE REMOTE | https://gravitational.com

Gravitational builds open-core software to automate the delivery and operations of cloud-native software across multiple locations (multi-cloud and on-prem). We are looking for ambitious and talented people across engineering and go-to-market (sales/marketing). Here are some of the things we have built in the past: Mailgun[1], Vulcand[2], OnMetal [3]. And some of the things you will help us with currently: Teleport[4], Gravity[5], Teleconsole[6].

Open positions include:

  * Fullstack engineer (React expertise a +)
  * Head of marketing (demand gen, content marketing, dev evangelism and general growth)
  * Sales Development Reps (qualifying inbound and participating in outbound campaigns for handoff to sales reps)
Locations: Toronto, Oakland, Remote Open positions on our about page: https://gravitational.com/about#jobs

Contact: jobs@gravitational.com

[1] https://www.mailgun.com

[2] https://github.com/vulcand/vulcand

[3] https://www.rackspace.com/cloud/servers/onmetal

[4] https://github.com/gravitational/teleport

[5] https://github.com/gravitational/gravity

[6] https://www.teleconsole.com/

Gravitational (YS S15) | Multiple Positions | Toronto, Oakland | ONSITE REMOTE | https://gravitational.com

Gravitational builds open-core software to automate the delivery and operations of cloud-native software across multiple locations (cloud and on-prem). We are looking for ambitious and talented people across engineering and go-to-market (sales/marketing). We are well-funded and profitable. We are an experienced team: we founded Mailgun[1] which was acquired by Rackspace, we created Vulcand[2] and some other cool stuff at Rackspace and are authors of Teleport[3], Gravity[4] and Teleconsole[5]. Open positions include:

  * Front-end engineer (marketing focused, React expertise a +)
  * Head of marketing
Locations: Toronto, Oakland, Remote

Open positions on our about page: https://gravitational.com/about#jobs

Contact: jobs@gravitational.com

[1] https://www.mailgun.com

[2] https://github.com/vulcand/vulcand

[3] https://github.com/gravitational/teleport

[4] https://github.com/gravitational/gravity

[5] https://www.teleconsole.com/

Many companies offer mid to low four figure referral bonuses for referring candidates that are hired in hard to find fields like finance, engineering.

Perhaps you can pre-screen “long-tail”[1], high potential candidates and connect them with insiders.

You could give a portion of the insider’s referral bonus to the candidate to drive that side of the market.

Candidates don’t have to come out of pocket to incentivize training (if your candidates have a good chance of getting hired) as the insider will get paid by the company.

Different take on this idea. Maybe it already exists?

[1] edit: maybe not the right term of art here, but I mean under the radar candidates (non-ivy, good grades, good work ethic, etc.).

Maybe I'm missing the point of your comment but a typical reason for delivering an application on your customer's infrastructure is that they don't want their data to leave their infrastructure. It's usually b-to-b where the customer is typically an enterprise buyer using their own data storage. So, the customer knows how its data is being processed.

Point taken. I've struggled with this because we see these terms intermingled in practice.

This is probably because most of our customers (SaaS vendors) think of everything that is not traditional multi-tenant SaaS as "on-premise". Also, self-hosted does connote the customer's IT is running the application, where a lot of times we see the vendor running the application (just on customer infrastructure).

This post was inspired by "The Nightmare Letter: A Subject Access Request under GDPR" [0]. Which shows the potential scary consequences of subject access requests.

There's a lot of FUD around this topic. I've seen posts opinions ranging from "no big deal" to "this is actually good for U.S. SaaS" to "This is going to kill SaaS". It will be interesting to see how enforcement of the GDPR plays out.

At the moment, with Facebook transgressions in the news, the pendulum seems to be swinging towards privacy. We'll see how far it swings.

[0] https://www.linkedin.com/pulse/nightmare-letter-subject-acce...

"That sounds like a shitty excuse to just dismiss the whole thing as too hard"

Disclosure: I work at the company that published this post.

I read it differently (albeit, I have much more context). I read it as a cautionary tail that Kubernetes makes it easier to get in trouble if you don't know what you are doing - so you better have a deep knowledge of you stateful workloads and technology. Perhaps obvious to some, but still a good reminder when dealing with a well-hyped technology like Kubernetes.