Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
DGAP
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
91.
▲
by
DGAP
7y ago
Yes! But that has various pros and cons as well.
92.
▲
by
DGAP
7y ago
Boldyreva
93.
▲
by
DGAP
7y ago
If you like Ptacek, read this: https://latacora.micro.blog/2019/07/24/how-not-to.html But more importantly, why do you need stateless auth tokens?
94.
▲
by
DGAP
7y ago
Anyone who's ever worked with Sift knows this is an unfair characterization. It reads like every other article in the NYT about tech or cybersecurity - uneducated fear mongering.
95.
▲
by
DGAP
7y ago
I'm pretty sure 90% of my friends and peers in the 21 - 25 cohort receive financial help from their parents. This is due to the fact that they're either still in school, which is increasingly expensive, or that they can't fin
96.
▲
by
DGAP
7y ago
Why not just use any of the number of existing satellite telecoms providers?
97.
▲
by
DGAP
7y ago
Favor Delivery | Austin, Texas (TX) | Android, Frontend, Senior, Backend, Test Automation, QA Analyst, QA Manager | Onsite | Full-time | https://jobs.lever.co/askfavor?lever-via=WUDy1PL7mZ We're an on-demand delivery c
98.
▲
by
DGAP
7y ago
Favor Delivery | Austin, Texas (TX) | Android, Frontend, Senior, Backend, Test Automation, QA Analyst, QA Manager | Onsite | Full-time | https://jobs.lever.co/askfavor?lever-via=WUDy1PL7mZ We're an on-demand delivery c
99.
▲
by
DGAP
7y ago
Looking for more anecdotal evidence, if you had to run an AV what would be the lowest impact?
100.
▲
by
DGAP
7y ago
Favor Delivery | Austin, Texas (TX) | Android, Frontend, Senior, Backend, Test Automation, QA Manager | Onsite | Full-time | https://jobs.lever.co/askfavor?lever-via=WUDy1PL7mZ We're an on-demand delivery company based
101.
▲
by
DGAP
7y ago
AWS has Macie to catch this sort of thing, not to mention the usual AWS security automation tools available like Security Monkey. Or the fact that a pen test should have caught this, or employees following the data use policy.
102.
▲
by
DGAP
7y ago
This article is a great illustration to me as well of how hard it is to do security right even if you're a professional, much less a developer who's mostly responsible for implementing features not building secure systems. The int
103.
▲
by
DGAP
7y ago
Agreed - but for non-technical consumer 2FA, there's really no other option that users are actually going to use. And SMS 2FA is still orders of magnitude better than just passwords when your threat model is credential stuffing and wea
104.
▲
by
DGAP
7y ago
And if you use 2FA, then it raises the cost of compromising your account to that of a targeted phishing attack at worst. That's an entirely different threat model.
105.
▲
by
DGAP
7y ago
Triple the estimate.
106.
▲
by
DGAP
7y ago
Unfortunately, using Google Tag Manager basically requires setting 'unsafe-inline', neutering your CSP.
107.
▲
Good Security Engineer/Bad Security Engineer
(medium.com)
2 points
by
DGAP
7y ago
|
0 comments
108.
▲
Matrix is hacked, hacker leaves friendly post-mortem on GitHub
(twitter.com)
56 points
by
DGAP
7y ago
|
6 comments
109.
▲
by
DGAP
8y ago
...that depresses me on several levels.
110.
▲
by
DGAP
8y ago
Excellent list - I immediately ctrl+f'd for Schneier's law as it's my favorite crypto axiom. My only suggestion would be adding: "Crypto is like catnip for programmers."[1] [1] https://blog.pinboard.in&#x
111.
▲
by
DGAP
8y ago
We do hear about it, and in the Western press primarily: https://www.nytimes.com/2017/05/20/world/asia/china-cia-spie... The difference is that when US-run agents get burned, they get publicly execu
112.
▲
by
DGAP
8y ago
Selective Klotho Re-uptake Inhibitors? SKRIs?
113.
▲
by
DGAP
8y ago
Not a great look for Stamos.
114.
▲
by
DGAP
8y ago
You or your business are much more likely to have your information stolen because of credential theft than someone discovering and exploiting vulnerabilities. This is regardless of whether your attacker is a nation state or a cheating stude
115.
▲
by
DGAP
8y ago
Maybe you do, but you obviously shouldn't.
116.
▲
by
DGAP
8y ago
Eh, most airlines going for satellite WiFi aren't doing it out of the goodness of their hearts - they're doing it because the unit economics make sense. There are exceptions like JetBlue who offer it for "free" though.
117.
▲
by
DGAP
8y ago
Long bitcoin in 2019? Brave.
118.
▲
by
DGAP
8y ago
My personal law from working in software consulting is "triple the estimate."
119.
▲
by
DGAP
8y ago
They'd only work for campuses, with elevators in all the dorms.
120.
▲
by
DGAP
8y ago
Somewhat ironically, the Israelis have their own, cruder, initialism for this.
More ›