Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
8organicbits
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
31.
▲
by
8organicbits
2mo ago
I think that statement is vacuous true for all magical thinking.
32.
▲
Forer Effect
(skepdic.com)
4 points
by
8organicbits
2mo ago
|
0 comments
33.
▲
by
8organicbits
2mo ago
The low hanging fruit are claude.md, commits co-authored by Copilot, etc.
34.
▲
by
8organicbits
3mo ago
> wasn't until late December of last year that AI models started to demonstrate particularly interesting capabilities What are you referring to here?
35.
▲
WordPress – Polls for ActivityPub
(wordpress.org)
1 points
by
8organicbits
3mo ago
|
0 comments
36.
▲
by
8organicbits
3mo ago
Does this actually remove from history? The feature says escape, but the back button and history still show the page (Firefox on Android).
37.
▲
by
8organicbits
3mo ago
I think it's about user agency. When we say that infinite scroll is addictive, we mean that the user keeps on scrolling even when they wish they could stop. It's also about harm. Trapping users on their phones is harmful to their
38.
▲
by
8organicbits
3mo ago
Forgejo is mention in the article, it powers Codeberg. I agree it doesn't have high adoption, but the news is that it is growing.
39.
▲
by
8organicbits
3mo ago
I may complain that I don't like the way a sleezy con man talks, and I may be able to detect his communication patterns, but that doesn't mean I want the con man to speak in a different way I can't detect as sleezy. I don
40.
▲
by
8organicbits
3mo ago
> respecting the reader When people say LLM slop is disrespecting the reader, I don't think they are complaining about style.
41.
▲
by
8organicbits
3mo ago
The unlisted video indexes still exist. https://unlistedvideos.com is one example.
42.
▲
by
8organicbits
3mo ago
This is an important point, private videos should not be impacted by this as knowing the URL isn't enough to access the video. Unlisted videos are indirect-object reference by design. It's poor security, but the user is expected t
43.
▲
Convert your RSS feeds into a static website
(xda-developers.com)
4 points
by
8organicbits
3mo ago
|
0 comments
44.
▲
by
8organicbits
3mo ago
I'm seeing a ton of restricted mode escapes documented online, like https://0xffsec.com/handbook/shells/restricted-shells/ so I'm not so sure. When basic utilities like less, man, and awk can run su
45.
▲
by
8organicbits
3mo ago
Does that work? I've never seen it used. It seems easy to escape. The docs seem to suggest using alternate approaches. > Modern systems provide more secure ways to implement a restricted environment, such as jails, zones, or contain
46.
▲
Assess the security of email communication between providers
(mecsa.jrc.ec.europa.eu)
2 points
by
8organicbits
4mo ago
|
0 comments
47.
▲
by
8organicbits
4mo ago
Cool tool, I'm also surprised by how different the startup stacks are from the general Internet. For HSTS, don't forget to check the preload list. Domains under .dev are all preloaded, for example, so they don't need to set t
48.
▲
by
8organicbits
4mo ago
> How can you check other people's certs? There are red flags you can look for, but you need to confirm with the domain owner to be sure. CAA records can tell you what CAs are supposed to issue a certificate. Many companies always u
49.
▲
by
8organicbits
4mo ago
Is there a detection component here too? Sandboxing development is great, but the next step is to deploy to production. How do you know if something malicious happened in the sandbox, such that you don't deploy the malware further?
50.
▲
by
8organicbits
4mo ago
> money will shift to those funds that do better I'm not disagreeing that people invest this way, but I'd like to point out that past performance does not imply future performance, and that investors should consider factors oth
51.
▲
The Shift in Peering Threatening the Internet's Foundations
(internetsociety.org)
10 points
by
8organicbits
4mo ago
|
0 comments
52.
▲
by
8organicbits
4mo ago
Of course plugins that do this already exist. Save your tokens.
53.
▲
Virtual Precision Clock
(mitxela.com)
2 points
by
8organicbits
4mo ago
|
0 comments
54.
▲
by
8organicbits
4mo ago
They probably meant it hyperbolically, but RSS was on a downward slope during that period. The recent uptick is fascinating. https://trends.google.com/explore?q=%2Fm%2F0n5tx&date=all&ge...
55.
▲
by
8organicbits
4mo ago
Anyone know the best practices for keeping AI crawlers off your RSS feeds? I know robots.txt works for the well-behaved bots. Other tools like interstitial captchas don't as the feed readers break if you send them anything but XML. Put
56.
▲
by
8organicbits
4mo ago
These approaches are obviously great if your goal is to force marketing down people's throats, but it kills the integrity of the platform. I don't get why people would continue using Google search (other than familiarity/mome
57.
▲
by
8organicbits
4mo ago
If someone enters a username that doesn't exist in the system then you randomly prompt for password or alternate method, so it looks like an account may exist. Username enumeration isn't usually considered a vulnerability, but it
58.
▲
by
8organicbits
4mo ago
I have it partially right. The extensions are not yet mandatory. https://www.feistyduck.com/newsletter/issue_137_acme_caa__ex...
59.
▲
by
8organicbits
4mo ago
One suggestion for anyone concerned about this weakness. You can use the CAA record to pin the domain to a specific certificate authority, issuance method, and account. This is imperfect, as CAA record validation (edit: of CAA extensions) i
60.
▲
Acme CAA Extensions to Become Mandatory
(feistyduck.com)
3 points
by
8organicbits
4mo ago
|
0 comments
More ›