Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
DownGoat
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
DownGoat
7y ago
People are missing the point on why you should be using cotton bags instead. Yeah they are more expensive to produce, and it is doubtful if you will ever be able to use the cotton bag enough to balance out the production costs, but that was
62.
▲
by
DownGoat
7y ago
They knew about it long before that even. That carbon dioxide is a greenhouse gas, and questions about our use of fuels that produce it were raised in the late 1800 hundreds. Climate change is a problem that has been ignored for over 120 ye
63.
▲
by
DownGoat
7y ago
It better to add two different devices with different secrets to the account, than both sharing the same secret. This reduces the chances that something goes wrong when a device is lost, or removed. The user can the remove the other device
64.
▲
by
DownGoat
7y ago
Not including a linter in the earlier C compilers are one of the hughe mistakes of that area. Compilers absolutely should have linters, they are very valuable tools. Think about all the common security mistakes in your average C applicatio
65.
▲
by
DownGoat
7y ago
CAPTCHA is not a fool proof, it is just the first layer in of defence in the signup/login form. CAPTCHAS increases the cost of password spraying, attackers can't simply fire up Hydra. They'll need additional tools and service
66.
▲
by
DownGoat
7y ago
This is obviously a bad idea. It costs nothing for an attacker to send 3 http requests, every minute, every hour, all day. They could lock your account basically forever. IP filtering and locking accounts are terrible ways of preventing pas
67.
▲
by
DownGoat
7y ago
> If other people did this, but ended up doing it from an insecure machine and lost the credentials / got hacked, I can see why at least some orgs might want to prevent people from doing this. The measure is not really about protect
68.
▲
by
DownGoat
7y ago
> Why make me solve a Captcha to see static content? Fair point, I usually run into this when using Tor, or VPN when accessing content behind Cloudflare, and or similar services. This is some anti abuse stuff, but is often overly agressi
69.
▲
by
DownGoat
7y ago
You can search the CVE database, but it will give you a lot of vulnerabilities that were detected in apps on the platforms, and not only the platform itself. https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=android
70.
▲
by
DownGoat
7y ago
HTTPS everywhere is a good thing. HTTPS was never about protecting against phishing, and has never protected you against phishing. There is no way to educate people about phishing, only way to protect against it is U2F. Education against ph
71.
▲
by
DownGoat
8y ago
A Nvidia GTX 1080 can do about 20-25 GH/s of MD5. This makes the whole searchspace even without taking the vendor prefixes into account, quite brute forceable. Here is a benchmark of hashcat that gives some insights into the speed of t
72.
▲
by
DownGoat
8y ago
> The only feature that comes to mind is the absence of sync to other devices (which is kinda expected). Why is that expected? Just because things are encrypted does not mean that they shouldn't be syncable. Signal offers this.
73.
▲
by
DownGoat
8y ago
It depends on your needs, on the server side you are probably not missing much. Apollo tracing might be nice if you want some statistics on how your graph is consumed. The client side depends on the client, we have a Angular SPA that extens
74.
▲
by
DownGoat
8y ago
There was actually a trick for the PlayStation that allowed you to play pirated games without any hardware mods. It involved starting a game with the CD case open, and using your finger to stop the CD from spinning at certain points. I was
75.
▲
by
DownGoat
8y ago
If it actually takes so little effort, then why aren't they outcompeted by someone putting more effort into it? Is breaking big on Youtube only luck based?
76.
▲
by
DownGoat
8y ago
We as in the public can probably never be 100% sure of that, but looking at where the project started, and the current state of anonymous networks there is no real alternative. They are definitely using Tor to make attribution harder when r
77.
▲
by
DownGoat
8y ago
They rely on Tor themselves, they have a strong incentive to disclose/patch any major flaws in the protocol. They might exploit smaller flaws for a single operation, but they probably have more to earn from a healthy Tor network.
78.
▲
by
DownGoat
8y ago
An intelligence operation has different requirements. While those listed applications might hide the contents of the messages, you can still see that messages were sent/received, and that might be enough to warrant you for summary exec
79.
▲
by
DownGoat
8y ago
It is because dropbear is very common in embedded systems. They are commonly riddled with vulnerabilities, so they are getting hacked almost as soon as they are publicly reachable. This is not because of dropbear, but because they are typic
80.
▲
by
DownGoat
8y ago
Spam Nation by Brian Krebs is excellent. It delves deep into the email spam scene, and covers some big events and the people around it. He talks to users which buy stuff they are advertised in spam emails, and looks into the quality of the
81.
▲
by
DownGoat
8y ago
I'd download that.
82.
▲
by
DownGoat
9y ago
They usually contains real world business cases from point-of-view of a technical person. Thats fits well with a large portion of HN users.
83.
▲
by
DownGoat
9y ago
True, but this is not really a problem for the user, but a problem for the system. It is reasonable to assume that the user that creates these type of accounts does not really care about the security of the system either.
84.
▲
by
DownGoat
9y ago
Can you give any example of where the US has been caught giving IP stolen from espionage, to a domestic business purely to give the business a better advantage? Where there the IP had no military or security value? If they did this, which c
85.
▲
by
DownGoat
12y ago
In my experience Blizzard games has worked fine with wine. Did you try running the games with wine?
86.
▲
Iranian engineer finds out his computer problems were cause by Stuxnet
(automation.siemens.com)
1 points
by
DownGoat
12y ago
|
0 comments
87.
▲
by
DownGoat
12y ago
He has a private repo on GitHub, I wonder if it is the code for the site. https://github.com/blakeeb/private/commits?author=blakeeb
88.
▲
by
DownGoat
12y ago
Here is a Defcon video about the topic https://www.youtube.com/watch?v=hABj_mrP-no