HNHacker News
TopNewBestAskShowJobs

flarecoder

89 karma · joined December 21, 2015

submissionscomments
flarecoder··on Sandboxed Trivy GitHub Action
Scans container images for vulnerabilities with Trivy running inside a sandboxed Docker container.

This action is forked from aquasecurity/trivy-action with security hardened by running Trivy inside a sandboxed Docker container. Credits to Aqua Security for the original action.

This action runs Trivy inside a Docker container with strict security settings to prevent container escape: * --read-only filesystem — the container's root filesystem is read-only * --cap-drop ALL — all Linux capabilities are dropped * --security-opt no-new-privileges:true — prevents privilege escalation inside the container * All scan targets are mounted read-only * Only the output and cache directories are mounted writable * A tmpfs is mounted at /tmp for Trivy's temporary files * No direct Docker socket access — image scans use docker save to export a tar file which is mounted read-only into the container

Contributions are welcome to improve this!

flarecoder··on Default musl allocator considered harmful to performance
For docker images, cgr.dev/chainguard/wolfi-base (https://images.chainguard.dev/directory/image/wolfi-base/ver...) is a great replacement for Alpine. Wolfi is glibc based. It's easy to switch from Alpine since Wolfi uses apk for package management with similar package names and also contains busybox like Alpine.
flarecoder··on DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
I'm the original author of the Spring Boot feature for heapdumps: https://github.com/spring-projects/spring-boot/pull/5670.

It seems that users commonly misconfigure Spring Boot security or ignore it completely. To improve the situation, I made this PR: https://github.com/spring-projects/spring-boot/pull/45624.

When the PR was created in 2016, endpoints were marked as "sensitive" and, for example, the heapdump endpoint would have to be explicitly enabled. However, Spring Boot has evolved over the years, and only the "shutdown" endpoint was made "restricted" in the later solutions. My recent PR will address that weakness in Spring Boot when users misconfigure or ignore security for a Spring Boot app so that heapdumps won't get exposed by default.

flarecoder··on I discovered caching CDNs were throttling my everyday browsing
Some random links about PMTU issues: https://www.znep.com/~marcs/mtu/ https://serverfault.com/questions/1050567/why-does-setting-m... https://serverfault.com/questions/126468/mtu-dsl-router-and-... https://serverfault.com/questions/162062/how-to-check-who-bl...
flarecoder··on I discovered caching CDNs were throttling my everyday browsing
Just curious if MSS or PMTU blocking has anything to do with the problem.

In the 2 different Wireshark dumps, a relevant difference is MSS=1460 and MSS=1380 in the second one.

I'd recommend setting the local NIC MTU to a low value just to see if it has an impact. However, the Wireshark dump doesn't show packet fragmentation, so perhaps this isn't a problem at all?

flarecoder··on Money is pouring into AI. Skeptics say it’s a ‘grift shift’
The move from crypto to artificial intelligence has fueled the markets this year, but some are questioning how much of it is real.
flarecoder··on java.nio.file.WatchService is subtly broken on Linux
Discussion on nio-dev mailing list: http://mail.openjdk.java.net/pipermail/nio-dev/2015-December...