Hacker News new | past | comments | ask | show | jobs | submit | dysinger's comments login

Is this hacker news? Where do I go to read news about hacking?


Larry Ellison is closely associated with a prominent technology company.


This 1 page poorly titled wrong rant is the #2 story on this site?

"Ever tried to security update a container?" lol. you are doing it wrong.

"Essentially, the Docker approach boils down to downloading an unsigned binary, running it, and hoping it doesn't contain any backdoor into your companies network." nope https://blog.docker.com/2014/10/docker-1-3-signed-images-pro...

"»Docker is the new 'curl | sudo bash'«" no it's not. most intelligent companies are building their own images from scratch.

People that care about what's in their stack take the time to understand what's in there & how to build things.


I think you're wrong. I think most users are not installing trusted builds from their OS vendors. Piping curl to bash is incredibly common--many popular software packagers are doing it [1].

About a year and a half ago, I was playing around with Docker and made a build of memcached for my local environment and uploaded it to the registry [2] and then forgot all about it. Fast-forward to me writing this post and checking on it: 12 people have downloaded this! Who? I have no idea. It doesn't even have a proper description, but people tried it out and presumably ran it. It wasn't a malicious build but it certainly could have been. I'm sure that it would have hundreds of downloads if I had taken the time to make a legit-sounding description with b.s. promises of some special optimization or security hardening.

The state of software packaging in 2015 is truly dreadful. We spent most of the 2000's improving packaging technology to the point where we had safe, reliable tools that were easy for most folks to use. Here in the 2010's, software authors have rejected these toolsets in favor of bespoke, "kustom" installation tools and hacks. I just don't get it. Have people not heard of fpm [3]?

[1] http://output.chrissnell.com/post/69023793377/stop-piping-cu...

[2] https://registry.hub.docker.com/u/chrissnell/memcached/

[3] https://github.com/jordansissel/fpm


It appears this was finally changed mid-March, but after initial release in December image signing initially worked as follows:

Docker’s report that a downloaded image is “verified” is based solely on the presence of a signed manifest, and Docker never verifies the image checksum from the manifest. An attacker could provide any image alongside a signed manifest.

https://news.ycombinator.com/item?id=8788770

https://titanous.com/posts/docker-insecurity

https://github.com/docker/docker/issues/9719

edit: add hn discussion, github issue.


Who cares?


Dear posters that post things like this: Did you delete your account? No? You Suck. Just delete your FB account. You'll feel better.



he's a sheeple like most of america. most of america cares about xbox more than they care about the constitution.


While I (as an American) resent the implication, it is unfortunately very true.

I hear arguments daily on the subject of the new Xbox and M$'s latest privacy invasion, but most everyone has no clue who Ed Snowden is or what NSA/PRISM are all about.


I just went and looked too and all my content going back to 2007 which a painstaking hand deleted is back(!)

I hope mark zuckerberg ends up broke doing LAMP consulting.


Boo for reusing Chicken scheme's name.


Puppet is mature and has tons of cookbooks & community. You may not like it but saying it "sucks" is not right. It works and is used tons.

Chef doesn't run over SSH in any environment I've used that wasn't a toy (vagrant w/ chef-solo). Please fact check.

Fanboy article.


No


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: