Viewing profile — bdesimone
bdesimone
HN member- Joined
- Tue, Mar 08, 2011, 10:46 PM UTC
- HN karma
- 271
- Public activity
- 97 items
- HN profile
- View on Hacker News ↗
About bdesimone
Recent public activity
- story
-
comment
Comment #45762199
Posting a coworker’s deep dive on the nuance of health checks that actually represent readiness. If you’ve had pods say "ready" while still failing traffic during rollouts, this wi…
- story
-
comment
Comment #45202022
FWIW, I'm very happy to see this announcement. Full MCP support was the only thing holding me back from using GPT5 as my daily driver as it has been my "go to" for hard problems an…
- story
- story
-
comment
Comment #44415788
Genuinely, didn't take it that way at all! I don't expect you to be an expert on Pomerium. > Funnily enough, Octelium started as a sidecar ext_authz svc for Envoy instances to oper…
-
comment
Comment #44415470
Quick note since it was mentioned. Pomerium does support Kubernetes at pretty much every level you mentioned (although I'm not entirely sure what a "a complete Kubernetes-tier plat…
-
story
Show HN: Pomerium Agentic Access Gateway – dynamic auth for AI agents
TL;DR: We are building a new Agentic Access Gateway in Pomerium to safely let AI agents (like GPT-based deep researchers, scripts or assistants) access internal apps and resources …
-
comment
Comment #22962173
Here's a collection of resources you might find helpful. https://github.com/pomerium/awesome-zero-trust/ Contributions/PRs very welcome.
-
comment
Comment #22469861
If you are interested in BeyondCorp-style access, I put together a collection of curated resources. https://github.com/pomerium/awesome-zero-trust PRs welcome.
-
comment
Comment #20656866
I agree that both can be used safely. And, yes to be clear, NMR here means "less likely to happen" not "better able to handle failure." Unfortunately, AES-GCM-SIV (or AEZ) aren't y…
-
comment
Comment #20656256
In the document they say that AES-CBC is vulnerable to padding oracle attacks, and AES-GCM uses random nonces and requires key rotation after so many iterations.
-
comment
Comment #20655895
> I see where this is coming and agree in spirit, but GCM is actually idiomatic Go and implemented through the crypto/aead interface, which does about as good a job as any library …
- comment
-
comment
Comment #8544320
Citizenship is already weird. My wife and I both being born in the US, we are tri-citizens and our descendants will also have tri-citizenship in perpetuity. It would have been quad…
- comment
-
comment
Comment #8104054
Yes. And you should probably assume that their claims of end-to-end encryption are about as solid as they were for iMessage. http://blog.cryptographyengineering.com/2013/06/can-app…
-
comment
Comment #8104012
In the very same doc you quote, they also say of iMessage: "Apple does not log messages or attachments, and their contents are protected by end-to-end encryption so no one but the …
-
comment
Comment #7702414
"Reopened on Novebmer 6" Is this an early draft?
-
comment
Comment #7471000
I am happy to vouch for William who has been driving the Miami meet ups. He knows his Go and is able to deconstruct rather tricky subjects and present them in a way that's easy to …
-
comment
Comment #7103254
I'm not suggesting prefixing.
-
comment
Comment #7102999
It's less complicated than what I'm reading here. * Use a passphrase of at least five random words.[1] * Keep that passphrases secret.[2] * Use a password manager like 1Password or…
-
comment
Comment #7050609
Agreed. Adds a bit of peer review to the mix.
-
comment
Comment #6931108
Edit2 = Damage control.