Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Jwarder
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
Jwarder
5y ago
Mozilla has identified issues with CAs that are part of eIDAS. The severity of these issues can be debated, but the nice part of Mozilla's root program is that these are publicly debated. For example, the community identified repeated
32.
▲
by
Jwarder
5y ago
I think it is a legitimate concern in both directions. Who should users trust more: Mozilla or their local government? Some countries have tried to use local PKI to spy on citizens. Mozilla has taken steps in the past to prevent abuse.
33.
▲
by
Jwarder
5y ago
I see two issues at play. Not all European CAs meet browsers' root programs requirements. Forcing everyone to accept those certs weakens all root programs (Mozilla's, Microsoft's, etc). There is also the concern that special
34.
▲
by
Jwarder
5y ago
my understanding is that it is super common, but not very concentrated in the earth. As a result it makes mining more difficult. You don't just find a ore vein in a cave, you have to dig up and process tons of stone in a wider area.
35.
▲
by
Jwarder
5y ago
Looks like someone setup a network where each hop deeper into the network has a name setup to display a line of ascii art.
36.
▲
by
Jwarder
5y ago
I wonder how much trouble with notetaking stems from people trying a one size fits all method. Personally, I have three tiers of notes. A physical notepad for meetings, random ideas, test results, that sort of thing. My goal is to write d
37.
▲
by
Jwarder
5y ago
I like seeing little notes from prior readers. References to other works, question marks, and angry exclamation points are all fun to see. Underlining or highlighting can be interesting to see what the other reader thought was important.
38.
▲
by
Jwarder
5y ago
Facebook reported that they logged passwords in plaintext by accident a couple of years ago. https://about.fb.com/news/2019/03/keeping-passwords-secure/
39.
▲
by
Jwarder
5y ago
How paranoid should I be of a browser plug-in that promises to track every interaction I make and provide that data for advertiser targeting?
40.
▲
by
Jwarder
6y ago
The flip side to that idea is that consumers choose to buy this limited lifespan furniture. IKEA isn't tricking people in an effort to grow forever; they are just producing what people want.
41.
▲
by
Jwarder
6y ago
What's wrong with it? I don't specialize in security, but I've seen peppers/global-salts in most of the "serious" password storage schemes I've seen. Looks like an easy layer of protection to limit brute
42.
▲
by
Jwarder
6y ago
Looks like you need to grab the build artifacts from their CI/CD system. https://ci.appveyor.com/project/ellson/graphviz-pl238/builds... Not something I would trust out of the blue, but that's the b
43.
▲
by
Jwarder
7y ago
If given the choice between modern disease control and a wall I would choose modern disease control. Your example of the flu is interesting. If humanity had modern resources to fight the ur-flu would it be worth the effort? How many lives
44.
▲
by
Jwarder
7y ago
> SARS, MERS and so on, which ultimately turned out to be nothingburgers As a reminder, SARS and MERS were contained thanks to massive international effort to identify the spreaders, quarantines (including whole hospitals), and restricti
45.
▲
by
Jwarder
7y ago
I read an article (>10 years ago so sadly I don't recall the title) about how computer science people see data differently from law people. Computers know nothing about the intent of data, it is only bits. The law (nominally) tri
46.
▲
by
Jwarder
7y ago
The word indirectly in "who can be identified, directly or indirectly" seems like it opens everything up. A session ID isn't directly PII, but it can be linked a user account and from there someone's name, address, etc.
47.
▲
by
Jwarder
7y ago
I found that I have changed my ideas on "enjoyment" per-activity, but not overall. For example: I've developed the habit of watching a movie while exercising in the evenings and listening to discussions on YouTube while gami
48.
▲
by
Jwarder
7y ago
I read the "only one correct way" to be a per-tool guideline. When looking a tool to do a specific task then (ideally) the tool should just process input with minimal futzing with configuration options. If you need to do somethi
49.
▲
by
Jwarder
7y ago
Not the parent poster, but prior objections I've seen are that people don't do a good job at picking random words and four words is too few.
50.
▲
by
Jwarder
7y ago
> This means that for strong performers going alone is better, and for weak performers going to a company is better. I'm not sure about this. Performance and value depend on the environment. Some organizations can provide the infr
51.
▲
by
Jwarder
7y ago
I can see why you would say that, but isn't classical engineering a counter example? Professional engineers have a culture of accountability and responsibility. No system is perfect, but (to my eyes at least) classical engineering wo
52.
▲
by
Jwarder
7y ago
Ha. I've been thinking about these sorts of problems and I'm leaning towards the idea that while governments are legitimate (groups of people pooling resources to achieve communal goals with some degree of compromise) most citize
53.
▲
by
Jwarder
7y ago
Are you sure your Pixel is vulnerable? Looks like the patch for Pixel 1 & 2 was released October 7th. https://source.android.com/security/bulletin/pixel/2019-10-0...
54.
▲
by
Jwarder
7y ago
The jobs numbers suggests where the trend is going. The github and article counts seem more useful to indicate the current state. When looking at those numbers I'd rather pick the more conservative number.
55.
▲
by
Jwarder
7y ago
Looks like 3:1 ish. https://thegradient.pub/state-of-ml-frameworks-2019-pytorch-...
56.
▲
by
Jwarder
7y ago
I don't see the article's idea of ownership as universal control, but more focused on being able to use whatever instance of the data you have without needing to rely on a third party. For example, if I own a book then I can read
57.
▲
by
Jwarder
7y ago
My reading of the issue is that Sendy's webform allows the external requester to bypass the server-side captcha logic by changing a client-side "hidden" input. If you want to be protected then you have to customize the form.
58.
▲
by
Jwarder
7y ago
Mozilla and Microsoft publish their lists. Chrome uses the OS's root store. I've seen other open source software use Mozilla's list, but I've never seen a list of what software does that. https://wiki.mozill
59.
▲
by
Jwarder
7y ago
The attacker needs to generate a new cert that the client trusts. This is easy on a corporate network where you can force users to trust a private CA. Unlikely to happen with a US ISP, but possible if someone hacks the CA (eg DigiNotar) o
60.
▲
by
Jwarder
7y ago
I kinda recall there being some options in old browsers (>10 years ago) where websites could send their privacy policy as a blob in the http header and the browser would enable/disable content based on pre-defined user options. How
More ›