Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
InitialBP
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
91.
▲
by
InitialBP
5y ago
"Deleted from social media" is a pretty weak definition of "being cancelled". Regardless of whether you agree or not "cancelling" is more about large scale boycott of a person and the media or services associat
92.
▲
by
InitialBP
5y ago
Disclaimer: I know basically nothing about ML. I think the idea is that data needed to imitate a _specific person_ would require less data. Overall a model like that might have orders of magnitude more data in general and maybe a smaller am
93.
▲
by
InitialBP
5y ago
> In addition to the local population, many people travel to cities where sports matches, concerts, and other events (e.g., conventions, auto shows, etc.) are held in the stadiums. The article directly addressed this point by saying: Whi
94.
▲
by
InitialBP
5y ago
If you're referring to the Russia Ukraine conflict with note about sanctions I don't think we've seen indication that sanctions are an "effective means" of pushback considering the fact that the Russia continues to
95.
▲
by
InitialBP
5y ago
I can appreciate that solution. Admittedly I didn't know anything about the app since I don't have access to any device to view it.
96.
▲
by
InitialBP
5y ago
They don't mean literally nobody cares about the product, just that this conversation isn't necessarily related directly to the product but more about design in general. My original point is just that it's a design that locks
97.
▲
by
InitialBP
5y ago
It's not just an annoyance, it makes your site literally unusable on a mobile device. What if I urgently need to access some details of my account and don't have laptop access. If I check "load desktop site" then load th
98.
▲
by
InitialBP
5y ago
> I have autofill turned off because it can fill into nefarious forms if you're not careful. One nice feature that 1pass has is that it will warn you when you attempt to autofill credentials for a url or mobile application that isn&
99.
▲
by
InitialBP
5y ago
To be fair I'm not familiar with the dropbox+1pass combo solution you're referring to, but I imagine that the people using that solution are in the minority and that by focusing on one unified solution and not spending time suppor
100.
▲
by
InitialBP
5y ago
Your argument against escaping is the same one against input sanitization. Literally you cannot know where all your data will go when storing it so how do you even begin to sanitize that data? No special characters? Alphanumerics only? You&
101.
▲
by
InitialBP
5y ago
Agree and Disagree. Sanitization has it's place, but from a user perspective it's better to just outright reject (through validation) inputs that aren't valid. There are often unexpected ways that data gets into the system (I
102.
▲
by
InitialBP
5y ago
Alternatively... validate (client side) => insert using sql parameterization (escaping) => escape per context when outputting Sanitizing is the idea that you are cleaning dangerous things from the original input (different than valida
103.
▲
by
InitialBP
5y ago
Insert using SQL parameters is "escaping". The parameterization ensures that the data being passed gets interpreted by the DB as the expected data type by ensuring special characters aren't interpreted as "special"
104.
▲
by
InitialBP
5y ago
While I generally agree that solar winds was lacking a lot on their internal DnR team (iv cut investments in cybersecurity) a lot of the identified issues are things that are seen in businesses EVERYWHERE. Until recently I was a pen tester
105.
▲
by
InitialBP
5y ago
When you say "Audit" do you mean in terms of security? I was a penetration tester for a while and it was quite common for my clients to have customers who requested a security audit of their product. We would conduct the assessmen
106.
▲
by
InitialBP
5y ago
The YubiKey's that support NFC are all significantly larger. The Nano does not currently support NFC. Size is a challenge with NFC specifically as I believe larger NFC chips lead to larger area of allowable communication.
107.
▲
by
InitialBP
5y ago
Penetration tester here. While my company was concerned about business at the beginning of the pandemic, we quickly saw a large uptick in business from corporate customers who were integrating remote employees into their new norm.
108.
▲
by
InitialBP
5y ago
These have been implemented in a lot of places extensively, such as Germany. There are also some implementations in the US. One such that I drove on often is when I-70 eastbound runs into the beltway at Baltimore, MD. The only problem with
109.
▲
by
InitialBP
5y ago
Regardless of whether PHP solved this particular problem, it also caused a lot of its own due to numerous security issues and documentation that encouraged unsafe use of libraries, until recently.
110.
▲
by
InitialBP
5y ago
These aareas of West Virginia and Virginia are exceptionally beautiful and serene places to visit, if you ever get a chance to drive by the Green Bank telescope it is Massive! In fact the dish of the telescope has a diameter of around 300 f
111.
▲
by
InitialBP
5y ago
On top of just "compliance" or "customers demand it", these types of penetration tests can and do expose real, serious vulnerabilities in software. Furthermore, I wouldn't underestimate the positive press that havin
112.
▲
by
InitialBP
5y ago
Penetration tester here - My anecdotal experience: I've worked on a number of projects where bill rate is something like $250-$400/hr per engineer depending on complexity, access to source code, size of the project, etc. Usually e
113.
▲
by
InitialBP
5y ago
In order to rollout a whole new ID system you'd need so way to validate the identity of the recipient before you gave them a new one. Presumably the easiest way would be just to turn in your old ID card, which many people don't ha
114.
▲
by
InitialBP
5y ago
I think in general you'll just see a lot of those restaurants and businesses that provide services to office employees move to where they can provide services to remote employees. Service industry businesses generally follow people and
115.
▲
GoKart
(praetorian.com)
1 points
by
InitialBP
5y ago
|
0 comments
116.
▲
by
InitialBP
5y ago
Just a thought on point number 2. I fully agree with you that a good "product" and design is a reason for people to pick one content provider over another. It's almost exclusively about what content a provider has access to.
117.
▲
by
InitialBP
5y ago
to be fair "Free and open" is different than "Free and Open Source". Open source has a much stronger connotation than open and I could certainly see calling it open if the source is available for the core of the product.
118.
▲
by
InitialBP
5y ago
I don't think correcthorsebatterystaple is easier to crack than the Troubador variation. Hash cracking often includes the use of a wordlist and a ruleset which builds variations on the words from a wordlist. Some common ones I use for
119.
▲
by
InitialBP
5y ago
What kind of situation occurs where you can't input special characters in a password field? I think in general the advice is that there should not be any limitations on special characters anywhere in the tech stack at all. (Including a
120.
▲
by
InitialBP
5y ago
Slack authentication works like many other web applications and once you've successfully authenticated you get a cookie which can be used to read/send messages on your behalf. If someone managed to get some malware running on a ma
More ›