Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
STRML
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
32 ms
·
361.
▲
by
STRML
12y ago
I love this! We use LDAP in exactly this fashion so this looks like it may be more-or-less a drop-in addition to how we work. Thanks for such a cool project!
362.
▲
by
STRML
12y ago
That's pretty much how it happens, in my experience. Contributing to OSS projects generally happens when you need it, and often stops when you don't / it isn't your job anymore. My most significant contributions to proje
363.
▲
by
STRML
12y ago
I think you're misunderstanding how you bypass the reprompt. LastPass has two separate features - auto-logoff and reprompt, and you can tick a bunch of boxes to decide which features you want reprompt for. I usually tick most of them.
364.
▲
by
STRML
12y ago
I like the reprompt feature as they have it - you can stay logged in, you can be prompted to autofill on websites, and you can use the password generator, but in order to open or save a site or note you are reprompted after a timer (x minut
365.
▲
by
STRML
12y ago
Okay, this is a crappy metaphor, but imagine they had a feature where you could put the car in standby while you went out for a quick errand, and just press a button to start the car up again without inserting the key, but the key has to be
366.
▲
by
STRML
12y ago
I believe this is the same issue that 1Password had in the past, and a lot of users complained about exposed urls/titles in their storage format. I believe they now decrypt the urls & titles on startup in their plugins and keep the
367.
▲
by
STRML
12y ago
I use Yubikey 2FA. That still doesn't fix the problem that all of your data is accessible while logged in, and that the usability goes to hell if you don't stay logged in.
368.
▲
by
STRML
12y ago
I'd definitely settle for an option where autofill is requested by the extension, but communicated via a bridge to a native application which can safely handle reprompts and cut off communication after a timeout.
369.
▲
Ask HN: I'm having doubts about LastPass security, what should I switch to?
48 points
by
STRML
12y ago
|
64 comments
370.
▲
by
STRML
12y ago
While that's true, a lot of the frustration with HTML/CSS/JS melts away when you have only a single target environment and don't have to worry about browser compatibility. Targeting a modern environment like Gecko would
371.
▲
by
STRML
12y ago
You're right - but the real win here is that hundred of thousands of developers already know HTML + CSS, and very few developers know XUL or even any native UI API. Given that these native APIs change with the platform, many developers
372.
▲
by
STRML
12y ago
I like keys with passphrases, although their security is somewhat questionable as you say. At least it prevents the scenario where the key is accidentally exposes somewhere via a lost storage device / bad scp command / whatever. A
373.
▲
by
STRML
12y ago
You can use SSH AuthenticationMethods to require a password as well, for 2FA in a sense - something you have (SSH key), something you know (password). You could even get more complex and pair with FreeIPA/PrivacyIDEA for 3(?)FA with Go
374.
▲
by
STRML
12y ago
This is a great perl script that makes for an easy AuthorizedKeysCommand [1]. SSH with LDAP is definitely an easier way to distribute keys and manage permissions than logging into each box. It's also a single point of failure in a way,
375.
▲
by
STRML
12y ago
Yes, I am still waiting for something prettier than software VPN or OpenS/WAN. Their docs show 5 ways to connect VPCs, all of them complex, all of them with significant downsides. One would think this sort of thing would be easier.
376.
▲
by
STRML
12y ago
I tried getting a Vagrant environment up but I'm not convinced it's worth it. There is at least one repo with what looks like a working config [1]. I was far enough along in development by the time I started messing with Vagrant t
377.
▲
by
STRML
12y ago
From my understanding, after talking to them at Web Summit, something like this is in the works. And they're aware of how incredibly complicated the AWS console is becoming. I don't know how or when they plan to address it, howeve
378.
▲
by
STRML
12y ago
While this looks nice, part of me can't help but be annoyed by yet another deployment option on AWS. We now have CloudFormation, Elastic Beanstalk (which can take many forms, including Docker), CodeDeploy, and Opsworks. I can imagine
379.
▲
by
STRML
12y ago
The bit about the semicolon separator was new to me. Are there many web services using the semicolon to send parameters? In any case, it seems that the real bug is that browsers don't properly recognize `;` as a separator and can deriv
380.
▲
by
STRML
12y ago
This is probably the most insane way I've ever seen a 3d environment created (look at the DOM), but it really is incredibly well done. The performance is of course not nearly as good as WebGL, but it is a great proof of concept and cou
381.
▲
by
STRML
12y ago
I've actually heard very bad things. They are a reseller and don't seem to stand behind their products. Here is one example: http://yashchandra.com/2014/05/06/do-not-buy-system76-develo...
382.
▲
by
STRML
12y ago
I do the same with control/fn as well. Karabiner is fantastic.
383.
▲
by
STRML
12y ago
That said, it is mostly good enough. I've used it for a few SASS projects in combination with Bourbon and it works great. IMO the huge compilation speedup (I saw reductions from 5-6s to about 200ms) was worth the slight move backwards
384.
▲
by
STRML
12y ago
Excellent! Thank you for putting forth the extra effort and thinking this through. Many comparable online solutions in the Bitcoin space do not offer similar offline tools, making them a non-starter for business use.
385.
▲
by
STRML
12y ago
Is there a way to sign a transaction offline but still run it through Coinbase? When it comes to decrypting private keys in the browser, unless the user inspects the javascript each and every time they use the site, there is no guarantee th
386.
▲
by
STRML
12y ago
Misleading title, they corrected the article (it's 1900MB/s, not 19000) but neglected to change the title. Surprisingly bad reporting. This is fast and definitely an improvement over the state of the art - at least for consumer pr
387.
▲
by
STRML
12y ago
We do something similar on BitMEX with SockJS. As long as you're not using AWS's ELB, load-balancing websockets is as easy as anything else. We use HAProxy to proxy the websocket connections as TCP, and round-robin the connections
388.
▲
by
STRML
12y ago
I agree 100%. It's far less usable than it was. The removal of text is yet another one of those silly design trends I'm sure we'll look back at with disdain in the near future.
389.
▲
by
STRML
12y ago
I don't understand how one could not know what percentage of the company that is. It seems wholly irresponsible not to; both from the perspective of the potential employee (who may get too little) and from the perspective of the empl
390.
▲
by
STRML
12y ago
I've had this happen to me, and quitting was one of the best decisions I ever made. If you can't be upfront about equity, it's a symptom of a much larger problem.
More ›