Live data from Hacker News

Viewing profile — bdesimone

bdesimone

HN member
Joined
Tue, Mar 08, 2011, 10:46 PM UTC
HN karma
271
Public activity
97 items

About bdesimone

Always happy to hear from folks bdd @ ${pomerium's website domain as you'd expect}

Recent public activity

  1. story
  2. comment
    Comment #45762199

    Posting a coworker’s deep dive on the nuance of health checks that actually represent readiness. If you’ve had pods say "ready" while still failing traffic during rollouts, this wi…

  3. story
  4. comment
    Comment #45202022

    FWIW, I'm very happy to see this announcement. Full MCP support was the only thing holding me back from using GPT5 as my daily driver as it has been my "go to" for hard problems an…

  5. story
  6. story
  7. comment
    Comment #44415788

    Genuinely, didn't take it that way at all! I don't expect you to be an expert on Pomerium. > Funnily enough, Octelium started as a sidecar ext_authz svc for Envoy instances to oper…

  8. comment
    Comment #44415470

    Quick note since it was mentioned. Pomerium does support Kubernetes at pretty much every level you mentioned (although I'm not entirely sure what a "a complete Kubernetes-tier plat…

  9. story
    Show HN: Pomerium Agentic Access Gateway – dynamic auth for AI agents

    TL;DR: We are building a new Agentic Access Gateway in Pomerium to safely let AI agents (like GPT-based deep researchers, scripts or assistants) access internal apps and resources …

  10. comment
    Comment #22962173

    Here's a collection of resources you might find helpful. https://github.com/pomerium/awesome-zero-trust/ Contributions/PRs very welcome.

  11. comment
    Comment #22469861

    If you are interested in BeyondCorp-style access, I put together a collection of curated resources. https://github.com/pomerium/awesome-zero-trust PRs welcome.

  12. comment
    Comment #20656866

    I agree that both can be used safely. And, yes to be clear, NMR here means "less likely to happen" not "better able to handle failure." Unfortunately, AES-GCM-SIV (or AEZ) aren't y…

  13. comment
    Comment #20656256

    In the document they say that AES-CBC is vulnerable to padding oracle attacks, and AES-GCM uses random nonces and requires key rotation after so many iterations.

  14. comment
    Comment #20655895

    > I see where this is coming and agree in spirit, but GCM is actually idiomatic Go and implemented through the crypto/aead interface, which does about as good a job as any library …

  15. comment
  16. comment
    Comment #8544320

    Citizenship is already weird. My wife and I both being born in the US, we are tri-citizens and our descendants will also have tri-citizenship in perpetuity. It would have been quad…

  17. comment
  18. comment
    Comment #8104054

    Yes. And you should probably assume that their claims of end-to-end encryption are about as solid as they were for iMessage. http://blog.cryptographyengineering.com/2013/06/can-app…

  19. comment
    Comment #8104012

    In the very same doc you quote, they also say of iMessage: "Apple does not log messages or attachments, and their contents are protected by end-to-end encryption so no one but the …

  20. comment
    Comment #7702414

    "Reopened on Novebmer 6" Is this an early draft?

  21. comment
    Comment #7471000

    I am happy to vouch for William who has been driving the Miami meet ups. He knows his Go and is able to deconstruct rather tricky subjects and present them in a way that's easy to …

  22. comment
    Comment #7103254

    I'm not suggesting prefixing.

  23. comment
    Comment #7102999

    It's less complicated than what I'm reading here. * Use a passphrase of at least five random words.[1] * Keep that passphrases secret.[2] * Use a password manager like 1Password or…

  24. comment
    Comment #7050609

    Agreed. Adds a bit of peer review to the mix.

  25. comment
    Comment #6931108

    Edit2 = Damage control.