HNHacker News
TopNewBestAskShowJobs

sajagi

112 karma · joined June 15, 2017

submissionscomments
sajagi··on Ask HN: What are the best websites that the Anglosphere doesn't know about?
Best worldwide outdoor map there is, with offline support. I use it very often to find trails not even locals know about (e.g. Japan). Don't forget to switch to Outdoor mode!
sajagi··on Show HN: Lightweight SFTP Server for Windows
There is an optional (web) gui. However the primary audience is for those who prefer scriptability (or console/config files in general) over GUIs.
sajagi··on Apple's New Map
Google and Apple get all the glory - but some of you folks might find mapy.cz useful, esp when traveling abroad. Mobile app offers even offline tourist maps for the whole world, including contours -- https://en.mapy.cz/turisticka?x=-119.7422922&y=37.8326869&z=...
sajagi··on Ask HN: As a team lead how to handle project going off the rails?
It all depends on what kind of company are you in, what kind of people are your superiors, etc. How much politics and backstage dealing is involved?

In an ideal situation I would say call be honest and tell the stakeholders your view.

On the other hand, from my corporate experience, it's not always the best course of action. See - as lwj1001 already said - some companies play sort of meta-game, where certain things are known but never said out loud. If you are in a position to change the environment - great! (But this is not likely the best opportunity to do so). Otherwise... I would still say your opinion to those who need to be informed, or even better - write them an email. The reason is - you might have to cover your ass in the near future. The worst that can happen is that everyone assume everyone know yet there is someone who doesn't.

sajagi··on SSH Check – public SSH server testing tool
It's quite probably because of compatibility with the older clients. Unfortunately you can't simply use only the safest algorithms out there because the clients wouldn't be able to connect :/
sajagi··on SSH Check – public SSH server testing tool
I actually decreased the cache expiry to 10 seconds instead, I believe that should be ok for everyone.
sajagi··on SSH Check – public SSH server testing tool
(disclaimer: I work for Rebex)

SSH libraries written by Rebex. With the exception of ECC it's all closed-source.

sajagi··on SSH Check – public SSH server testing tool
Alright, thanks!
sajagi··on SSH Check – public SSH server testing tool
I'll take a look - it will take some time as I am currently swamped. Can you please check again in few days? Thanks!
sajagi··on SSH Check – public SSH server testing tool
I totally understand your concern.

However, here's my perspective:

- if the server is public already then black hats can simply probe your networks (IPv4 is not that big) and find the servers by themselves. The odds are that hackers are probably not interested in your company anyway.

- there are people who don't care about security of their servers (or rather are lazy / naive) and might find this service useful. Even if we were black hats it would at last alarm them that something is wrong. If they ignore the warnings - well - god help them.

EDIT: typos

sajagi··on SSH Check – public SSH server testing tool
Hi andreaso, do you happen to have a list of encryption algs on your side? We don't support chacha20-poly1305 (yet) and afaik aes in gcm mode, but e.g. aes ctr are reliable so I find it strange these are not supported on your side.
sajagi··on SSH Check – public SSH server testing tool
I am tempted to not interfere with the darwinian process ;) But seriously, we'll probably add some note like that.
sajagi··on SSH Check – public SSH server testing tool
It is not, but thanks for sharing that link, looks very useful!
sajagi··on SSH Check – public SSH server testing tool
Even if the IP address was guaranteed static then I wouldn't dare recommending admins to add an exception to firewall. That would certainly be a very bad practice. There are tools available (mentioned in the comments around) that do the same job and can be run in the DMZ (the question is, would anyone go through the source code and verify the tool does not contain any malicious code?).
sajagi··on SSH Check – public SSH server testing tool
I think it's more the other way round. You already have a public SSH server for whatever reason (e.g. hosting, tunelling, ...) and you might use this tool to check its capabilities.

The reputability of such service or even existence thereof does not have anything to do with how much your server is or is not secured.

sajagi··on SSH Check – public SSH server testing tool
Hi hannob, I'll re-check the classifications. Pretty sure you're right about the hmac-sha1 being still ok. Wrt oakley 14 and umac64 (and others) I'll try to add more detailed justifications. Thanks for your comment!
sajagi··on SSH Check – public SSH server testing tool
you have to wait 10 minutes ... I am adding a refresh button as we speak.
sajagi··on SSH Check – public SSH server testing tool
i am adding refresh button to my to-do list! :)
sajagi··on SSH Check – public SSH server testing tool
hi snvzz, which server did you try it on? i tried few ipv6 servers and it was ok.