Live data from Hacker News

Viewing profile — raesene4

raesene4

HN member
Joined
Tue, Aug 26, 2014, 5:52 PM UTC
HN karma
267
Public activity
96 items

About raesene4

Security tester, general security type, being doing this kind of thing for 15-20 years in a variety of places. one of several raeseneX accounts for different devices I have :)

Recent public activity

  1. comment
    Comment #11353958

    Good article even though I don't agree with all the conclusions. I find a good way to think about things is that every single dependency you have adds another set of people you hav…

  2. comment
    Comment #11352856

    This is v.cool, although for the Windows version it'd be great if it became possible to swap out the virtualization back-end so it's not tied to Hyper-V. At the moment VMWare Works…

  3. comment
    Comment #11345845

    for NPM? As far as I'm aware it's not even an available feature. None of rubygems/PyPi/NuGet require digital signatures... What repositories were you thinking of that do require th…

  4. comment
    Comment #11345718

    A big problem with Software repositories that don't allow for /enforce cryptographic signing by the developer is that this can happen... Ideally the developer would sign before pub…

  5. comment
    Comment #11342859

    Most of the programming language Package managers that I've seen either don't have the facility or it's not widely used.

  6. comment
    Comment #11259404

    Yep, at the moment, with raw docker engine, if a user has access to create containers, they're basically able to get root on the box, as the docker daemon runs as root and there is…

  7. comment
    Comment #11258960

    With 1.10 you can just enable User namespaces, which allows for root in a container to map to a non-privileged user outside the container, that way it's a one-time (per instance) c…

  8. comment
    Comment #11258793

    I'd say that it's a trade-off whether you think the enhanced isolation provided by containerization/virtualization is more of a security benefit than the risks posed by the increas…

  9. comment
    Comment #11258213

    Good presentation. One thing I'd mention is that they talk about the CIS security guide, but it's currently pretty out of date as it covers 1.6 and therefore misses a lot of Docker…

  10. comment
    Comment #11110553

    Interestingly that's not the cases everywhere in the UK. for example Dumfries and Galloway saw a 10% drop in property prices last year...

  11. comment
    Comment #11110526

    Whilst other areas are expensive London it totally in a league of it's own. Edinburgh (most expensive part of scotland) average property price £234k. London, average property price…

  12. comment
    Comment #11108609

    have you tried using something like https://gethttpsforfree.com/ as a front-end to the Lets encrypt process?

  13. comment
    Comment #11103865

    well whilst hardware tokens are not always the right answer, there are good reasons to resist their replacement with things like "SMS 2FA" which isn't really 2FA at all ,as you hav…

  14. comment
    Comment #11103161

    FWIW, I saw that ad. Looks very interesting, but I think you may have a challenge getting someone who is a Vuln researcher/pen tester type (who most commonly have CVEs, PoCs to the…

  15. comment
    Comment #11103035

    Yep the customer fraud guarantee is a thing in the UK as well (at the moment), and to an extent that minimizes the loss where it's one customer's app. that gets compromised. Where …

  16. comment
    Comment #11102919

    I wonder why you got downvoted for this, for me security is a key concern for the challenger banks. What Mondo is (from my reading) trying to do is very cool but quite ambitious. A…

  17. comment
    Comment #11088583

    you are kidding right? the commands needed are right there on the docker hub page https://hub.docker.com/_/postgres/

  18. comment
    Comment #11087835

    any particular reasons you don't trust Docker security?

  19. comment
    Comment #11087833

    Your comment relates more, I think, to the general Docker project than subuser specifically. The answer to your question is that it all depends on your definition of "easier". dock…

  20. comment
    Comment #11087806

    FWIW I think this is pretty cool. The main docker use-case is not desktop software, and some of it's choices are unlikely to suit that use-case well. So, good to see a project look…

  21. comment
    Comment #11087791

    That's essentially what Docker hub already is. you can do docker pull postgres and get a postgres service which runs in a container.

  22. comment
    Comment #11087772

    You may be thinking of the lack of user namespacing in Docker. Until v1.10 root in a container was the same user as root outside the container. This did not automatically lead to a…

  23. comment
    Comment #11081496

    yeah it's super useful, nice interface and all the docs are hosted on S3 which is interesting...

  24. comment
    Comment #11080135

    there are two excerpts from their financial accounts in there if that makes you any happier (and justifies my use of the plural :) one from the P&L and one from the staffing sectio…

  25. comment
    Comment #11080078

    from http://www.musicbusinessworldwide.com/ouch-soundcloud-losses... definitely not profitable at the time of those accounts