Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Sjoerd
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
Sjoerd
1y ago
What is the attack scenario here? Where are the security boundaries? How does the attacker gets their repository with a symlink in it to the victim? Is Helm typically run as a privileged user? How would this work? And why doesn't the v
2.
▲
by
Sjoerd
1y ago
To compensate for the US emissions of CO2 equivalent, you would need to create in the order of 4 cubic kilometers of charcoal every year. You could cover the whole of California with a layer of 1 centimeter (about half an inch) of charcoal
3.
▲
by
Sjoerd
1y ago
Do you have a link to that Yahoo publication? Or any more information on it?
4.
▲
by
Sjoerd
2y ago
I came to the same conclusion. Many string comparison implementations don't actually compare one character at a time. In one case strcmp seemed to compare eight characters at a time, so you would need to guess eight characters correctl
5.
▲
by
Sjoerd
2y ago
This differs for different template engines. In Angular, for example, the template is parsed into a DOM tree, and then template variables are placed in the correct place. This makes injection really hard. In the above example, it would be i
6.
▲
by
Sjoerd
3y ago
When doing symmetric encryption you usually need a nonce or IV, which is also sent to the other party along with the ciphertext and authentication tag. Why does the API for libsodium allow you to specify your own nonce and keeps it separate
7.
▲
by
Sjoerd
5y ago
They aren't guessable, except for ULIDs generated by the same process in the same millisecond. To keep chronological order even within the same timestamp, ULIDs within generated within the same millsecond become incremental. This can b
8.
▲
by
Sjoerd
7y ago
I agree that landscaping choices could be more environmentally friendly. However, planting trees in yards will have a limited impact; if 1.2 trillion trees cancel a decade of CO2 emissions, half a billion trees will cancel about 36 hours of
9.
▲
by
Sjoerd
8y ago
Such a thing is typically called a deterministic password manager. One problem with it is that you can't change the algorithm. If you want to change your PBKDF2 from 1000 to 5000 iterations, then you can't login anymore on any of
10.
▲
by
Sjoerd
8y ago
You seem to seed the SecureRandom object with the current time. I think this reduces security and it would be better to omit the seed and let SecureRandom seed itself. It also looks like you do normal String equals to compare secrets, which
11.
▲
by
Sjoerd
9y ago
Token binding provides something like that. With token binding you have a private/public key pair for each site that supports it. An identifier is created from the public key and signed with the private key, to prove your identity. ht
12.
▲
by
Sjoerd
10y ago
It is currently unclear whether violating the terms of service is a crime: https://www.eff.org/deeplinks/2017/02/violating-terms-use-is...
13.
▲
The password guessing bug in Tenex
(sjoerdlangkemper.nl)
2 points
by
Sjoerd
10y ago
|
0 comments