Live data from Hacker News

Viewing profile — kkl

kkl

HN member
Joined
Sat, Jul 12, 2014, 12:02 AM UTC
HN karma
491
Public activity
103 items

About kkl

he/him

https://kel.bz

https://argemma.com

Recent public activity

  1. comment
    Comment #47903350

    SSH CAs are not incompatible with my argument! An SSH CA can sign short-lived certificates for just-in-time generated keys.

  2. comment
    Comment #47903270

    > "we can't have service accounts" To be clear: This is not my position! I advocate for service accounts in my post: > It is much harder to reason about, say, the security of an ar…

  3. comment
    Comment #47898108

    Part of the threat model for an Engineering team is that people come and go. They move teams which have different levels of access. They leave the organization, in most cases, on g…

  4. story
  5. story
  6. comment
    Comment #47446984

    > "Had the engineer that acted on that known better, or did other checks, this would have been avoided." takes long drag tweet[1] here> I personally find "LLMs can do $THING poorly…

  7. comment
    Comment #47415814

    > The job of a code reviewer isn't to review code. It's to figure out how to obsolete their code review comment, that whole class of comment, in all future cases, until you don't n…

  8. comment
    Comment #47415337

    It’s also the case that someone you trust makes an honest mistake and, for example, gets their laptop stolen and their credentials compromised. I do trust my team, and want that to…

  9. comment
    Comment #47155322

    Congratulations! Fish is such a wonderful shell. It’s been my daily driver for many years now but I’ve had a renewed appreciation for it now that I’m working in several different d…

  10. comment
    Comment #47153889

    I could also buy that the free domains were ran up by scammers which could have caused some of the hair trigger Safe Browsing denylisting.

  11. comment
    Comment #47097359

    While there are compliance/security benefits it is not the primary motivation. If you have fairly complicated infrastructure it can be way more efficient to have a pool of ready to…

  12. story
  13. story
  14. story
  15. story
  16. story
  17. story
  18. story
  19. story
  20. comment
    Comment #13675843

    Losing control of your actual phone is not the same as losing control of your phone number. I'm not sure about Microsoft, but Google supports several other 2FA mechanisms in additi…

  21. comment
    Comment #13370985

    I think this is true of "Second Wave" black metal bands but less true of more recent output.

  22. comment
    Comment #13115741

    What properties does email have that asynchronous messaging services (e.g. Signal) do not?

  23. comment
    Comment #13115676

    Signal does have a desktop application. I believe you can also register a Signal account using a phone number from a service like Twilio. I'm not 100% sure that will work with Sign…

  24. comment
    Comment #13115114

    Most interesting e2e projects have abandoned email, specifically SMTP, as a secure messaging platform. I would look outside SMTP-based solutions if I were to start using a differen…

  25. comment
    Comment #13081499

    Praetorian | Security Engineer | Austin, Texas | REMOTE (For principal and staff positions) Praetorian is different. We are a collective of highly-technical engineers focused on he…