Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
SahAssar
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
241.
▲
by
SahAssar
1y ago
Me too. https://web.archive.org/web/20250914073627/https://www4.cour... works
242.
▲
by
SahAssar
1y ago
Isn't it the hinge, the folding oled screen and general durability of moving parts that are the hard parts of a foldable? This has none of those.
243.
▲
by
SahAssar
1y ago
> But never ever anyone was rooted because of malware that was snuck into an official .deb package. We got pretty close with the whole XZ thing. And people generated predictable keys due to a flaw in a debian patch to openssl. This stuff
244.
▲
by
SahAssar
1y ago
And who would control that whitelist? How would it be any different than the domain system or PKI CA system we have now? Do you think there would be the time to properly review applications to get on the whitelist?
245.
▲
by
SahAssar
1y ago
Heartbleed? Solarwinds? Spectre/Meltdown? Stuxnet? Eternal Blue? CVE-2008-0166 (debian predictable private keys)?
246.
▲
by
SahAssar
1y ago
It's not, and a third of them are tagged as unstable. JSR also still seems to not encourage proper versioning.
247.
▲
by
SahAssar
1y ago
Well, that would also require all the services to support webauthn/FIDO, which a lot of them don't. Some who do support it only allow one key or trivial bypass via "security questions".
248.
▲
by
SahAssar
1y ago
I'm going to guess estonia which has had this since mid 2000's IIRC.
249.
▲
by
SahAssar
1y ago
I've never had a M.2 SSD not work with a proper device, but I guess that might vary.
250.
▲
by
SahAssar
1y ago
But wouldn't a subtype like `mytype` in my example (`application/mytype+json`) still be be a valid mime-type and still avoid your concerns? I've used these before.
251.
▲
by
SahAssar
1y ago
CSP blocks execution/inclusion, but since json does not execute and any json mimetype will not do execution there is no problem. Any CSP-allowed other script can read that application/json script tag and decode it, but it is no di
252.
▲
by
SahAssar
1y ago
Why not use a somewhat proper mime type like `<script type="application/mytype+json">` or similar? Seems like your suggestion is not what the spec recommends: https://html.spec.whatwg.org/multipage/
253.
▲
by
SahAssar
1y ago
MV2 is not deprecated on firefox, does the bypass work there too? I'd probably send gorhill a message with the info and then it can either be published to the readme or the extension unarchived and hotfixed or at least published somewh
254.
▲
by
SahAssar
1y ago
The TLS guarantees are to the edge of the infra of the vendor. If that vendor has decided to use infra providers that issue certs for them without their knowledge and they have not implemented CAA then the blame is not on TLS, it is on the
255.
▲
by
SahAssar
1y ago
The cert you mention is this one, right? https://crt.sh/?id=18844641499 Seems like they use cloudflare as their DNS provider, which uses Google as their cert provider and this has happened before with them. See for example
256.
▲
by
SahAssar
1y ago
> I've found a way in which uMatrix can be bypassed if a website were to specifically target it Please do tell.
257.
▲
by
SahAssar
1y ago
Could I ask for a source on that and how common it is? Seems like it was used way back in the cold war (and even then not blocked/jammed) and I'd guess that current authoritarian regimes would perhaps not bother considering how fe
258.
▲
by
SahAssar
1y ago
How would that be different for trains? Trains would have similar numbers or more devices, moving at a similar speed (for high speed trains compared to planes at take-off/landing).
259.
▲
by
SahAssar
1y ago
(Posting while the title is "Fuse is 95% cheaper and 10x faster than NFS", I'm guessing that will get changed based on the HN rules) This is not at all about NFS vs FUSE, this is about specific NFS providers vs specific FUSE
260.
▲
by
SahAssar
1y ago
You'd have the feature, but you also need to supply the model. The feature seems to just be that ffmpeg has the ability to run the model, it does not include the model.
261.
▲
by
SahAssar
1y ago
Why would that one specifically find buyers? Do people commonly use vecs as a short for vectors or am I missing something?
262.
▲
by
SahAssar
1y ago
I have a few, only bought on open market. There are still quite a few XX.XX left, but mostly just under obscure cTLDs (unless you are willing to consider IDN/Unicode domains under .ws or similar)
263.
▲
by
SahAssar
1y ago
I don't understand what MCP gives that a REST API with a OpenAPI definition would not give?
264.
▲
by
SahAssar
1y ago
Quite a few of these seem to be not really about YAML but rather about k8s and helm.
265.
▲
by
SahAssar
1y ago
No love for njs, the engine for running javascript inside of the nginx web server?
266.
▲
by
SahAssar
1y ago
The DigiID app could interact with websites, that's how it works for many other digital IDs in europe. For example with bankID (sweden, and I think the norway version does the same) when you need to authenticate you either scan a QR co
267.
▲
by
SahAssar
1y ago
> You could certainly do a reverse proxy and use HTTP instead of FastCGI as the protocol between the client facing httpd and the application server That's what I meant. Things like X-Sendfile (or X-Accel-Redirect in nginx) works wit
268.
▲
by
SahAssar
1y ago
> Considering that it the db isn't public and the disclosures are listed at the bottom, before the publication, this is mostly white hat and helps the company they target The never disclosed to the target company (not that I think t
269.
▲
by
SahAssar
1y ago
> FastCGI or some other method to avoid forking for each request is valuable regardless of runtime. If you have a runtime with high startup costs, even more so. What's the point of using FastCGI compared to a plain http server then?
270.
▲
by
SahAssar
1y ago
> it'd be good to callout OpenIDC as a predecessor to SAML SAML is older than OpenID Connect by ~13 years.
More ›