Live data from Hacker News

Viewing profile — ptcrash

ptcrash

HN member
Joined
Sat, Jun 13, 2020, 9:49 PM UTC
HN karma
197
Public activity
52 items

About ptcrash

aspe:keyoxide.org:OHWUKGD35YMACG2RFR5VTOZCSA

Recent public activity

  1. comment
    Comment #42446985

    Happy to see the effort! Fresh blood in the authn space is always welcomed. Without rehashing the other good points commenters have made already, I’ll just say that every project s…

  2. comment
    Comment #42024035

    I think it's more of a logic problem. I suspect the engineers made a false assumption that bcrypt can hash a trivial amount of data like some other hashing algos.

  3. comment
    Comment #42024027

    If you want to validate a username/password authn attempt against a cache, then yes the username and password have to be someone in the mix.

  4. comment
    Comment #39803062

    Yes but PIV/CAC identity is not related to break-glass passwords. They both serve different purposes and it's safe to assume that the typical government worker will only ever need …

  5. comment
    Comment #39659281

    Ignoring obvious flame-bait, it sounds like the termination was an amicable feeling then, yeah?

  6. comment
    Comment #39098941

    Would you care to share for those of us who haven’t written a grant application before?

  7. comment
    Comment #37827091

    Both situations seem possible. I guess time will tell how Unity wants to move forward. Others mentioned it earlier but it looks like Godot had a big boost in users from this fiasco…

  8. comment
    Comment #37827064

    Well, the transition in leadership is uncommon but they don’t officially give us a reason, so we’re left to speculate until someone inside gives us more info. But from a purely spe…

  9. story
  10. story
  11. comment
    Comment #34005026

    Non-paywall link: https://web.archive.org/web/20221215195859/https://www.washi...

  12. comment
    Comment #33948563

    Same here. I also switch to light mode when I'm in a very bright environment and it seems to have helped a lot with eye strain since last year. I feel like these studies are being …

  13. comment
    Comment #33945085

    I'd argue it's because the risk is not worth the reward. Pingback and Trackback is used to send a monsoon of spam and I'd wager site maintainers are not too keen on enabling the ne…

  14. comment
    Comment #33945051

    I've read through the spec along with the FAQ that epeus so graciously shared here. The idea of mentioning beyond the scope of one website's walled garden seems like a very natural…

  15. comment
    Comment #33759481

    Is this a new iteration in fail2ban? I gave it a cursory look and I couldn’t find any new features that make it a better tool than its predecessor

  16. story
  17. story
  18. comment
    Comment #33460459

    It's not just arcane it's a horrible idea from an infosec perspective. Thinking about all my wonderful developers having local trusted root CAs just sitting on their hard drives is…

  19. comment
    Comment #33100437

    I didn’t know what NeRFs were so I had to look it up. This article seems like a good introduction for anyone else that’s out of the loop like me: https://www.matthewtancik.com/nerf…

  20. comment
    Comment #30693657

    I think it's neat to see company's like VMWare try to amalgamate containerization into their portfolio. Tanzu is like all the cons of on-prem like inelasticity applied to K8s

  21. comment
    Comment #30693600

    I don't have an easy answer for you because I'm still struggling to find the "proper" solution myself. That's why I'd kill to have the agencies weigh in. I'm not a fan of SealedSec…

  22. comment
    Comment #30693216

    The guideline was updated this month but released last year. That dupe link probably has a lot of relevant discussion.

  23. comment
    Comment #30693195

    One of the most common misconfigurations I've seen is improper secrets handling. I'm glad to see it called out but I wish they would go into a little deeper detail on detection and…

  24. comment
    Comment #30693141

    Yes. While many agencies have a bad reputation post-Snowden, CISA and NSA have for many years - and will continue to release hardening guides that are invaluable to security engine…

  25. story