Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Firehed
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
31 ms
·
301.
▲
by
Firehed
14y ago
My thoughts exactly. Once again, poorly-considered reactive security measures waste money and accomplish absolutely nothing useful. And we all know that as soon as this starts happening, they'll install security cameras to watch the securi
302.
▲
by
Firehed
14y ago
I vote for who I like the best, and that does not limit it to the two parties that have a chance of producing a winner. Abstaining from voting strengthens everyone else's vote that much more, indicating that I don't care who wins. I opt to
303.
▲
by
Firehed
14y ago
Yes, and PBKDF2 relies on other algorithms that have also shown problems. It's just looping and clever bitmasking (and takes about 10LOC to implement, assuming you have hash_hmac easily available). So if there's a problem found with sha256
304.
▲
by
Firehed
14y ago
People that want their messages private should be minimally aware of the technology they're using to transmit said messages. Nobody has a reasonable expectation of privacy when sending a postcard, and that's a decent analogy to email and ot
305.
▲
by
Firehed
14y ago
There's a lot of stuff that has to break. Theory being that (at least until there's a certain amount of momentum) the structure of the undamaged building will slow the collapse. Remember, the damage was three quarters of the way up the buil
306.
▲
by
Firehed
14y ago
> you can buy them to your name, and then after a few transfers/transactions it would take the collaboration of an army of disparate users worldwide to determine where did the coins come from Sounds exactly like money laundering to me,
307.
▲
by
Firehed
14y ago
I work with ex-PayPal engineers on similar systems. While I can't give numbers as they're confidential, our automated systems catch a lot of attempted fraud, and I know Paypal does far more payment volume and has much more sophisticated fra
308.
▲
by
Firehed
14y ago
Banks are not doing merchant processing for most people. Having some sort of reserve to guard against chargebacks is incredibly common in the industry; PayPal, however, is known for going completely over the top as the article and numerous
309.
▲
by
Firehed
14y ago
If it can't validate the cert, it could be the sign of a MITM attack. Likely? No, but I wouldn't take content with cert issues and run it as root. At least not without validating it in some other way.
310.
▲
by
Firehed
14y ago
Living in a city does not lend itself well to getting stuff done at night "when there are no distractions" precisely because those environments provide those nighttime distractions. Early founder schedules tend to be necessarily isolating
311.
▲
by
Firehed
14y ago
Probably due to the garbage SQL the framework generated for you, or the write-through cache it failed to provide. Yes, it's true that a simple request router will probably not add a lot of overhead, whether it came from a framework or was s
312.
▲
by
Firehed
14y ago
The new array syntax isn't a breaking change; however there was a lot of functionality deprecated in 5.3 that was completely removed in 5.4 which would definitely break some code. Unfortunately there were some bugs introduced in 5.4 that ar
313.
▲
by
Firehed
14y ago
Interesting point, although I don't consider email a platform like I do Facebook or Twitter. While there's no central database, there's a means of determining where the right server to talk to lives attached to the username. We'd need some
314.
▲
by
Firehed
14y ago
How many successful open-source platforms are there? I can't think of any. Unlike Free software, platforms have a maintenance cost (servers), and that cost cannot be paid by donated man-hours. The only thing close that I can think of is Bi
315.
▲
by
Firehed
14y ago
Sorry, no. Fees are paid to the issuing bank, acquiring bank, and network. The majority of it goes to the issuing bank, and that's the non-negotiable rate when you get a merchant account. That fee is known as the interchange fee. The pro
316.
▲
by
Firehed
14y ago
The pricing only applies to swiped payments, not keyed - so it's not an option. And if it was possible, it's definitely a TOS violation (though not illegal, unless someone thinks you're laundering money)
317.
▲
by
Firehed
14y ago
If the only thing you're selecting your merchant processor on is a couple of basis points , you're going to end up screwing yourself over regardless. You'll never get the real cost of processing out of a traditional merchant processor regar
318.
▲
by
Firehed
14y ago
The networks get very little (IIRC a small flat fee per transaction on the order of 5 to 10 cents, but I don't have our pricing in front of me and it's some of the most opaque pricing you'll ever see) - most of interchange goes to the issui
319.
▲
by
Firehed
14y ago
I see myself using Twitter a lot less if I had to use their mobile app, rather than a third-party one that doesn't suck (I use TweetBot exclusively). Conversely, I use no third-party Facebook applications, unless you count FB Connect as a m
320.
▲
by
Firehed
14y ago
Which Google makes in... about ten minutes (according to 2011 revenue of ~$38B). That's a rounding error if I've ever seen one, never mind the future revenue it will bring them: some customers will be a straight $300, the rest will be $70-1
321.
▲
by
Firehed
14y ago
It's always beneficial, that doesn't mean it's always worth it. I could spend $300+/month on an internet connection with a tenth of the bandwidth of what Google's rolling out here (seeing that I don't live in Kansas City) and it would certa
322.
▲
by
Firehed
14y ago
No, it does not. Here's a sample: function checkPassword($user, $posted_password) { return bcrypt(strtolower($posted_password), $user->saved_hashed_password) === $user->saved_hashed_password; } function setPassword($user
323.
▲
by
Firehed
14y ago
Or Instapaper v2? Paid upgrades have been around since the dawn of software, and there are plenty of companies that have been around long enough to show it works quite well. Adobe is a great example, and Microsoft as well although they've o
324.
▲
by
Firehed
14y ago
I know quite a few developers who only work on stuff that they hope will result in an acquihire. Can they guarantee it? Of course not, but I feel it's a pretty selfish approach to building something that's not just for your own use. For exa
325.
▲
by
Firehed
14y ago
Easy to build, hard to scale (although far easier than when Digg was first built). Also getting the voting algorithm right, assuming they're going to continue with that model, takes a lot of refinement. But yeah, overall I agree. Why would
326.
▲
by
Firehed
14y ago
This is a terrible idea - incredibly easy to bruteforce, among other things. You now have effectively a two-character password, and even though those characters rotate based on a different set of criteria, the number of valid possibilities
327.
▲
by
Firehed
14y ago
Actually, most of those lists are based on PHP4 or older (meaning their opinions are fully eight years out of date; a LOT has changed) or are made irrelevant by changing one or two quite well-documented confit settings. The little that's l
328.
▲
by
Firehed
14y ago
PHP was designed (I use the term loosely) to get dynamic websites up and running very quickly, and it's default configuration succeeds at that. So I don't think it's fair to call the loose error behavior a problem in PHP, as changing that
329.
▲
by
Firehed
14y ago
Uh, if you don't collect any personal information, COPPA isn't an issue. So if you don't ask for name and birthdate, you have no need to ask for their birthdate. To my knowledge, playing a game requires no personal information.
330.
▲
by
Firehed
14y ago
I totally agree. ORMs are not a bad thing and save you from writing the same code over and over again. The key is to understand what it's doing behind the scenes and not be afraid to go in and change it if it's generating stupid queries. Is
More ›