Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Deathmax
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
Deathmax
3y ago
This depends on which service you are using, any of the free products allow for training, but the paid services do not. Allows training on input: 1. Gemini (formerly Bard): https://gemini.google.com/ . Policy: https:/&
62.
▲
by
Deathmax
3y ago
To expand on that, Cloudflare's standard product is their HTTP reverse proxy. To proxy arbitrary TCP/UDP traffic, you need to use their Cloudflare Spectrum service ( https://www.cloudflare.com/en-gb/application
63.
▲
by
Deathmax
3y ago
Data is crowdsourced and contributed by users. On a much larger scale, Apple and Google collect data from iOS and Android devices to power their WiFi/mobile tower based geolocation services. Android's Location Services: https:&#x
64.
▲
by
Deathmax
3y ago
Battleye has integrations with Proton as well, but as with EAC, it's opt in by the developer, and not every dev enables it.
65.
▲
by
Deathmax
3y ago
> Okta for example charges $2 just for sign in: https://www.okta.com/pricing/ You're looking at the wrong product, $2/user/month is for their Workforce Identity Cloud, so auth for employees, not end u
66.
▲
by
Deathmax
3y ago
For WSJ at least, it appears that archive.is is fetching the AMP page, which returns the full content of the article and is hidden with CSS, and modifying the page to unhide the paywalled content + hide ads. It might be using other techniqu
67.
▲
by
Deathmax
3y ago
You might not be on a "Always Free" account then. AFAIK, you're not subject to reclamation if you add a payment method to the account. Here's the link to their documentation on reclamation of idle resources: https:/
68.
▲
by
Deathmax
3y ago
From what I understand, checking that a certificate has been submitted to CT logs should not have privacy implications, only trust in a set of CT logs and their public keys to be able to verify Signed Certificate Timestamps (SCTs). SCTs can
69.
▲
by
Deathmax
3y ago
> In my opinion, most of the governments must have obtained access to numerous Certificate Authority private keys by now. As a result, they would not only be logging DNS records but also the entire unencrypted data transfer. Certificate
70.
▲
by
Deathmax
3y ago
> I searched for a couple hours last week and couldn't find a single way to submit a CCPA request to Google. 1. Navigate to google.com 2. Click on Privacy on the bottom of the page, redirecting to https://www.google.com&#
71.
▲
by
Deathmax
4y ago
GitHub does have support for SSH CAs, but it's an Enterprise feature: https://docs.github.com/en/enterprise-cloud@latest/organizat...
72.
▲
by
Deathmax
4y ago
In the UK Ofcom recently (2020) relaxed the rules on Band C channels (channel 140+) to allow for indoor non-licensed use. These have been a godsend in a crowded environment, as the lower non-DFS channels are very crowded, while the DFS chan
73.
▲
by
Deathmax
4y ago
> As far as I know, the merchant always bears the full liability for fraud, whether you use 3ds or not. This is very much untrue. If a merchant initiates the 3DS flow, liability for fraudulent transactions shifts from the merchant onto t
74.
▲
by
Deathmax
4y ago
The actual TOTP secrets are (or should be) encrypted with the backup password that the user chose, so access to the backups wouldn't automatically result in compromised TOTP secrets unless the backup password was weak.
75.
▲
by
Deathmax
4y ago
I'm guessing it's http://people.csail.mit.edu/venkatar/cc-starvation.pdf
76.
▲
by
Deathmax
4y ago
EE's Content Lock is enabled by default, and is called out in the article itself. To opt out of Content Lock, you must undergo age verification, either via ID checks in person at the store, or via a credit card. Please note: All new an
77.
▲
by
Deathmax
5y ago
You would want to host the status page on completely independent infra, such that if your service goes down, it doesn't take down the status page as well. This includes DNS, hence the separate domain. For example, with Facebook's
78.
▲
by
Deathmax
5y ago
Which would justify Apple using on-device scanning more if iCloud is end-to-end encrypted, except that it isn't. Apple has the technical capability to decrypt photos stored on iCloud, so why risk the slippery slope and governments appl
79.
▲
by
Deathmax
5y ago
Salts being exposed is not a massive risk in of itself, as the purpose of the salt is to prevent the use of pre-computed tables to reverse a hash into plaintext, forcing an attacker to bruteforce each individual hash+salt instead of being a
80.
▲
by
Deathmax
5y ago
And you no longer have to worry about the meanings of positional arguments changing between versions and potentially running the wrong command.
81.
▲
by
Deathmax
5y ago
There's two Let's Encrypt issues at play at the moment. The issue that your comment about cached/discovered intermediates relates to is that some servers were still manually constructing the chain that goes leaf -> R3 ->
82.
▲
by
Deathmax
5y ago
The firewall would need to be able to handle all the DDoS traffic as well, since your current idea would still pass the game server's IP back to a client. This is doable if you're hosting on a cloud provider and let their firewall
83.
▲
by
Deathmax
5y ago
Do you verify that the document is signed by a country's CA, and if so, do you have a list of countries and document types that you are able to validate against (since procuring the CAs is probably the more annoying bits for this type
84.
▲
by
Deathmax
5y ago
There's a lack of documentation since this isn't officially released yet, but my assumption is that you need write permissions to id-token in order to generate a JWT. As forked repos can at most get read access[1], presumably that
85.
▲
by
Deathmax
5y ago
GCP does allow you to sign into a service account using OIDC credentials. Docs: https://cloud.google.com/iam/docs/access-resources-oidc
86.
▲
by
Deathmax
5y ago
They don't do cloud hosted machines anymore, but the client is still free. You pay to get additional features (full 4:4:4 color, multi-monitor, drawing tablet support, and other enterprisey features). https://parsec.app/
87.
▲
by
Deathmax
5y ago
Starling[1] and Monzo[2] have their own APIs accessible to end users which are not Open Banking[3]. Monzo has a separate set of OB APIs and AFAIK Starling doesn't have an OB API as only the big, high-street UK banks (HSBC, Barclays, RB
88.
▲
by
Deathmax
5y ago
> Don't disclose to the client anything not in their view. Either full of edges cases (how do you efficiently compute visibility, and can you prevent models from popping in as a result of latency) or computationally expensive[0]. Va
89.
▲
by
Deathmax
5y ago
You get to make changes without having to respect the GPL and thus no longer obligated to provide those changes to your end users, as you have effectively laundered the kernel source code by passing it through an "AI" and get to r
90.
▲
by
Deathmax
5y ago
GitHub says you don't need to credit GitHub for any of the code suggestions, but since it's trained on public sources of code, anyone have a clue on potential licensing pitfalls?
More ›