HNHacker News
TopNewBestAskShowJobs

Artemis2

5,344 karma · joined September 4, 2013

Founder of ProcessOut (https://processout.com).

l@processout.com

submissionscomments
Artemis2··on Steve Singh stepping down as Docker CEO
Xerox PARC!
Artemis2··on Stripe Acquires Touchtech
You’d still have to handle the complete flow for the case where the exemption has been used multiple times since the last authentication though.
Artemis2··on Ghidra source code officially released
https://news.ycombinator.com/item?id=19315273
Artemis2··on Luarocks.org Security Incident March 2019
Very serious handling of the issue!
Artemis2··on Notes on the Amazon Aurora Paper
CockroachDB is made up of several layers to implement SQL and transactions on top of a distributed key-value store: https://www.cockroachlabs.com/docs/stable/architecture/overv...

TiDB has a similar architecture: https://www.pingcap.com/docs/architecture/

Artemis2··on Facebook is the worst thing that's ever happened to the internet
Unfortunately, with trackers such as the Like button embedded in every web page and shadow profiles, social media is definitely not opt-in.
Artemis2··on Removing Coordinated Inauthentic Behavior from Russia
“Coordinated Inauthentic Behavior” is a nice euphemism!
Artemis2··on Design Considerations for High-Throughput Cloud-Native RDBMS [pdf]
There is also a series of posts regarding the design of Aurora on the AWS blog, although about everything is described in the original paper:

https://aws.amazon.com/blogs/database/amazon-aurora-under-th...

https://aws.amazon.com/blogs/database/amazon-aurora-under-th...

https://aws.amazon.com/blogs/database/amazon-aurora-under-th...

https://aws.amazon.com/blogs/database/amazon-aurora-under-th...

Artemis2··on FoundationDB Record Layer
DynamoDB with strong consistency turned on works pretty nicely for us.
Artemis2··on FoundationDB Record Layer
This is powering CloudKit. Very cool!
Artemis2··on Road Tripping Around Europe in a Tesla Is Less Fun Than You’d Think
Most payment gateways offer a card fingerprinting feature. Here’s Stripe’s: https://stripe.com/docs/api/cards/object#card_object-fingerp....

It’s fine with PCI DSS as long as it is not reversible.

Artemis2··on How to dump 3000 pounds of confetti on Times Square
> The confetti thrown at midnight is made from recycled material that would otherwise be discarded, and all of it is biodegradable.
Artemis2··on Electron 4.0.0
⌘+F “performance” or “memory” does not show anything :-/
Artemis2··on Going Head-To-Head: Scylla vs. Amazon DynamoDB
Quorum reads will always be much faster in the same AZ :-(
Artemis2··on Going Head-To-Head: Scylla vs. Amazon DynamoDB
> The global reservation is divided to multiple partitions, each no more than 10TB in size.

I think this should be 10GB partitions.

By the way, maybe it’s worth mentioning adaptive capacity? https://aws.amazon.com/blogs/database/how-amazon-dynamodb-ad...

Artemis2··on Google May Have to Get Used to Third Place in the Cloud
Caused by a bad BGP route announcement [1]; this is outside of the control of Google. However, they do seem to have global incidents more often than the competition (for example [2] last July)

1: https://status.cloud.google.com/incident/cloud-networking/18...

2: https://status.cloud.google.com/incident/cloud-networking/18...

Artemis2··on October 21 post-incident analysis
That’s not it, but I really like Whimsical (https://whimsical.co) to produce great-looking diagrams.
Artemis2··on Ask HN: What are some of the tech blogs you follow regularly?
Good addition! Here are some more:

https://ferd.ca

https://blog.filippo.io

https://lethain.com

http://movingpackets.net

https://www.integralist.co.uk

https://peter.bourgon.org/blog

https://engineering.linkedin.com/blog

https://begriffs.com

https://mijailovic.net

http://tatiyants.com

http://blog.pentestbegins.com (seems down right now?)

https://kalzumeus.com/archive

http://blog.stephenwolfram.com

https://paragonie.com/blog

https://www.filfre.net

https://brandur.org/articles

http://archagon.net

https://eklitzke.org

I guess I could go on forever…

Artemis2··on Ask HN: What are some of the tech blogs you follow regularly?
Some favorites of mine I haven’t seen mentioned:

https://blog.acolyer.org

https://jvns.ca

https://stratechery.com

https://blog.cloudflare.com

https://latacora.singles

https://www.schneier.com

https://www.ben-evans.com

plus an endless amount of newsletters…

Artemis2··on AWS Service Operator for Kubernetes Now Available
Do you mean OpenShift?

https://www.openshift.com

Artemis2··on Ask HN: What podcasts do you listen to regularly?
99% Invisible, Planet Money are good.
Artemis2··on Refreshing Plaid's brand
I learned a new word today!

https://en.wikipedia.org/wiki/Guilloché

Artemis2··on Break another CTF by taking over its machine
I cannot overstate how much I despise these “helpful” cloud agents. They are useful for experimentation to update user accounts (SSH keys, etc. — GCP uses for its web shell as well), but they are a nightmare for production use. They are a very straightforward path from cloud account compromise to instance takeover.

Azure pulls the same trick. AWS seems fine.

Artemis2··on Very Good Security
Thanks for the detailed reply! There is indeed a lot to do with authentication/authorization (and things like audit logging…). I’ll look more at EnvKey later to understand the cryptography better.

Stripe/other gateways do abstract most of PCI DSS from you, and will not return card data via API calls, so that somewhat sidesteps the compliance issue.

Artemis2··on Very Good Security
Looks cool! I can very much appreciate progress in this space. I haven’t been able to find this info by skimming the website: while I understand that the user ultimately holds the keys that can decrypt the secret, how do you prevent this key from becoming the weakest link? Assuming the worst, users could just store their key where they used to store their secrets before EnvKey (like app environment)?

Something I appreciate very much about running in the cloud is being able to use the control plane’s APIs to authenticate requesters (e.g. Kubernetes API + Service Accounts or AWS IAM + Instance Roles). Does EnvKey have anything in the way of that?

Regarding PCI compliance: if card data is encrypted, the scope of compliance simply moves over to the keys :-)

Artemis2··on Passive observations of a large DNS service
AFAIK a lot of Google’s HTTPS traffic is also routed using anycast. They also offer this to GCP customers under GCLB (https://cloud.google.com/load-balancing/).

I don’t know how they deal with changes in routes.

Artemis2··on Google Hacker Asks Tim Cook to Donate $2.5M in Unpaid iPhone Bug Bounties
Recommended read: https://www.apple.com/business/docs/iOS_Security_Guide.pdf
Artemis2··on Facebook has asked U.S. banks to share financial information about customers
If you bank in Europe, look up PSD2 :-)
Artemis2··on How Sellers Trick Amazon to Boost Sales
Planet Money as well: https://www.npr.org/templates/transcript/transcript.php?stor...

They don’t seem to ship the actual items but random junk instead (to get a tracking number?).

Artemis2··on Stripe Issuing – An API for creating physical and virtual cards
Does Stripe bypass card networks when processing these cards for Stripe merchants? That would be very cool.
Page 1 of 21Next →