HN user

yfiapo

155 karma
Posts0
Comments28
View on HN
No posts found.

I agree this was a security concern and it was reported and addressed appropriately. With that said as things go this is pretty minor; perhaps a medium severity issue. Information disclosures like this may be leveraged by attackers with existing access to the lower environment, in conjunction with other issues, to escalate their privileges. By itself, or without the existing access, it is not usable.

More over, the issue wasn’t that AWS recommended or automatically setup the environment insecurely. Their documentation simply left the commonly known best practice of disallowing trusts from lower to prod environments implicit, rather than explicitly recommending users follow that best practice in using the solution.

I don’t think over-hyping smaller issues, handled appropriately, helps anyone.

We're not done with our request payload yet! We sent:

Host: neverssl.com

This is actually a requirement for HTTP/1.1, and was one of its big selling points compared to, uh...

AhAH! Drew yourself into a corner didn't you.

...Gopher? I guess?

I feel like the author must know this.. HTTP/1.0 supported but didn't require the Host header and thus HTTP/1.1 allowed consistent name-based virtual hosting on web servers.

I did appreciate the simple natures of the early protocols, although it is hard to argue against the many improvements in newer protocols. It was so easy to use nc to test SMTP and HTTP in particular.

I did enjoy the article's notes on the protocols however the huge sections of code snippets lost my attention midway.

This feels akin to excessively auto-completing shells to me. It is pretty awesomely quick when you are starting, but it feels like it has to impact learning/muscle memory which gives you the accuracy and speed in the long-term. Maybe just the bias from learning without these things but I can't shake the feeling.

I don't know if this is everyone's reasons but for me it is:

- it does too much. doesn't follow the Unix norms of doing one thing and doing it well. things like DNS resolution, time sync, etc all exist as systemd components.

- complexity - similar to doing too much but also just that it is no longer easily inspected and understood imo.

- participates in the Linux cycle of reinventing the wheel, excessively. Linux distros felt like they were changing their service management commands every other release for a while.

- breaks compatibility with BSDs.

I'm sure it solves real problems for real people.. but I don't like it.

The article you linked is from five years ago when the new badges were being initially tested. They have been rolled out for years with color photos. Both styles still work and if you don't go into one of a few big offices you might not have easy access to the newer style.

I was diagnosed with ADHD almost twenty years ago as a young adult. In my experience learning about how your mind works and spending time to come up with the best system and techniques to keep yourself on task is absolutely critical and should be worked on by any adult with ADHD. I would say that long-term it is more important than medication.

With that said, medication is also quite helpful. In my experience it provided a quick and independent support to my feeling better and productive. I found them critical when the controls I had built for myself proved insufficient or had collapsed. For example, when I moved from an office job to remote work I found the change and the lack of societal pressure to be focused on work left me in disarray. Medication helped me stand myself back up and find the routines and structures that worked in the new environment. As I built these support structures up I found the need for medication was reduced and stopped taking medication for many years. Years later, after a cross-country move which came with the loss of local friends and community I found it necessary to restart. I prefer to not take medication unnecessarily so one day I may be at the point where I stop taking them again, but I'm not there yet.

My advice would be to try medication if your gut says you need it but if you already feel fairly happy and productive then it may not be necessary.

Ah, but there is so much value in fresh eyes. Miod, who has been involved with OpenBSD development for 20 years and has surely seen those function names a thousand times, provided the historical reason (they thought they might need to allocate memory) but agreed they never ended up using that.

The fresh eyes don't have the history and are thus able to point things out that the older eyes inherently accept.

That's neat to see. This may not be a big story but as a fan of OpenBSD who doesn't currently have time to read the CVS log I appreciate it.

OpenBSD source is one of the cleanest I've had the pleasure to work with. You (generally) won't be scoffed at for submitting a semantic change like this, fixing typos, or the like. It certainly isn't perfect but the bar feels higher than elsewhere. Clean code and as importantly the documentation kept in sync.

Thank you for even trying to answer my rambles! :-)

I think my contention with the iron is the tipping point and how quickly it goes. Pop-sci tv makes it seem like you fused a single iron atom and bam. Maybe it is you fused an iron atom and it is like a day, a year or a thousand years and that adds up; still bam in terms of cosmic timelines but it is not what I hear when I listen and hear "instant collapse".

Thank you for the thoughts on dark matter and energy as well, and the link on radiation pressure, I will read it.

I'm sure there are great explanations out there but I haven't had time to read up on them, but a few of the space things that always bother me when I watch pop-sci space tv:

- "as soon as iron starts to be produced in the core of a star it instantly collapses" - I get that fusing iron costs energy rather than produces it and this causes a collapse.. but can it really be that quick? There are other fusion reactions that are still producing energy, right?

- dark matter / energy - I understand we have observations that indicate there is some type of matter we can't see but it feels a lot like saying "magic" or "the ether".

- how different size stars form - if there is a critical mass where a star "ignites" and after igniting starts pushing away from itself with the energy being produced, how do we get stars of such varying masses? Like, why didn't this 100x solar mass star start fusing and pushing the gases away before they were caught in its gravity? Do the more massive stars ignite on the same schedule but continue to suck in additional matter anyway, gravity overcoming the solar wind?

Cool that there are some specialty tools in this space and will use if I hit that performance challenge.

Minor nit, I found the performance table (https://github.com/eBay/tsv-utils/blob/master/docs/Performan...) confusing at first and second glance. Alternating colors indicate.. different OSes? That doesn't seem to be the important message to convey as you are trying to show the speed of your tool and not the OS. Recommend to use the coloration to provide differentiation between tools instead of OS.

I'm sure that will be the case for certain companies. For companies who routinely deal with PII, PCI, or other regulated data the security teams are likely to be much more worried about the potential for sensitive data to be inadvertently shared outside of the company. Even if it is communiques about only business sensitive matters (e.g., iPhone 12 XXL release) that is not something very security conscious companies will be happy having in the hands of a third-party without an appropriate security review.

Having run a security program at such a company, at the minimum I would expect a SOC 2 or ISO 27001 audit of your company before I would allow my company to utilize your services as it is tightly integrated to our internal communication platforms.

This isn't to say you need that now but you should understand there are segments of the potential customer base that will not work with you without being able to pass that level of scrutiny.

I've worked for a company with a whale client like that (maybe not total shutdown bad but pretty close). The argument for why they never bothered to just acquire the startup was their fear of ruining the agility of the startup. That seemed like a reasonable concern as they were a massive, heavily regulated company.

Hmm, I'm straining my own analogy already so I won't try to beat that horse any deader. :-) I am mostly trying to argue the positives of centralized inspection at network chokepoints in simplicity and guarantee of coverage.

I don't work for a bank so I can't speak definitively to their applications. A few sample applications I see listed as certificate pinned in Netskope (a CASB) though include:

  Adobe Creative Cloud
  Amazon Work Spaces
  Docusign
  GitHub
  Google Drive
  GoToMeeting
  iCloud
  Microsoft Office 365 Outlook.com
  Microsoft Skype for Business
  Salesforce.com
Note this typically refers to native applications and plugins which also connect over TLS and not web applications.

The other side of the argument is frequently discounted and as an IT security person myself I understand that. However, there is a real challenge for companies who deal with large amounts of very sensitive data. To be able to effectively monitor for data loss it makes a lot of sense to be able to monitor the connection points between your protected network and outside networks. The move to all traffic being encrypted and uninspectable breaks this paradigm.

You can cover some of the same concern by implementing an agent on every connected computing device but this brings much greater complexity as you are monitoring potentially hundreds to thousands more places and still have to worry if you have complete coverage.

Consider an analogy of going through international customs. Do you employ customs officials at the border who are allowed to sample and inspect private belongings to verify laws are being followed? Or do you employ an official to help pack the belongings of each individual who you think may eventually cross the border? The second example is a bit stretched but hopefully illustrates the scale problem.

I've submitted many such small corrections to OpenBSD to help keep that standard high. No one will place those contributions on the same level as real development but I like that I've helped. And I know I appreciate it when even the documentation is kept at the same bar.

One of the reasons I fell in love with OpenBSD was the commitment to correctness throughout the entire system. This is a lot harder with Linux because they only control the kernel and not the entire distribution.

Yeesh, the mindwash is strong. I had a hard time continuing to read this post after the Prestige by Association section. Working at a respected company known for cutting edge work is generally a good sign but it does not make you an Internet God or widen my eyes.

It is like saying you went to Harvard or MIT. That's neat. You are probably reasonably intelligent. However, even that isn't an automatic and I'll reserve judgement until I've made my own assessment.