Live data from Hacker News

Viewing profile — pquerna

pquerna

HN member
Joined
Fri, Aug 28, 2009, 1:07 PM UTC
HN karma
2,879
Public activity
408 items

About pquerna

Now: ConductorOne CTO & Co-Founder https://www.conductorone.com/

formerly: ScaleFT CTO (acquired by Okta), cloudkick dude, rackspace racker. (yc w09, acquired dec 2010 by rackspace)

apache httpd hacker.

blog thing: https://paul.querna.org/

Recent public activity

  1. comment
    Comment #44588843

    it's happening? "Ex-Intel executives raise $21.5 million for RISC-V chip startup": https://www.aheadcomputing.com/ I believe the founding team is all in Oregon - and mostly all ex-…

  2. story
  3. comment
    Comment #42252222

    okta is not "active-active" in a multi-region sense, they run in a single active AWS single Region per-tenant. You can pay extra to have a faster failover in a region level failure…

  4. comment
    Comment #42024114

    per https://trust.okta.com/security-advisories/okta-ad-ldap-dele... > 2024-07-23 - Vulnerability introduced as part of a standard Okta release This issue is not an "okta is old" is…

  5. comment
    Comment #41587899

    Our app https://www.okta.com/integrations/conductorone/ > is in the Okta OIN ("marketplace") using OIDC? So not sure what you mean by that?

  6. comment
    Comment #41266600

    This is an Eclipse foundation project, not an Apache Software Foundation (ASF) project? it's all volunteers/open source, but this isn't an ASF project.

  7. story
  8. comment
    Comment #40494288

    What about "access controls" for the AuthZ side, instead of Permissions? Wondering HNs collective wisdom on this-- at work we've been using Access Controls on our homepage for awhi…

  9. comment
    Comment #39918026

    For this general pattern implemented in Golang, check out redis_rate: https://github.com/ductone/redis_rate This fork also implements Redis Client Pipelining to check multiple limi…

  10. comment
    Comment #39046693

    The API for Let's Encrypt to do this requires possession of the private key, which pwned keys doesn't always have. Sometimes they just have an "attestation" of compromise: https://…

  11. comment
    Comment #37299962

    You can also just, Log the spans as they are being created to stderr/stdout -- I've done this on a previous project with this approach of "spans first". It made it debuggable via o…

  12. comment
    Comment #35285539

    Yeah, but... shouldn't Github of rotated their keys over the last decade? I mean it seems like its clearly a key that wasn't in an HSM.. and over the lifetime, hundreds? Thousands …

  13. comment
    Comment #35285496

    Would it of been possible for Github to use Host-key rotation instead of hard breaking it? https://lwn.net/Articles/637156/ I'm honestly not familiar with anyone actually using hos…

  14. story
  15. comment
    Comment #34983224

    congrats on the launch! three questions / thoughts: 1) Your post mentions "Ranking", and while do the most impactful work first is great, the method I have most often used is when …

  16. comment
    Comment #33887579

    Its cool to see the automation the kubernetes team stuff does against Github -- but has it been expanded to other resources, eg AWS or some other SaaS used? Other thought I had, is…

  17. comment
    Comment #33564659

    thank you -- can't edit it anymore, but paul.querna (spelled my own name wrong)

  18. comment
    Comment #33557658

    i've also been working on a similar tool -- working towards open sourcing it too. would you be interested in taking a look? paul.quenra at conductorone com

  19. comment
    Comment #33363095

    This is how Okta's Advanced Server Access works: https://www.okta.com/products/advanced-server-access/

  20. comment
  21. comment
    Comment #30002050

    hello. i added support for httpd to support systemd socket activation in 2013: https://svn.apache.org/viewvc?view=revision&revision=1511033 httpd can start as non-root, assuming ot…

  22. comment
    Comment #29259150

    At a $previous_job I basically also did what the post is describing. The "best" thing we did was actually using a "template database": https://www.postgresql.org/docs/14/manage-ag-…

  23. story
  24. comment
    Comment #27008734

    > In June 2012, he became an advisor and received options for shares in the company Sumo Logic, Inc. The next month, Kail authorized and signed on behalf of Netflix a vendor agreem…

  25. story