Hacker Newsnew | past | comments | ask | show | jobs | submit | plausibilities's commentslogin

Wasn't NordVPN recently pwned via an IPMI security hole?

iLO is kind of a piece of crap, but I do love my Xen and resource pools


Pretty sure the IPMI software is crap no matter the brand. I know the SuperMicro one requires a very old Java version fat client to interact with it, and is very flaky.


The newer versions finally support a HTML5 console instead of the old java webstart horror they used to ship with.


Also, if you need to interact with a Supermicro BMC that doesn't support the HTML5 console (for example, because it's running older firmware), I reverse-engineered the proprietary "iKVM" protocol (along with a lot of other parts of the BMC) and implemented support for it on a branch of noVNC, which you can find here: https://github.com/kelleyk/noVNC


Waaaat! Praise be. Now I can justify the last 45min reading HN...


Thank you for your contribution!

Keeping that "Just buy a shitload of cheap-o eBay 2U/4U hand-me-downs" workflow viable for years to come :D


Indeed. We have used this in production for some time now!


Yes, but that stuff isn't actually IPMI. You normally only need it if need a graphical console (or haven't re-directed to the IPMI serial link), or need to mount a boot image, which is typically painfully slow. (FreeIPMI and associated tools like conman are good for IPMI management, with a set of workarounds for defective implementations.)


People in wealthy gated communities often don't lock their front doors. Similar principle.


They're being snarky and accusing you of being an edgelord.

Your level of detachment feels extreme to them and upsets them and thus they've deemed it a gimmick/act.


You didn't see this coming considering how long they've been pushing the "Single File Component" narrative?

https://vuejs.org/v2/guide/single-file-components.html


Yeah but some clueless hiring manager will read it and think he's a proactive go-getter or some shit like that


Employer making me choose between career advancement and LOB success and then tying my job security to the latter.

I usually have comparable or better options available at any given time due to the sheer number of recruiters who are constantly floating things my way.

An up-to-date, relevant skillset is worth a potential 5 figure pay bump in the near future, which tends to be much more lucrative than slightly increased job security at my current pay rate.

They usually get one screw-up before I skip out for a better paying gig.

Fool me once, shame on you. Fool me twice, shame on me.

Have more than tripled my salary in the last 6 years hopping around like this.

But honestly, I'm also just not a fan of management styles which attempt to extract additional value via appeals to fear.

Usually if I see workplace management react to crunch time by letting shit roll downhill while making negative implications about how resistance might impact job security, that instantly puts me in job hunting mode.

I might stick around for a bit to help out people on my team that I actually like, but at that point I'm already mentally checked out and looking for my next gig.


:kappa:


greybeard spotted :P


If you're not a scrub, go through non-scrub recruiters, and manage to get through a handful of high-vis projects relatively unscathed, word travels extremely quickly and from then on out you can pretty much coast mostly on reputation.

It's a small world out there sometimes.


We've all already been successfully trolled.

The well has already been poisoned.

Paranoia has now been compounded.

Clarity regarding contemporary domestic political landscape has now been further muddled.

Effective astroturfing was always a secondary objective.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: