HNHacker News
TopNewBestAskShowJobs

kdv

32 karma · joined January 20, 2018

submissionscomments
kdv··on Ask HN: Is there a better PCAP analyzer than Wireshark?
If you don't need immediate access to the packet payload, I've been enjoying Brim Desktop [1]. It comes pre-packaged with Zeek (formerly Bro) and gives you a UI to view and query those Zeek logs, which will link flows together. It also supports opening specific flows in Wireshark for deeper analysis. It might not do everything you need, but it's improved my pcap analysis workflow. It's free at the moment, and this part of the demo [2] gives you an overview of processing a pcap.

[1] https://www.brimsecurity.com [2] https://youtu.be/InT-7WZ5Y2Y?t=382

kdv··on Warp – Mobile VPN
How is Cloudflare handling IP allocation here? I might be mis-understanding how WireGuard works, but it doesn't look like there is an official method for IP dynamic assignment.
kdv··on I made my own WireGuard VPN server
I truly appreciate Wireguard's simplicity but what's the best way to handle key management and peer address assignment in larger deployments?
kdv··on Ask HN: Are you working on interesting technical problems?
We have the full support of the network admin staff, so punching out is not an issue, we just want to keep it as clean as possible. My guess is our control channel will likely end up being some combination of WSS/Redis (if it plays nice w/ mutual auth and load balancing) or a variation of our current polling HTTP/REST solution. Thanks for the offer, I might take you up on it ;)
kdv··on Ask HN: Are you working on interesting technical problems?
You sound like you have some experience in this area so I'll ask. I'm working with fielded devices that typically sit on enterprise networks. We operate much like an IoT device, but without the hardware constraints. The current c2 system uses a traditional polling REST HTTP protocol and we're looking to migrate something more real-time (for config pushes) and lighter on the server. Currently looking at everything from HTTP/2 SSE, Websockets, MQTT over WS, or even HTTP using something like Google's Cloud IoT. As you can probably tell we'd like to keep the wire protocol enterprise-network friendly. Any advice?
kdv··on MacOS command line version of the WireGuard VPN is now available for testing
I'm certainly comfortable with WireGuard for machine to machine connections, but I don't see how it would replace traditional VPN w/ 2FA (e.g OVPN w/ Duo) for non-technical staff to access internal apps (at least without something similar to PAM)
kdv··on MacOS command line version of the WireGuard VPN is now available for testing
Edited my question above for clarity. Any info on performance, key management, and managing peer address assignment in larger deployments?
kdv··on MacOS command line version of the WireGuard VPN is now available for testing
Is there any info on how many concurrent clients the WireGuard server can handle? I'd be interested in hearing if anyone has used this for management traffic to a large (>100) number of devices

Edit: ..and if so, how they handled IP assignment and key distribution.

kdv··on Cloud SQL for PostgreSQL now generally available
Interesting. I'm curious how they compare to Citus and if there are any tight integrations with their over services (managed Kafka or Elasticsearch)
kdv··on Cloud SQL for PostgreSQL now generally available
We get that, but I left off (for brevity) the reasons why Citus would be a net positive for our use case.
kdv··on Cloud SQL for PostgreSQL now generally available
Does anyone have insight or experience using this in production? We're currently running PostgreSQL 10 w/ pg_partman on our own hardware but looking at a several options for cloud migration. Unfortunately, Citus Cloud on GCP doesn't appear to be an option (yet?)

- Google Cloud SQL (PostgreSQL)

- Citus Cloud (AWS Only)

- Citus (managed ourselves) on GCP

kdv··on Cloud SQL for PostgreSQL now generally available
My understanding is people are able to run and manage Citus themselves on GCP (not Cloud SQL), but Citus Cloud (the managed solution) is only available in AWS.
kdv··on Tinc VPN: Secure Private Network Between Hosts
Interested to hear more about your use case and why you moved from tinc to zt. Are you usually deployed behind a NAT? Do you use ZT's servers?
kdv··on Ask HN: Quarantine (dangerous) Internet traffic with VirtualBox?
I wouldn't use virtualbox in any situation where security is a concern nor Qubes OS unless you know what you're doing. Your best option for minimal effort is to use VMware workstation or Fusion, avoid shared folders and transfer data using SSH over a host-only interface that you disconnect when not in use.

Bonus: If you don't need two-way transfers, you can even setup a one-way transfer system that only allows the client to write drop files to specific directory.

kdv··on Introducing Chronicle, a new Alphabet business dedicated to cybersecurity
That's great! Certainly not saying you should abandon those efforts, but see if you can find a security shop that has experienced researchers doing what you want do and sell them on your value based on what you already know and have experience with. It's one of many approaches, but it worked for me when I had limited outside time to devote. Good luck!
kdv··on Introducing Chronicle, a new Alphabet business dedicated to cybersecurity
I don't know of any security talent with moderate people skills that has trouble getting a job. However, there does seem to be a huge misunderstanding on how to best break into the "security industry", which is just too generic and really the wrong question to ask. What specifically do you want to do? Then you can identify the most efficient way to get there. Most people I know found their way in through other careers as developers, sysadmins, or network admins..focusing on security where they were first. Things will grow from there.

Hypothetically, if you have solid experience as a full stack web developer then I would suggest finding a way to pivot off that expertise (web application security, infrastructure, etc) rather than diving into the Shellcoders Handbook, x86, and K&R, which are going to be more tailored towards reverse engineering and vulnerability research.

kdv··on Ask HN: What's your email setup?
That's a reasonable question. You're absolutely correct that security is often highly dependent on account configuration, but Google has invested more into security than any other mail provider and my ridiculous prediction is that their anomaly detection powered by their all-powerful compute network is only going to create a bigger gap there.

For most people, the biggest risk is a troll abusing account recovery or weak 2FA settings to hijack your email account, pivot to other accounts, and wreck your online life. In those cases, you're probably safe w/ a strongly configured Fastmail account (although there have been some recent issues brought to light around Fastmail's account recovery practices [1])

[1] https://news.ycombinator.com/item?id=15855081

kdv··on Ask HN: What's your email setup?
These days you pretty much have to choose between privacy (e.g Protonmail, Fastmail, self-hosted) and security (Google). Account security should matter more since your primary email address probably holds the keys to the kingdom for the rest of your digital life. Oh, and privacy as you know it is essentially dead.
kdv··on BeyondCorp: How Google Ditched VPNs for Remote Employee Access
BeyondCorp sounds great in theory, but deployment sounds like a nightmare without going to one of the several companies that are offering it as a service. It's certainly not as accessible as a decent VPN w/ 2FA, and I doubt we'll see mass deployment for smaller groups until then.
kdv··on PostgreSQL 10: Partitions of partitions
Erm I think you're thinking of materialized views. Regular views are essentially stored queries.

https://www.postgresql.org/docs/10/static/rules-materialized...

kdv··on PostgreSQL 10: Partitions of partitions
A simple example is you bucket your data into monthly tables such that when you run a query that has a timestamp constraint, the query analyzer is smart enough to only scan a subset of the tables that are relevant to your query. It's also really nice for expiring old data with table drops.
kdv··on PostgreSQL 10: Partitions of partitions
Traditional views are just stored queries that are built on the fly, so there's no performance improvement. Materialized views are stored/cached on disk and will give you some performance improvements but you'll have deal with when/how the cache is updated and the resulting penalties.
kdv··on PostgreSQL 10: Partitions of partitions
Is anyone that was using pg_partman before migrated to native partitioning yet? No support for ON CONFLICT and PKs are serious limitations that are available with pg_partman.