Hacker Newsnew | past | comments | ask | show | jobs | submit | esseph's commentslogin

Too late. The data has been touched far too many times. The chain of custody and any accountability will never happen.

Just the opposite, caching is everywhere now. How do you think a CDN works?

But they also say "Here, this is Sarah your auditor. Answer these questions and resolve the findings." - every year

It's all CyberSecurity insurance compliance that in many cases deviates from security best practices.


This is where the problems come from. Auditors are definitely what ultimately causes IT departments to make dumb decisions.

For example, we got dinged on an audit because instead of using RSA4096, we used ed25519. I kid you not, their main complaint was there wasn't enough bits which meant it wasn't secure.

Auditors are snake oil salesman.


This is 100% it- the auditor is confirming the system is configured to a set of requirements, and those requirements are rarely in lockstep with actual best practices.

You mean immutable?

That wasn't what I was thinking about. There's a phrase for it using active and back up partitions but I can't find what it's called

A/B updates?

I'm not giving game ownership of my kernel, that's fucking insane. That will lead to nothing but other companies using the same tech to enforce other things, like the software you can run on your own stuff.

No thanks.


> Ubuntu just recently got a way to automate its installer (recently being during covid). I think you can do the same on RHEL too. But that's largely it on Linux right now. If you need to admin 10,000+ computers, Windows is still the king.

1. cloud-init support was in RHEL 7.2 which released November 19, 2015. A decade ago.

2. Checking on Ubuntu, it looks like it was supported in Ubuntu 18.04 LTS in April 2018.

3. For admining tens of thousands of servers, if you're in the RHEL ecosystem you use Satellite and it's ansible integration. That's also been going on for... about a decade. You don't need much integration though other than a host list of names and IPs.

There are a lot of people on this list handling tens of thousands or hundreds of thousands of linux servers a day (probably a few in the millions).


Nah, they hate Altman, and many are running DeepSeek @ home.

Even if they run DeepSeek at home, it is still AI.

Those who have principles in hating AI should never touch it or use it and swear by that.


Because they've literally been creating stories about A16Z.

I've posted about some and they just get instaflagged or hidden.


I'm sure all of that is true, but so is "Department of Defense".

They're also the largest holder of IPv4 space, still. https://bgp.he.net/report/peers#_ipv4addresses


Why does the DoD hold so many IPv4s?

They were assigned a huge prefix at the creation of the internet iirc

ARPANET, precursor to the internet, was a DoD project.

Connecting with previous and current coworkers. Then leveraging that network for jobs, many of which may not even get posted.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: