HNHacker News
TopNewBestAskShowJobs

lsofzz

57 karma · joined November 28, 2018

I keep the in-extinguishable fire under bay.

Been there done that - SRE/DevOps/SecEng/SysEng/SoftEng

submissionscomments
lsofzz··on Sick of Windows but can't afford a Mac? The cynic's guide to desktop Linux
> I spent the time to learn to use Linux effectively, and I still want to use something else.

It does take time to be effective. I like to emphasise that learning to be effective at Linux is not a sprint - it's a marathon.

lsofzz··on Sick of Windows but can't afford a Mac? The cynic's guide to desktop Linux
I have two macs. And, yes, I surely I can afford many more of it.

But, whether you own a mac or not, once you start using Linux (and it takes patience to do so _effectively_), I can guarantee that you _will_ never want to use anything else.

- Linux user for the past 22 years (for the most part been so much fulfilling).

lsofzz··on AWS IAM is having issues again
> They can rebuild that whole datacenter a hundred times over and still not feel it in their wallet.

Agreed.

lsofzz··on Cloudflare Package Repository Mirrors
> How is this supposed to work? (I use Arch BTW) supposed I'm in a country X, does Cloudflare basically caching the request to server that are in country X? But I'm already close to that server and I'm always cautious with mirrors that are in country X, often they were out of date :(

According to what I read in their main page https://cloudflaremirrors.com/archlinux, they seem to be caching the packages from mirrors and serving it via their anycast network.

lsofzz··on An Introduction to OpenBSD [video]
OpenBSD is also a great choice for a firewall too https://www.openbsd.org/faq/pf/
lsofzz··on Ampere’s Product List: 80 Cores, up to 3.3 GHz at 250 W; 128 Core in Q4
I looked around but didn't find it. Thanks a lot.
lsofzz··on Ampere’s Product List: 80 Cores, up to 3.3 GHz at 250 W; 128 Core in Q4
> Especially when ARM Graviton 2's vCPU on AWS are actual CPU core while Intel / AMD instances are CPU thread.

Thank you for that information. Is there a reference that documents this somewhere?

lsofzz··on Security Bulletin VLC 3.0.11
> What would you think about sandboxing all media related components?

You have to be very _specific_ when you say _sandboxing_. Since, the attack surface is mostly at the decoding layer - there are at least few dozen ways to sandbox the processing logic on modern UNIX-like OS based on the requirements:

1. Farm out, give it its own namespace and filtered list of seccomp2 calls to do the decoding.

2. Farm out, compartmentalize the decoding layer to BSD jails

3. Same as 2) but using chroot - give the necessary libs/bins/mount

4. Farm out, run the decoding components on a separate VM - somewhat akin to QubeOS.

5. Farm out, run ephemeral spark jobs to process the decoding on a compartmentalized VMs/Containers....

These days the word _sandbox_ is overloaded.

It used to be that you put things that are in userland under selinux and go to bed at night.....

lsofzz··on Security Bulletin VLC 3.0.11
> Follow the blog: https://codecs.multimedia.cx/ but there's no source code release yet AFAIK.

Nice; though the documentation/blog is quite hard to follow :)

lsofzz··on Fakecracker: NetBSD as a Function Based MicroVM
> No need to assume anything. The article starts out:

Aha. Reading now.

lsofzz··on Consistency Models (2018)
For any tool authors, jepsen is invaluable piece <3.

A lot of software in the messaging/storage space has undergone jepsen test and I for one am grateful to Jepsen's author Kyle Kingsbury for his incredible work in setting their expectations correct.

lsofzz··on Consistency Models (2018)
> A foolish consistency is the hobgoblin of little minds . . .

Didn't quite get the connection here. Care to elaborate? :)

lsofzz··on Fakecracker: NetBSD as a Function Based MicroVM
I assume this is a play on the word "firecracker"? :D

https://github.com/firecracker-microvm/firecracker

lsofzz··on Fakecracker: NetBSD as a Function Based MicroVM
> Doesn't this apply to really any sort of isolated environment? What's wrong with chroot vs a vm?

If you are implying _PoC GTFO_, then definitely I do not have anything to suggest today that either is secure but I would rather not base my comment on what's not seen in the wild and also on the limited breadth of my research.

If anything, we've learnt the from past exploitations of guest additions/kernel modules in guests/vmm, that all of it is real and possible. Given enough resource, time and eyeballs, a _lot_ of the bugs are exploitable - you just have to ask some of the folks in offsec who develop exploits for living.

lsofzz··on Fakecracker: NetBSD as a Function Based MicroVM
> Chroot vulnerabilities have been discovered and fixed over time, as any security issue in an operating system is. It's not accurate to say that they are insecure in a blanket fashion especially these days. My opinion is that we should be using Unix as it is meant to be used, as on operating system, and using its time worn facilities meant for purposes such as

I think you are right in general terms but I do not think an attacker will play by the rule and use `chroot` in UNIX-like OS as it is "meant to be used". They will use whatever means necessary - whether it be 0day or other un-patched vulnerability to get a break out.

lsofzz··on Show HN: Yet Another Covid Map. In 3D for a better sense of proportions
Nice. Would it not be possible to source data for other countries?
lsofzz··on Container technologies at Coinbase: Why Kubernetes is not part of our stack
Oh bummer
lsofzz··on Container technologies at Coinbase: Why Kubernetes is not part of our stack
> I'm not your son, nor am I talking about what DevOps "is about", but about what is became in practice, which you would have understood hadn't you rushed to reply in the most condescending tone you managed to invoke.

Fair enough. I am letting you know though the part where you got mixed up - that is not because _What DevOps has become in practice_. That is precisely because of failings and shortcomings in team culture and/or the organisation that practice DevOps.

lsofzz··on GnuTLS: TLS 1.3 session resumption works without master key, allowing MITM
It's hard to know exactly how bloated SSL/TLS libraries have become without actually taking the time to research them but some of the folks behind `LibreSSL` seem to know crypto well enough.
lsofzz··on Amazon sues former AWS marketing VP Brian Hall after he takes Google Cloud job
> Would a company like Amazon not have full time lawyers retained on salary instead of relying on outside counsel with that conflict?

That was a good laugh for a bit. Thanks. I read the first few words of yours as:

  Would a company like Amazon not have full time lawyers retained on salary to lie ....
lsofzz··on Container technologies at Coinbase: Why Kubernetes is not part of our stack
> Nomad has been brought forth in a lot of comments, and it has a feature that nobody brought up yet, I think. It's multi-platform. It currently has official task runners for Docker, Isolated/Raw Fork/Exec, Java, and Qemu. It has several community-based task drivers, including Windows IIS and FreeBSD Jails.

I think `rkt` and `lxc` are missing from your list.

lsofzz··on Container technologies at Coinbase: Why Kubernetes is not part of our stack
> I tried using Nomad once after being a little worn out by Kubernetes' complexity. For some reason, the Nomad abstractions didn't click on the first couple attempts. In comparison, Kubernetes' abstractions mapped 1:1 to my understanding of the service oriented architecture.

<3 Nomad. However, Nomad only satisfies a really tiny part of Kubernetes ecosystem which is the ability to pack containers and schedule them efficiently in a cluster; Plus, it scales really well. Kubernetes provides a bit more than that.

lsofzz··on Container technologies at Coinbase: Why Kubernetes is not part of our stack
> I think this is a big failing of the DevOps movement as a whole (at least what DevOps became in practice — devs doing ops) which results in things like passwordless mongodb exposed to the internet...

Hardly. If anything at all, it tells about the _team_ and/or the culture of the organisation. In any DevOps/SRE/Opsec culture worth the salt, an immediate blameless postmortem analysis would be performed to help with premortem analysis in future.

DevOps is not about exposing unsecured endpoints. You've got it all wrong son.

lsofzz··on Container technologies at Coinbase: Why Kubernetes is not part of our stack
> Thank you. I use most of this, I've been using it for years and I just don't talk about it because it's hard to argue when people just want to force an idea that k8s is "really the best way of doing things".

I wouldn't call it the best way; Rather a good way because Kubernetes does encapsulate the really good bits from scalability, development, security and reliability aspect. It's not a panacea but if you have team bandwidth to run k8s cluster, it's definitely worth a look.

<3 HAProxy. It's a solid piece of software tested to the teeth over the years and is great; Here's the thing: You can run it as your preferred ingress controller too :) https://www.haproxy.com/blog/dissecting-the-haproxy-kubernet...

lsofzz··on Container technologies at Coinbase: Why Kubernetes is not part of our stack
> So if you'll indulge me -- this list is exactly why a system like Kubernetes is valuable and why I think personally that it contains a lot of essential complexity.

Yes. I would agree to your statement precisely as an answer to @jen20.

Some things such as getting stateful systems, HPAs and persistent storages were a little tricky initially but a breeze after.

But I do want to mention that you really really need a team to look after it. Without it, it'll bound to be another snowflake.

[edit]: <sigh/> i meant to say stateful when i wrote stateless.

lsofzz··on The Go Language was rid of blacklist/whitelist and master/slave
> No. We can fix things one at a time. Master/slave doesn't upset me but it does upset some people. Ok, if they're willing to put in the effort to update the code and all the docs then I'm willing to adopt the new terminology.

I have nothing against change but _context_ matters. When I read about `pty` masters or slaves, I think of pseudo-terminals not humans.

lsofzz··on The Go Language was rid of blacklist/whitelist and master/slave
> Good thing I don't have a master's degree.

Hah. Exactly.

lsofzz··on The Go Language was rid of blacklist/whitelist and master/slave
I'd also say `man` from the unix manual <- yep, would you consider that to be the elephant in the room?

If I had to hazard a guess, we are all a bunch of technologists/engineers/tinkerers who deal with technical stuffs; not some societal driven definitions and constraints that supposedly define what `man` is in this context. We bloody well know what `man` is in this context - manual pages. For some odd $deity fore shaken reason, please don't try to bend the meaning of it.

lsofzz··on The Go Language was rid of blacklist/whitelist and master/slave
> That's the beauty of identity politics. No matter what you say, you are always going to encroach on someone's identity.

> Whoever promoted it, was a machiavellian genius. People can't rebel if they keep each other in check.

That is exactly what I wanted to say too but you said it better.

I'd point out that there are possible hundreds if not thousand other software that use the terminology. It doesn't offend me at all.

$> man -k slave grantpt (3) - grant access to the slave pseudoterminal grantpt (3p) - grant access to the slave pseudo-terminal device jack_netsource (1) - Netjack Master client for one slave kdeinit5 (8) - Launcher for applications built with kdeinit support, ... ptmx (4) - pseudoterminal master and slave pts (4) - pseudoterminal master and slave ptsname (3) - get the name of the slave pseudoterminal ptsname (3p) - get name of the slave pseudo-terminal device ptsname_r (3) - get the name of the slave pseudoterminal Tcl_CreateSlave (3) - manage multiple Tcl interpreters, aliases and hidden c... Tcl_GetSlave (3) - manage multiple Tcl interpreters, aliases and hidden c... unlockpt (3) - unlock a pseudoterminal master/slave pair unlockpt (3p) - unlock a pseudo-terminal master/slave pair

$> man -k master agentxtrap (1) - send an AgentX NotifyPDU to an AgentX master agent getpt (3) - open the pseudoterminal master (PTM) gnutls_session_ext_master_secret_status (3) - API function gnutls_session_get_master_secret (3) - API function gnutls_session_set_premaster (3) - API function jack_netsource (1) - Netjack Master client for one slave mmafm (1) - creates AFM font metrics for multiple master fonts mmpfb (1) - creates single-master fonts from multiple master fonts ptmx (4) - pseudoterminal master and slave pts (4) - pseudoterminal master and slave pulseaudio-ctl (1) - Control pulseaudio's basic functions such as the maste... RAND_DRBG_get0_master (3ssl) - get access to the global RAND_DRBG instances SSL_get_client_random (3ssl) - get internal TLS/SSL random values and get/set... SSL_get_extms_support (3ssl) - extended master secret support SSL_get_server_random (3ssl) - get internal TLS/SSL random values and get/set... SSL_SESSION_get_master_key (3ssl) - get internal TLS/SSL random values and ge... SSL_SESSION_set1_master_key (3ssl) - get internal TLS/SSL random values and g... Tcl_GetMaster (3) - manage multiple Tcl interpreters, aliases and hidden c... Tk_GetImageMasterData (3) - define new kind of image unlockpt (3) - unlock a pseudoterminal master/slave pair unlockpt (3p) - unlock a pseudo-terminal master/slave pair WildMidi_MasterVolume (3) - sets the overall audio level of the library. xapian-replicate (1) - Replicate a database from a master server to a local copy

lsofzz··on The Beauty of Unix Pipelines
> Unix is seriously uncool with young people at the moment. I intend to turn that around and articles like this offer good material.

I offer you my well wishes on that.

← PreviousPage 3 of 5Next →