HNHacker News
TopNewBestAskShowJobs

mac-chaffee

480 karma · joined December 11, 2017

submissionscomments
mac-chaffee··on A human postmortem of the 1996 AOL outage
That's really cool! I actually did download an archive of aol-sucks while researching this, but the software I was using to look through the mbox file was kinda buggy so I gave up. I'm literally the meme of the miner guy giving up right before hitting diamonds.
mac-chaffee··on Show HN: BunkerWeb – the open-source and cloud-native WAF
I'd generally confirm that suspicion: https://www.macchaffee.com/blog/2023/wafs/

WAFs have a few valid uses in my opinion: "virtual patching" and the ability to create custom rules such as blocking/challenging/rate limiting obviously bad traffic. But the giant rulesets are actively harmful IMO. "Defense in depth" is not a valid justification for doing something actively harmful to both your users and the time budget of your security team.

mac-chaffee··on A cheat sheet for why using ChatGPT is not bad for the environment
I agree but there's a lot of nuance to the next question of "well what IS bad for the environment" and tech's role in that question.

I've been unsatisfied with how people in tech address that complex subject so I wrote about it here: https://www.macchaffee.com/blog/2025/tech-and-the-climate-cr...

mac-chaffee··on NLRB acting general counsel rescinds non-compete labor policy
I wrote up a bit of background on non-competes in mid-2024, I see my fears came true: https://www.macchaffee.com/blog/2024/non-competes/
mac-chaffee··on Dear friend, you have built a Kubernetes
I welcome a k8s replacement! Just how there are better compilers and better databases than we had 10-20 years ago, we need better deployment methods. I just believe those better methods came from really understanding the compilers and databases that came before, rather than dismissing them out of hand.
mac-chaffee··on Dear friend, you have built a Kubernetes
Author here. Yes there were many times while writing this that I wanted to insert nuance, but couldn't without breaking the format too much.

I appreciate the wide range of interpretations! I don't necessarily think you should always move to k8s in those situations. I just want people to not dismiss k8s outright for being overly-complex without thinking too hard about it. "You will evolve towards analogues of those design ideas" is a good way to put it.

That's also how I interpreted the original post about compilers. The reader is stubbornly refusing to acknowledge that compilers have irreducible complexity. They think they can build something simpler, but end up rediscovering the same path that lead to the creation of compilers in the first place.

mac-chaffee··on SAPwned: SAP AI vulnerabilities expose customers' cloud environments and privat
Shocked that there was a tiller instance running. That's been deprecated since 2020: https://helm.sh/blog/helm-v2-deprecation-timeline/
mac-chaffee··on AWS Secrets Manager Agent
The use-case seems to be intentionally narrow:

> The Secrets Manager Agent provides compatibility for legacy applications that access secrets through an existing agent or that need caching for languages not supported through other solutions.

mac-chaffee··on ChatGPT Edu
Some of the use-cases mentioned would mean FERPA applies: https://studentprivacy.ed.gov/faq/i-want-use-online-tool-or-...

Surprised FERPA wasn't mentioned explicitly. At least this version doesn't use the data for training, but I shudder to think of all the college administrators dumping student information into their personal ChatGPT accounts right now...

mac-chaffee··on Amazon Cloud Traffic Is Suffocating Fedora's Mirrors
Each with a unique public IPv4 address too!
mac-chaffee··on Mental health in software engineering
It's especially frustrating that I firmly believe operations is a solved problem, but good luck getting a company to adopt the practices that every other mature tech company has already figured out.
mac-chaffee··on Backdoor in upstream xz/liblzma leading to SSH server compromise
Build-related fixes are only treating the symptoms, not the disease. The real fix would be better sandboxing and capability-based security[1] built into major OSes which make backdoors a lot less useful. Why does a compression library have the ability to "install an audit hook into the dynamic linker" or anything else that isn't compressing data? No amount of SBOMs, reproducible builds, code signing, or banning binaries will change the fact that one mistake anywhere in the stack has a huge blast radius.

[1]: https://en.wikipedia.org/wiki/Capability-based_security

mac-chaffee··on Cloudflare Announces Firewall for AI
That would only be true if WAFs weren't so easily bypassed: https://habr.com/en/companies/dsec/articles/454592/
mac-chaffee··on Weaveworks is shutting down
I personally consider the ArgoCD UI an anti-feature. Attaching some hulking mass of Javascript dependencies to the thing that has cluster-admin rights to my production cluster is unnecessary attack surface for me.

ArgoCD also has its own auth system and permissions. You give ArgoCD cluster-admin rights, then it uses impersonation to pretend like it has lower permissions. One little bug there and you can trick ArgoCD into escalating your permissions, which happens a lot: https://github.com/argoproj/argo-cd/security/advisories/GHSA...

While not officially supported, you can technically deploy Flux with limited permissions, but ArgoCD's dependence on impersonation means it cannot run with lower permissions.

mac-chaffee··on I looked through attacks in my access logs
In actuality, WAFs hurt more than help. They give a false sense of security since they are so easily bypassable, plus they have a significant performance cost and a significant chance of blocking legitimate traffic: https://www.macchaffee.com/blog/2023/wafs/
mac-chaffee··on Ask HN: Does Cloudflare block HN comments if you have code blocks in a reply?
WAFs are 2000s-era software that have long overstayed their welcome: https://www.macchaffee.com/blog/2023/wafs/
mac-chaffee··on Qdrant 1.7.0
We have been working this year to increase our US presence, and we're hiring now: https://join.com/companies/qdrant/9929148-cloud-platform-dev...

Source: I work at Qdrant from the US :)

mac-chaffee··on ACM Code of Ethics and Professional Conduct
I wrote about this here: https://www.macchaffee.com/blog/2023/ethics-self-attestation...

Too many jaded technologists throw their hands up and just ignore ethics. At least ACM are _doing something_ about it.

mac-chaffee··on Tell HN: Firefox has madea lotof progress. Let the browser wars continue
The encryption Chrome uses isn't just some key on disk that can be scooped up. On macOS at least, it's stored in the secure enclave which only signed Chrome binaries can access.

Now all this is pointless due to Chrome allowing remote debugging, but Firefox could come along and do it right and it would actually be an increase in security. A random unsandboxed binary trying to access the key would be blocked by the kernel.

mac-chaffee··on Tell HN: Firefox has madea lotof progress. Let the browser wars continue
What I want next is for FireFox to do something to protect my cookies on disk. Chrome at least encrypts them using a key backed by the system keychain (although Chrome allows remote debugging from any other process, negating any benefits).

https://mango.pdf.zone/stealing-chrome-cookies-without-a-pas...

mac-chaffee··on Stop deploying web application firewalls
I actually wrote this post in preparation for a fight about WAFs with a SOC2 auditor, wish me luck! :)

The specific control says "Boundary protection systems (for example, firewalls, DMZs, IDS/IPS, and EDR systems) are configured, implemented, and monitored to protect external access points", which seems to leave room for doing stuff other than WAFs.

mac-chaffee··on Stop deploying web application firewalls
DDoS prevention is outside my area of expertise, so I'm not sure. I should clarify that this blog isn't referring to that use-case :)
mac-chaffee··on ‘Mind-boggling’ sea creature identified as digenean trematode
Kin selection takes place within a single species:

> The DNA confirmed that both the sailors and tiny passengers inside the hemisphere belong to the same species.

mac-chaffee··on Blocking Visual Studio Code embedded reverse shell before it's too late
Unfortunately, differentiating good behavior from malicious behavior is a central pillar of security, and the existence of this feature undermines that pillar.

* The fact that it's in a popular signed binary means it bypasses app allow-lists.

* The fact that it flows through Microsoft's servers bypasses firewall allow-lists.

* The fact that no stage2 is required bypasses antivirus scanning.

I say "unfortunately" because I personally think attempting to differentiate good behavior from malicious behavior is losing battle. Design-based or resilience-based security controls are the way to go IMO: https://kellyshortridge.com/blog/posts/control-vs-resilience...

mac-chaffee··on NFS > FUSE: Why We Built Our Own NFS Server in Rust
Funnily enough, "the end of time" for NFSv3 is in about 15-83 years, depending on whether the implementation uses signed or unsigned 32-bit integers for timestamps: https://lwn.net/Articles/717076/
mac-chaffee··on Kubernetes Exposed: One YAML Away from Disaster
DevOps still must draw the line somewhere. DevOps people typically don't physically plug cables into switches, for instance. With the ever-growing complexity of infra, I see that line having to shift more and more, with either PaaS products or platform engineering teams filling the space by providing something like Kubernetes as a service to the DevOps folks.
mac-chaffee··on Ask HN: Who wants to be hired? (August 2023)
Location: NC

Remote: Yes

Willing to relocate: No

Resume: https://www.macchaffee.com/

Technologies: Kubernetes, Linux Admin., Security, Python, Ansible, SRE, Platform Engineering

Email: On resume

mac-chaffee··on Ask HN: Could you share your personal blog here?
I write about DevOps (mainly containers and Kubernetes) and security stuff: https://www.macchaffee.com/blog/
mac-chaffee··on The problem with federated web apps
That looks closer to the right solution, but...

> Remember, your private key is your identity in Nostr, so if it is compromised you'll lose your followers and will have to start from scratch rebuilding your identity.

This is the same gripe I have with home servers on the fediverse: home servers come and go, and private keys sometimes need rotating. Making you lose all your friends and content when that happens is not an acceptable tradeoff.

I think the solution is entirely separating "identity" from every single other concern such as security (private keys), hosting (home servers), and public identity ("display name").

mac-chaffee··on SEC notifies SolarWinds CISO and CFO of possible action in cyber investigation
No, that was a separate incident: https://www.theregister.com/2020/12/16/solarwinds_github_pas...

From what I can tell, all we know is that the attackers definitely got into their build system (since the trojan was signed), and we know they moved laterally through exploits in various Microsoft products: https://en.wikipedia.org/wiki/2020_United_States_federal_gov...

Page 1 of 5Next →