HNHacker News
TopNewBestAskShowJobs

adansdpc

4 karma · joined September 22, 2015

[ my public key: https://keybase.io/adansdpc; my proof: https://keybase.io/adansdpc/sigs/bbph-tMFXREkSr_3gIrjOEYR0nE6BSFJDz6Bgji2J38 ]
submissionscomments
adansdpc··on Show HN: A First Look at Witnet’s Decentralized Oracle Prototype Sheikah
Direct link to GitHub repo: https://github.com/witnet/sheikah
adansdpc··on Why the Witnet blockchain will make the most of Rust
BTW, Witnet is hiring Rustaceans among other profiles:

https://angel.co/witnet-foundation-1/jobs

adansdpc··on Introducing Witnet: smart contracts with real power
The Wit token plays a really important role in the network, so we want its initial distribution to be as fair as possible. We want it to end up in the hands of its end users (developers), not speculators.

That's we we're conducting a highly compliant token offering open to the general public through the Republic crowdfunding platform:

https://republic.co/witnet

adansdpc··on Introducing Witnet: smart contracts with real power
Witnet is designed to be compatible with existing smart contract platforms like Ethereum thanks to bridge nodes.

Here's another article explaining Witnet<>Ethereum bridges in detail: https://medium.com/witnet/ethereum-loves-witnet-9a3fd21e6f5c

adansdpc··on Show HN: Mongoaudit – CLI tool for auditing and pentesting MongoDB servers
Stampery's CTO and Mongoaudit project lead here! Our reasons to launch this product:

Companies of all sizes use MongoDB, Stampery included. Why? It’s schema-less, fast, scalable. We all love its deep query-ability.

But it’s no secret that MongoDB pays more attention to scalability, performance and ease of use than to security. There are quite a few holes in its default configuration settings.

This, combined with lazy admins and devs led to what the press has dubbed the MongoDB apocalypse. More than 25,000 MongoDB instances were targeted by hackers. Information was encrypted and money was asked for the decryption keys. In some cases information was wiped with no way to recover it.

Mongoaudit tackles this problem and more. It not only detects misconfigurations, known vulnerabilities and bugs. It also gives advice on how to fix problems and recommends best security practices.

Among other tests, it checks if: + MongoDB listens on a port different to default one + MongoDB HTTP status interface is disabled + TLS/SSL encryption is enabled + Authentication is enabled + SCRAM-SHA-1 authentication method is enabled + Server-side Javascript is forbidden + Roles granted to the user only permit CRUD operations + The user has permissions over a single database + The server is vulnerable to a dozen of different known security bugs

Once the tests are run Mongoaudit can either display a basic report on screen or send a detailed one via email. This personalized report links to a series of guides on how to fix every specific issue and how to harden the targeted MongoDB deployment.

We have also published the Mongoaudit guides in our Medium publications— be sure to check them: https://medium.com/mongoaudit

Feedback is more than welcome!!!

adansdpc··on Show HN: Trailbot – Monitor Your Data and Act Upon Unwanted Modifications
Hi Darío,

When compared to Tripwire, AIDE, Graylog or other conventional SEM solutions, Trailbot offers a much more extensible and powerful policies engine that allows anyone to write, fork, customize and share their own smart policies written in javascript or coffeescript.

Other big point in favor of Trailbot is that we are strong believers and supporters of the technological sovereignty movement, so we open sourced all the components in Trailbot's stack so that you can self-host the whole thing in case you don't want to trust any third party.

In addition, all traffic going between Trailbot Watcher and Trailbot Client is encrypted end-to-end using asymmetric cryptography (PGP with 4096 bits keys).

Thanks a lot for your interest, we hope you find Trailbot useful :)

adansdpc··on Show HN: Trailbot – Monitor Your Data and Act Upon Unwanted Modifications
Hi community!

We have just open sourced Trailbot, a files and logs tracking daemon for GNU/Linux that triggers Smart Policies upon unwanted modifications.

Current security solutions are based on an obsolete paradigm: building walls and fences. Companies advertise their overcomplicated perimeter security systems as if they were impenetrable. But nevertheless we hear everyday about cyber security breaches at even the largest corporations. It’s not a matter of “if” but “when” the perimeter will get breached.

In any case walls and fences will not protect you at all from internal breaches and insider threats. Furthermore, most data resides nowadays in the cloud, where walls, borders and fences fade and blur.

With Trailbot you can rest assured of the integrity of your data, being it a system log or any other important file. It doesn't matter if an outsider got access to your systems or an insider decided to go rogue—you are now in control.

Would love to hear your thoughts and feedback!