Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
InitialBP
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
InitialBP
2y ago
Kipchoge is less like "quietly focusing on a sustainable career" and more like "consistently maintaining the highest quality and pace of development and rarely if ever having an off week".
32.
▲
by
InitialBP
2y ago
Your example isn't a very good one. If you are 99.99% as good as the next candidate you get no job? How about you get a different job because you're still a top performer. Most (all?) jobs don't have only a single role to be
33.
▲
by
InitialBP
2y ago
Agree with you if privacy first is the goal then open sourcing it is absolutely the right move. However, it IS still possible to MITM these days - although more difficult. frida.re has a ton of useful features and community tooling built ar
34.
▲
by
InitialBP
3y ago
I don't think this is entirely true. If people who are currently renting move into homes then their apartments will be rented to people who are looking for housing. It seems like if you add supply to one area of the housing market like
35.
▲
by
InitialBP
3y ago
That seems like a super obvious conclusion, the fact that it isn't what is actually happening is a good indication that it isn't as straightforward as you'd think. This might be true for an individual that only owns one or tw
36.
▲
Learning Apple/pkl for K8s templating
(medium.com)
1 points
by
InitialBP
3y ago
|
0 comments
37.
▲
by
InitialBP
3y ago
Bit of a rambly reply: There are different types of web security vulnerabilities and the attacks you see from automated scanners are likely to be far less sophisticated than targeted web attacks. Specifically these scanners are going to spa
38.
▲
by
InitialBP
3y ago
> ancient exploitation strings from 30 years ago that haven't worked on any serious webserver since that time Unfortunately, there are plenty of serious (business critical) servers that _ARE_ vulnerable to these types of attacks. I&
39.
▲
by
InitialBP
3y ago
Think about motivations for a moment. The seller is motivated to make the buying process as easy, fast, and uncomplicated as possible. This is a direct correlation with how many things they sell, and in response how much money they make. On
40.
▲
by
InitialBP
3y ago
1Password can do this for you, and I assume many other password managers as well. https://support.1password.com/one-time-passwords/
41.
▲
by
InitialBP
3y ago
Business don't want online shopping to be high-friction, but Thankfully consumer opinion is pushing more for security and less for making it as easy as possible to buy stuff online. I'll happily take this shit-show cacophony of va
42.
▲
by
InitialBP
3y ago
If this was something used only by your company or a specific project, then I’m absolutely on board. However, this is in a library used in thousands (millions?) of projects. Since it’s potentially a breaking change you can’t just change it
43.
▲
by
InitialBP
3y ago
From a security angle... .net webapps written in asp.net behave similar to PHP in that any file with a .aspx extension that is within the web root will execute by default. This means that asp (and php) webservers are particularly vulnerable
44.
▲
by
InitialBP
3y ago
This already IS a huge problem in the medical/health vertical. You should NEVER order supplements, makeup, or medicines/chemicals from Amazon for this reason. I think there have been a few different noteworthy events where issues
45.
▲
by
InitialBP
3y ago
I think most people would agree that you should support the local version of a business over the financial district version because you want to keep people employed in your community, but at the same time I personally would rather support l
46.
▲
by
InitialBP
3y ago
Definitely agree with you here. The parent has a very valid point about not always over-securing things that don't need to be secured, but physical line cutting and wireless shutoff are very different threats. Someone walking around yo
47.
▲
by
InitialBP
4y ago
If you want to do deployments with single-file apps or other "whole stack in a single process" type of deployments there are other options to do it with zero-downtime. One good option would be to spin up a second server/insta
48.
▲
by
InitialBP
4y ago
That's true of many illegal things. Trespassing is illegal, but people still put locks, gates, fences, etc on their property because people will still trespass if they want to. The purpose of the law is to dissuade people from doing
49.
▲
by
InitialBP
4y ago
If you removed it from the app stores, a humungous percentage of people would no longer install the app. There will certainly be some tech literate folks who do so, but most people have very little tolerance for technical challenges outside
50.
▲
by
InitialBP
4y ago
According to the report, the replay attack is only valid for 1 hour for login links, and 1 week for sign up links. I agree that there's some risk here, but the fix is probably straightforward (adjust timing to something more realistic
51.
▲
by
InitialBP
4y ago
I'd go a step further and stay the author is really making security researchers look bad. Can't really blame anyone for being concerned about corporate retaliation, but there are most certainly institutions that would send an emai
52.
▲
by
InitialBP
4y ago
Either I'm missing something here or the login CSRF explained in the report is a very weird and not exceptional impactful vulnerability. As described the author is talking about using a CSRF attack to force someone to authenticate to a
53.
▲
by
InitialBP
4y ago
Unrelated recommendation - 1Password will scan QR codes and can store TOTP 2fa tokens for you. I assume other password managers also have similar features.
54.
▲
by
InitialBP
4y ago
You can't put a hyperlink on a magazine, the tv, or the radio. There are definitely reasonable applications of shortened URLs that apply outside of the normal day-to-day web browsing and applications.
55.
▲
by
InitialBP
4y ago
I'm fully in agreement with all of your downsides (although ads aren't necessarily a dealbreaker for me). The pain point for me is that my family/friends circle isn't willing to try and use new software especially stuff
56.
▲
by
InitialBP
4y ago
It's worth noting that there was a lot of pressure from the major browsers to deprecate flash due to security issues throughout the years. Flash produced a lot of great media but in the end it wasn't built with security in mind, a
57.
▲
by
InitialBP
4y ago
Just to play devils advocate, what if you just made a private subreddit for your family? While I also struggle with the android/apple divide in my family I feel like getting them all to agree to use an existing social platform would be
58.
▲
by
InitialBP
4y ago
Maybe not "essential" but I'm willing to guess that a huge percentage of the modern web communicates over HTTP or HTTPS. "Essential" is interesting because you could definitely argue that HTTP isn't essential,
59.
▲
by
InitialBP
4y ago
Tex also makes keyboards with a trackpoint. I haven't personally used them but have seen some great looking custom builds. https://tex.com.tw/collections/keyboard
60.
▲
by
InitialBP
4y ago
I'm not sure about all languages but this actually caught me by surprise. When you do a 'mv' command (tested on macos) it does not retain file permissions by default. You actually need to pass a special flag in order to do so
More ›