Viewing profile — pquerna
pquerna
HN member- Joined
- Fri, Aug 28, 2009, 1:07 PM UTC
- HN karma
- 2,879
- Public activity
- 408 items
- HN profile
- View on Hacker News ↗
About pquerna
formerly: ScaleFT CTO (acquired by Okta), cloudkick dude, rackspace racker. (yc w09, acquired dec 2010 by rackspace)
apache httpd hacker.
blog thing: https://paul.querna.org/
Recent public activity
-
comment
Comment #44588843
it's happening? "Ex-Intel executives raise $21.5 million for RISC-V chip startup": https://www.aheadcomputing.com/ I believe the founding team is all in Oregon - and mostly all ex-…
- story
-
comment
Comment #42252222
okta is not "active-active" in a multi-region sense, they run in a single active AWS single Region per-tenant. You can pay extra to have a faster failover in a region level failure…
-
comment
Comment #42024114
per https://trust.okta.com/security-advisories/okta-ad-ldap-dele... > 2024-07-23 - Vulnerability introduced as part of a standard Okta release This issue is not an "okta is old" is…
-
comment
Comment #41587899
Our app https://www.okta.com/integrations/conductorone/ > is in the Okta OIN ("marketplace") using OIDC? So not sure what you mean by that?
-
comment
Comment #41266600
This is an Eclipse foundation project, not an Apache Software Foundation (ASF) project? it's all volunteers/open source, but this isn't an ASF project.
- story
-
comment
Comment #40494288
What about "access controls" for the AuthZ side, instead of Permissions? Wondering HNs collective wisdom on this-- at work we've been using Access Controls on our homepage for awhi…
-
comment
Comment #39918026
For this general pattern implemented in Golang, check out redis_rate: https://github.com/ductone/redis_rate This fork also implements Redis Client Pipelining to check multiple limi…
-
comment
Comment #39046693
The API for Let's Encrypt to do this requires possession of the private key, which pwned keys doesn't always have. Sometimes they just have an "attestation" of compromise: https://…
-
comment
Comment #37299962
You can also just, Log the spans as they are being created to stderr/stdout -- I've done this on a previous project with this approach of "spans first". It made it debuggable via o…
-
comment
Comment #35285539
Yeah, but... shouldn't Github of rotated their keys over the last decade? I mean it seems like its clearly a key that wasn't in an HSM.. and over the lifetime, hundreds? Thousands …
-
comment
Comment #35285496
Would it of been possible for Github to use Host-key rotation instead of hard breaking it? https://lwn.net/Articles/637156/ I'm honestly not familiar with anyone actually using hos…
- story
-
comment
Comment #34983224
congrats on the launch! three questions / thoughts: 1) Your post mentions "Ranking", and while do the most impactful work first is great, the method I have most often used is when …
-
comment
Comment #33887579
Its cool to see the automation the kubernetes team stuff does against Github -- but has it been expanded to other resources, eg AWS or some other SaaS used? Other thought I had, is…
-
comment
Comment #33564659
thank you -- can't edit it anymore, but paul.querna (spelled my own name wrong)
-
comment
Comment #33557658
i've also been working on a similar tool -- working towards open sourcing it too. would you be interested in taking a look? paul.quenra at conductorone com
-
comment
Comment #33363095
This is how Okta's Advanced Server Access works: https://www.okta.com/products/advanced-server-access/
- comment
-
comment
Comment #30002050
hello. i added support for httpd to support systemd socket activation in 2013: https://svn.apache.org/viewvc?view=revision&revision=1511033 httpd can start as non-root, assuming ot…
-
comment
Comment #29259150
At a $previous_job I basically also did what the post is describing. The "best" thing we did was actually using a "template database": https://www.postgresql.org/docs/14/manage-ag-…
- story
-
comment
Comment #27008734
> In June 2012, he became an advisor and received options for shares in the company Sumo Logic, Inc. The next month, Kail authorized and signed on behalf of Netflix a vendor agreem…
- story