Live data from Hacker News

Viewing profile — webvictim

webvictim

HN member
Joined
Thu, Mar 21, 2013, 10:30 PM UTC
HN karma
159
Public activity
53 items

About webvictim

Devops Engineer at https://goteleport.com

[ my public key: https://keybase.io/webvictim; my proof: https://keybase.io/webvictim/sigs/CpqUgeYKI_OlnkrSjacQxw1_-F6RgVvjHokfFR9f5II ]

Recent public activity

  1. comment
    Comment #25077508

    I genuinely thought the same thing. I opened my MBP and it was sluggish, felt like it was dead. Browser wouldn't load, Zoom wouldn't load, I rebooted and the same problems persiste…

  2. comment
    Comment #23796451

    The problems are very real if you work at any large organisation which has compliance requirements.

  3. comment
    Comment #23787299

    Setting all of that infrastructure up and subsequently maintaining it involves a considerable amount of time and knowledge. Some people just want a solution that's easy to deploy a…

  4. comment
    Comment #22793712

    Yes, even for very regular users I would recommend setting up a process requiring users to get a new certificate on a daily basis with a short validity period. You can automate a l…

  5. comment
    Comment #22793600

    It's something of an implementation detail - you don't generally specify the usage of certs on a user-by-user level, you do it by trusting the entire CA in /etc/ssh/sshd_config and…

  6. comment
    Comment #22760091

    Author here. My take on this is that fail-closed is a vastly better security model than fail-open. I am genuinely surprised that OpenSSH actually issues certificates with no expiry…

  7. comment
    Comment #22755344

    Author here - yes, this is why. I looked into Ed25519 and while there are a lot of great reasons to use it (such as a shorter key footprint and it being much quicker on mobile devi…

  8. comment
    Comment #22755310

    Don't get me wrong, using AuthorizedKeysCommand is a lot better than having a static ~/.ssh/authorized_keys file on a server, but it isn't anything like as powerful as using user c…

  9. comment
    Comment #22754686

    Having been on the rough end of this during a huge LDAP outage, I can confirm that LDAP is great until such time as it isn't.

  10. comment
    Comment #22754682

    This is definitely the premise of what I was going for with the post. I'm a firm believer in the idea that short-lived certificates which expire by default are one of the best ways…

  11. comment
    Comment #22754662

    Author here - thanks for the feedback. As another reply points out, I did try to also cover the use of a bastion host along with one form of 2-factor authentication. I'm considerin…

  12. comment
    Comment #22754492

    Author here. If you specify an IdentityFile then that’ll be tried first (as an explicit identity) but if that doesn’t work then by default, ssh-agent identities will be tried seque…

  13. comment
    Comment #22451146

    Maybe banners, artwork, bio, follow relevant accounts, make some starter tweets with popular hashtags to get some follows back, interaction with some key people. I wouldn’t pay for…

  14. comment
    Comment #19787345

    FYI, I was hired by Gravitational back in April 2018 and I was given that same take-home assignment as part of the interview process - to write a CNI plugin for k8s which created a…

  15. comment
    Comment #16000311

    The drain on the systems in Europe from those who are “gaming the system” and who are long term sick pales into insignificance when you consider the overall savings due to the coll…

  16. comment
    Comment #14967837

    https://www.quora.com/What-are-the-salary-ranges-of-each-lev... https://www.glassdoor.com/Salary/Google-Salaries-E9079.htm It seems similar to the way it was at Facebook in that wh…

  17. comment
  18. comment
    Comment #14300776

    Commits are a really terrible metric when it comes to measuring productivity for this exact reason.

  19. comment
    Comment #14286392

    My family weren't at all well off when I was growing up in the UK, but my Dad had some contacts in a local IT business who had a spare BBC microcomputer that he got hold of around …

  20. comment
    Comment #14286331

    The shorter way of expressing a similar sentiment is 'virtue signalling'.

  21. comment
    Comment #14286324

    Watch some early videos of Zuck and it'll be much more obvious. He's had a lot of training in public speaking and engagement and he's a ton better than he used to be now. I'm not s…

  22. comment
    Comment #13969721

    There are no companies which have such a policy, because it's illegal.

  23. comment
    Comment #12682581

    Collaboration has definitely got a lot better than it was years ago; FB has probably managed it better than anywhere I've worked before. The amount of money and effort they've inve…

  24. comment
    Comment #12682564

    Yes, it worked much better against the hum of the A/C units than the chatter.

  25. comment
    Comment #12680475

    Haha, thank you. My heritage is clearly given away by my phraseology :)