It does take time to be effective. I like to emphasise that learning to be effective at Linux is not a sprint - it's a marathon.
57 karma · joined November 28, 2018
Been there done that - SRE/DevOps/SecEng/SysEng/SoftEng
It does take time to be effective. I like to emphasise that learning to be effective at Linux is not a sprint - it's a marathon.
But, whether you own a mac or not, once you start using Linux (and it takes patience to do so _effectively_), I can guarantee that you _will_ never want to use anything else.
- Linux user for the past 22 years (for the most part been so much fulfilling).
Agreed.
According to what I read in their main page https://cloudflaremirrors.com/archlinux, they seem to be caching the packages from mirrors and serving it via their anycast network.
Thank you for that information. Is there a reference that documents this somewhere?
You have to be very _specific_ when you say _sandboxing_. Since, the attack surface is mostly at the decoding layer - there are at least few dozen ways to sandbox the processing logic on modern UNIX-like OS based on the requirements:
1. Farm out, give it its own namespace and filtered list of seccomp2 calls to do the decoding.
2. Farm out, compartmentalize the decoding layer to BSD jails
3. Same as 2) but using chroot - give the necessary libs/bins/mount
4. Farm out, run the decoding components on a separate VM - somewhat akin to QubeOS.
5. Farm out, run ephemeral spark jobs to process the decoding on a compartmentalized VMs/Containers....
These days the word _sandbox_ is overloaded.
It used to be that you put things that are in userland under selinux and go to bed at night.....
Nice; though the documentation/blog is quite hard to follow :)
Aha. Reading now.
A lot of software in the messaging/storage space has undergone jepsen test and I for one am grateful to Jepsen's author Kyle Kingsbury for his incredible work in setting their expectations correct.
Didn't quite get the connection here. Care to elaborate? :)
If you are implying _PoC GTFO_, then definitely I do not have anything to suggest today that either is secure but I would rather not base my comment on what's not seen in the wild and also on the limited breadth of my research.
If anything, we've learnt the from past exploitations of guest additions/kernel modules in guests/vmm, that all of it is real and possible. Given enough resource, time and eyeballs, a _lot_ of the bugs are exploitable - you just have to ask some of the folks in offsec who develop exploits for living.
I think you are right in general terms but I do not think an attacker will play by the rule and use `chroot` in UNIX-like OS as it is "meant to be used". They will use whatever means necessary - whether it be 0day or other un-patched vulnerability to get a break out.
Fair enough. I am letting you know though the part where you got mixed up - that is not because _What DevOps has become in practice_. That is precisely because of failings and shortcomings in team culture and/or the organisation that practice DevOps.
That was a good laugh for a bit. Thanks. I read the first few words of yours as:
Would a company like Amazon not have full time lawyers retained on salary to lie ....I think `rkt` and `lxc` are missing from your list.
<3 Nomad. However, Nomad only satisfies a really tiny part of Kubernetes ecosystem which is the ability to pack containers and schedule them efficiently in a cluster; Plus, it scales really well. Kubernetes provides a bit more than that.
Hardly. If anything at all, it tells about the _team_ and/or the culture of the organisation. In any DevOps/SRE/Opsec culture worth the salt, an immediate blameless postmortem analysis would be performed to help with premortem analysis in future.
DevOps is not about exposing unsecured endpoints. You've got it all wrong son.
I wouldn't call it the best way; Rather a good way because Kubernetes does encapsulate the really good bits from scalability, development, security and reliability aspect. It's not a panacea but if you have team bandwidth to run k8s cluster, it's definitely worth a look.
<3 HAProxy. It's a solid piece of software tested to the teeth over the years and is great; Here's the thing: You can run it as your preferred ingress controller too :) https://www.haproxy.com/blog/dissecting-the-haproxy-kubernet...
Yes. I would agree to your statement precisely as an answer to @jen20.
Some things such as getting stateful systems, HPAs and persistent storages were a little tricky initially but a breeze after.
But I do want to mention that you really really need a team to look after it. Without it, it'll bound to be another snowflake.
[edit]: <sigh/> i meant to say stateful when i wrote stateless.
I have nothing against change but _context_ matters. When I read about `pty` masters or slaves, I think of pseudo-terminals not humans.
Hah. Exactly.
If I had to hazard a guess, we are all a bunch of technologists/engineers/tinkerers who deal with technical stuffs; not some societal driven definitions and constraints that supposedly define what `man` is in this context. We bloody well know what `man` is in this context - manual pages. For some odd $deity fore shaken reason, please don't try to bend the meaning of it.
> Whoever promoted it, was a machiavellian genius. People can't rebel if they keep each other in check.
That is exactly what I wanted to say too but you said it better.
I'd point out that there are possible hundreds if not thousand other software that use the terminology. It doesn't offend me at all.
$> man -k slave grantpt (3) - grant access to the slave pseudoterminal grantpt (3p) - grant access to the slave pseudo-terminal device jack_netsource (1) - Netjack Master client for one slave kdeinit5 (8) - Launcher for applications built with kdeinit support, ... ptmx (4) - pseudoterminal master and slave pts (4) - pseudoterminal master and slave ptsname (3) - get the name of the slave pseudoterminal ptsname (3p) - get name of the slave pseudo-terminal device ptsname_r (3) - get the name of the slave pseudoterminal Tcl_CreateSlave (3) - manage multiple Tcl interpreters, aliases and hidden c... Tcl_GetSlave (3) - manage multiple Tcl interpreters, aliases and hidden c... unlockpt (3) - unlock a pseudoterminal master/slave pair unlockpt (3p) - unlock a pseudo-terminal master/slave pair
$> man -k master agentxtrap (1) - send an AgentX NotifyPDU to an AgentX master agent getpt (3) - open the pseudoterminal master (PTM) gnutls_session_ext_master_secret_status (3) - API function gnutls_session_get_master_secret (3) - API function gnutls_session_set_premaster (3) - API function jack_netsource (1) - Netjack Master client for one slave mmafm (1) - creates AFM font metrics for multiple master fonts mmpfb (1) - creates single-master fonts from multiple master fonts ptmx (4) - pseudoterminal master and slave pts (4) - pseudoterminal master and slave pulseaudio-ctl (1) - Control pulseaudio's basic functions such as the maste... RAND_DRBG_get0_master (3ssl) - get access to the global RAND_DRBG instances SSL_get_client_random (3ssl) - get internal TLS/SSL random values and get/set... SSL_get_extms_support (3ssl) - extended master secret support SSL_get_server_random (3ssl) - get internal TLS/SSL random values and get/set... SSL_SESSION_get_master_key (3ssl) - get internal TLS/SSL random values and ge... SSL_SESSION_set1_master_key (3ssl) - get internal TLS/SSL random values and g... Tcl_GetMaster (3) - manage multiple Tcl interpreters, aliases and hidden c... Tk_GetImageMasterData (3) - define new kind of image unlockpt (3) - unlock a pseudoterminal master/slave pair unlockpt (3p) - unlock a pseudo-terminal master/slave pair WildMidi_MasterVolume (3) - sets the overall audio level of the library. xapian-replicate (1) - Replicate a database from a master server to a local copy
I offer you my well wishes on that.