HNHacker News
TopNewBestAskShowJobs

mac-chaffee

480 karma · joined December 11, 2017

submissionscomments
mac-chaffee··on The rule says, “No vehicles in the park”
I see a lot of "just add more specifics to the rule" in here, but that's fighting a losing battle. There will always be another edge case, and the rule will end up being so long and complicated that no one will properly follow it anyway.

I think the solution is to put the goal of the rule right next to the rule. Maybe vehicles are banned to improve air quality, to improve pedestrian safety, to reduce noise, or some combination. Or maybe there really is no good reason, and the writer of the rule just enjoys power.

Reminds me of writing security policies. There will always be exceptions, but if you include the goals of each rule, your users are empowered to recognize when an exception is a good idea. Otherwise, you get either blind compliance or secret non-compliance.

mac-chaffee··on New rule would give electric utilities incentives for investing in cybersecurity
> You can't just purchase a "deluxe cybersecurity firewall appliance" and plug it into your network, even if it costs $50,000

Those cost a quarter of a million per year nowadays...

mac-chaffee··on Infinite Mac: Classic Macintosh system releases and software on a web browser
I've been messing around with this for the past week, it's very cool. There's even a CloudFlare Durable Objects-based AppleTalk networking stack, which I think is such an interesting fusion of old and new: https://blog.persistent.info/2022/07/infinite-mac-networking...
mac-chaffee··on Last Call to Migrate Mojang Accounts
I hit an unexplained error while migrating, and the error page told me to go to https://help.mojang.com/ which has an expired TLS cert as of today.

Then I tried to submit a support ticket here: https://help.minecraft.net/hc/en-us/request/new?ticket_form_...

But when you click "Submit", nothing happens. I can see that their CORS config is broken and doesn't allow requests to zendesk's API.

I did eventually get my migration to go through. The trick was to enter my security question answers and click the button (where nothing happens, also a bug). Then close the tab and re-open it (control + shift + t).

mac-chaffee··on Thinking about our passive exposure to IPv6 issues
Since universities were some of the first movers to the internet, there's a lot of legacy stuff holding them back. When you add in the sheer size and the lack of centralized power (which the author has talked about[1]), I'm definitely not surprised.

[1]: https://utcc.utoronto.ca/~cks/space/blog/tech/UniversityMone...

mac-chaffee··on New macOS malware steals info, including a user's entire Keychain database
The advice you are getting so far sucks. The default security settings on macOS are easy to bypass: https://www.macchaffee.com/blog/2023/hacking-myself/

Unfortunately these are design weaknesses, so any "software stack" would just be a bandaid.

mac-chaffee··on Docker-compose.yml as a universal infrastructure interface
I just give developers access to k8s and teach them about it. That's really just my admission that the Kubernetes API isn't perfect, but it's better than many alternatives. If I were to build something to hide k8s from developers, eventually I'd have to add so many extra options that I'd probably end up re-inventing the Kubernetes API anyway.

That may just be unique to my job. Maybe another company could force all apps into nice boxes that prevents their bespoke platform API from leaking.

mac-chaffee··on Docker-compose.yml as a universal infrastructure interface
The Kubernetes API is itself a leaky abstraction over many different concepts. Putting docker-compose over top of that is just an even leakier abstraction.

Even their example of using Ingresses is already leaky because there is no similar concept of Ingresses in docker-compose, so they're hacking it with labels. What if I need to set a higher request timeout for my app? I have to set a docker-compose label that converts into an Ingress annotation (the leaky part of the Ingress abstraction)? And this is somehow less cognitive load?

Like all similar attempts to simplify deploying apps, it only works if all your apps fit in a nice box. Anything slightly non-standard (like needing different classes of storage volumes) will expose the leakiness. Even Kubernetes kinda still expects all your apps to be stateless web services and will fight you otherwise.

mac-chaffee··on Docker is deleting Open Source organisations - what you need to know
Not a lot of people pull by hash; they pull by tag. Tags are not immutable, so the image I get from "python:3.11" today will almost certainly change due to security updates and I will be none the wiser.
mac-chaffee··on Docker is deleting Open Source organisations - what you need to know
May want to keep your eye on dragonfly, a P2P image distribution protocol: https://d7y.io/docs/
mac-chaffee··on Gitlab loses one-third of its value after company issues weak forecast
I always reference this post when the subject of self-hosting "simple" things comes up: https://utcc.utoronto.ca/~cks/space/blog/sysadmin/RunningSer...
mac-chaffee··on I spent a week without IPv4 to understand IPv6 transition mechanisms
> The results show that rewriting the packets is quite a bit more expensive than just allowing or dropping a packet. For example, if we look at the unidirectional test with 10,000 flows, we see that we dropped from 14M pps [packets per second] to 3.2M pps, we also needed 13 cores more to do this!

https://atoonk.medium.com/linux-kernel-and-measuring-network...

Just speculating, but I believe the cost comes from all the memory operations of reading/editing/writing every packet, not from the NAT table lookup.

mac-chaffee··on KWOK: Kubernetes WithOut Kubelet
Kubernetes is only tested against 110 pods per node: https://kubernetes.io/docs/setup/best-practices/cluster-larg...

In my testing, it's a limitation in either the container runtime or kubelet in processing all the events that flow from pods. And since the container networking and container storage interfaces aren't part of Kubernetes, there are likely scaling issues in those pieces of software as well.

mac-chaffee··on Psql Tips
Oh yeah seems that FETCH_COUNT is special and is not a regular setting.

All normal settings that you can SET can also be set per-DB and per-user: https://www.postgresql.org/docs/current/config-setting.html#...

mac-chaffee··on Psql Tips
By default, psql will fetch the entire result first then print it out. This is usually fine until you need to fetch more rows than your client's RAM. To fix that, you can run "\set FETCH_COUNT 10000". Then psql will use a cursor which only fetches 10000 rows at a time, using a constant amount of RAM.

This can be handy if e.g. you typically run psql on the server/container running postgres itself and you want to avoid an accidentally large query from oomkilling your database. You can set FETCH_COUNT per database and per user with ALTER: https://www.postgresql.org/docs/current/config-setting.html#...

mac-chaffee··on Down the Cloudflare / Stripe / OWASP Rabbit Hole
I've been running the OWASP coreruleset in production for about a year now and it has been a big pain. The way I made it manageable was 1) training users that "if you see a 403 error, tell me ASAP" and 2) learning the ModSecurity rule syntax to be able to create rule exceptions for users very quickly. This is not possible to do at Cloudflare's scale.

Even then, users who didn't know the intricate details of the Web Application Firewall (like Troy in this case) would waste hours hunting down the issue. Since less popular sites often have more illegitimate traffic than legitimate traffic, there was really no good way for me to proactively fix WAF issues.

The conclusion I have drawn is that WAFs really only have a few very narrow use-cases.

The main use-case is when you want to write your own rule to protect hosts from a specific zero day while they are being patched. Like a simple rule to detect Log4J [1] was an effective band-aid while we scrambled to implement real patches. But WAFs have an inherent weakness: clever attackers can pretty much always circumvent rules, or force to you write a rule that is so complex that it causes slowness or blocks legitimate traffic.

Another use-case is when you have to deploy some untrusted code that is likely vulnerable to common (>1 year old) vulnerabilities. Like running an old/archived wordpress instance. This is the only time when the coreruleset makes sense IMO.

As I see it, WAFs are a tool created in a simpler time when the number of possible attacks and applications was small. In the modern era where there is a constant deluge of zero-days, huge attack surfaces, tons of variability in applications, and lots of sites where RCE/SQLi is a feature (think CI job definitions, Juptyer notebooks, custom query languages), WAFs have lost their effectiveness.

[1]: https://github.com/coreruleset/coreruleset/issues/2331

mac-chaffee··on Kubernetes as a platform vs. Kubernetes as an API
The author admits it's extreme, but is clearly trying to normalize it:

> Someone defines Kubernetes as “a well-designed and extensible API with programmable reconciliation logic, that happens to come with a container orchestrator built in.” I like that definition.

mac-chaffee··on Kubernetes as a platform vs. Kubernetes as an API
Amazon publishing a blog that blatantly argues for vendor lock-in? Who would have guessed?

One of the big benefits of Kubernetes is the cloud-agnostic API for running pretty much any application. CustomResources can help blur that boundary and make it easier to use some managed services, but actually arguing in favor of that approach for everything is a pure advertising tactic.

It's no secret that managed services are several times more expensive than equivalent EC2 time. Sometimes it's worth it. But to throw Kubernetes into the mix just to run some controllers that deploy those services will pointlessly add to your monthly bill. Running any Kubernetes cluster is not cheap, even if it's just a bunch of controllers.

mac-chaffee··on Tell HN: Firefox Is an awesome browser right now
Don't use it on macOS. It has no protections at all for cookie theft. Unencrypted SQLite DB sitting in a user-readable directory. Chrome and (I think) Safari both use encryption keys in the secure enclave. That's still not perfect (Chrome remote debugging and Safari code injection can get around those), but better than nothing at all.
mac-chaffee··on Russhian Roulette: 1/6 chance of posting your SSH private key on pastebin
Yep, same with cookies and cloud credentials: https://www.macchaffee.com/blog/2023/hacking-myself/
mac-chaffee··on Why the infosec community is ahead of the curve and rationalists and nihilists
Not sure if this is exactly what the person you replied to is talking about, but I recently looked through a list of tools for restricting the permissions of programs: https://www.macchaffee.com/blog/2023/hacking-myself/

Spoiler: they're all kinda bad, but macOS sandboxing is promising

mac-chaffee··on Ask HN: Has anyone worked at the US National Labs before?
If scientific computing interests any students in the NC triangle area, we're looking for a Fall intern to do some platform engineering: https://unc.peopleadmin.com/postings/247397
mac-chaffee··on CircleCI incident report for January 4, 2023 security incident
Is tying session tokens to IPs actually common? I can't imagine it is given the unreliability of IP addresses causing issues.

I used to live somewhere where outbound traffic went through one of three CGNAT IPs at random, and I only had auth issues with one really old site that predates the NAT hell that is the modern internet.

mac-chaffee··on Memories. Their Cloud
> Digital self-storage has gotten more complex as I discovered when I visited the DataHoarder subreddit. Posts there with technical advice for the best home setup were jargon-filled to the point of incomprehension for a newbie.

Yeah the ability to de-cloud is something us technologists may take for granted. Even just the process of combining a multi-part zip file and is something the average person may have trouble with.

mac-chaffee··on LastPass user vaults stolen in recent hack
They talk about how the federated version is safer due to the long random master password, but...

Federated LastPass is tied to your company's SSO, which means your real master password is technically a login.microsoftonline.com (or equivalent) cookie stored in plain text on your hard drive that is valid for 8+ hours. One bad "pip install" typo and your teams' passwords are toast. That was true even before the breach.

mac-chaffee··on Know Your Carrying Capacity
I do wish I knew of a better solution/mitigation. I feel like there might not be anything an individual really can do. It depends on coworkers picking up the slack or leadership/customers just demanding less (hah).

I quit my last job over this, which kinda inspired this post. I tried to formally shed some of my responsibilities, but the only people who volunteered were other over-capacity people! So really nothing changed haha

mac-chaffee··on Commercials make us like TV more (2010)
I think this is the paper they're talking about: https://academic.oup.com/jcr/article/36/2/160/1942726

Interestingly, they did control for the effects of TV that was edited with commercials in mind (cliffhangers, etc.) in "Study 2", where participants watched a 4-minute animation with and without interruptions.

mac-chaffee··on Don't use Kubernetes yet
Agreed. You really get what you pay for with the managed k8s offerings, and you really can't get a lot of good software for ~$72 per month. Not having to run the control plane is a drop in the ocean of complexity that comes with k8s (node provisioning/patching, monitoring, hardening, upgrades, intrusion detection, cluster scaling, multi-cluster, ingress, tls).

That's why things like OpenShift exist which cost an order or magnitude more than just a managed control plane.

mac-chaffee··on Gitea – a painless self-hosted Git service
I've been happy with Gitea. It's very fast, and upgrades cannot be simpler. Just download the new binary and start it. The migrations run automatically.

If you need a git hosting service but "hosting git" isn't your day job, then the alternatives are way more complex than necessary IMO.

mac-chaffee··on My students cheated... a lot
A large part of any syllabus is a description of the academic integrity policy. Most universities even mention it during orientation. Most all my exams had "by signing, I agree to..." next to where you write your name. Universities care a lot about cheating. It even makes the news.

The cop is always visible, the sign is clearly posted, but they still trespass. Most got less-than-minimum sentences anyway.

← PreviousPage 2 of 5Next →