Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Xk
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
Xk
16y ago
> At first I decided to hack RSA algorithm, I did too much investigation on SSL protocol, tried to find an algorithm for factoring integer, analyzed existing algorithms, for now I was not able to do so, at least not yet, but I know it's
62.
▲
by
Xk
16y ago
All you've done now is shipped off the responsibility to the API. The API is not bug free, I guarantee you. There will still be XSS vulnerabilities, but they'll just live in the API now. Imagine you decide to fix buffer overflows by switchi
63.
▲
by
Xk
16y ago
> especially code hosting sites, should be a bit more concerned. Not really. There are many examples of sites which should be more concerned. Anything with your credit card information, say. > Using a WAF and white listing parameter
64.
▲
by
Xk
16y ago
> Actually, the fix isn't to stop making mistakes. I know that. I wrote "The fix is also very simple: "Check the bounds of your arrays before you use them"" in order to demonstrate that saying "Sanitize your input" is equally wrong.
65.
▲
by
Xk
16y ago
Those two pieces of advice really are like telling programmers "just don't make mistakes". Giving that advise is really, really easy. Every competent web developer knows that. The hard part is actually implementing it. For example, lots of
66.
▲
by
Xk
16y ago
You won't get any better with that. Even if MD5 was a true source of randomness, the problem is still that you've only got 32 bits, so you'd expect a collision after 2^16 with a random function. Besides, xoring the other bits does nothing t
67.
▲
by
Xk
16y ago
Okay, sure, but that's trivial. You've just created a bijection from Z[62^5] to Z[62^5]. I could just use "X+1 mod 62^5" and get the same effect, minus some fake attempt at security.
68.
▲
by
Xk
16y ago
This scares me. > I could run it out to md5 and trim the first n chars but that’s not going to be very unique. What? MD5 going to be orders of magnitude better than what he's given. > Storing a truncated checksum in a unique field m
69.
▲
by
Xk
16y ago
You don't need the "in general". If there is a proven theorem that something is impossible, either the theorem is wrong or it's impossible. > the halting problem is solved routinely by people in software engineering research groups I'm
70.
▲
by
Xk
16y ago
Okay, yes. By 'hash', I meant generic, general purpose hashing function. MD5. SHA-1. SHA-2. SHA-3 (any of the finalists). Anything that is fast enough that you would use it to compute a cryptographically secure checksum of a large block of
71.
▲
by
Xk
16y ago
I agree you that this article has nothing to do with salting, and I don't know why the grandparent comment was even made, but there are a few points I would like to make about what you've said. > when really there is absolutely nothing
72.
▲
by
Xk
16y ago
Not only that, but if you were to write this in (say) Java, which uses a linear congruential random number generator, doing it this way would probably be even faster due to the higher quality random numbers. The least significant bits on a
73.
▲
by
Xk
16y ago
Upvoted because that's a valid point, but I did consider it before just doing that. I knew the developers of the site were looking here. I knew there was nothing critical running on this site. They were asking for feedback. Given that, it i
74.
▲
by
Xk
16y ago
Usernames aren't sanitized yet. (As is visible with the '<asdf' in the 'foobar' link above.) EG: http://profile.io/xss2
75.
▲
by
Xk
16y ago
Yeah, that's me -- I can't change my name, but if I could I would. I didn't realize there was the developer list and thought I would have an isolated test page.
76.
▲
by
Xk
16y ago
Escape < and > (and everything else), and check the site for XSS. I don't mean to be rude, and I realize you two coded this up in a really short amount of time -- but before this site goes live it would be best to have it secure. De
77.
▲
by
Xk
16y ago
Whoever it was that fixed the XSS (necro?), I'm impressed how fast that was. But please don't rely on just escaping < and >. You have to worry about double-quotes too, I can end a string and add a "onload" or "onfocus" attribute if
78.
▲
by
Xk
16y ago
That's all very nice, but it seems to do more with the fact that each person gets his/her own subdomain. And given that I found three xss's in about five minutes [edit: and then like ten more in the next five seconds, after realizing any in
79.
▲
by
Xk
16y ago
C macros are not Turing complete, they're a pushdown automaton. C++ templates are. Check out this IOCCC entry which does simulate a Turing machine, but only by having another script repeatedly run it. Edit: Yes, I meant to copy the link, se
80.
▲
by
Xk
16y ago
The OP took the title of the page. <title>IPad’s Rivals Can’t Beat It on Price - NYTimes.com</title> Edit: The original comment said something like, and I don't have the exact quote, "The OP changed the title and introduced
81.
▲
by
Xk
16y ago
And short of "fill in the bubble", any written exam also provides an advantage to the students you like the best.
82.
▲
by
Xk
16y ago
Or you can write a simple OCR program that can send HTTP requests.
83.
▲
by
Xk
16y ago
Since you say it would "just as useful to me", then I would assume that means it doesn't have to do with the actual person who submitted it (and correlate to age, or something) because you couldn't do that (easily) without a name attached.
84.
▲
by
Xk
16y ago
On a similar note, would the project still work if we reported it to you anonymously? I trust that you won't do anything bad with what I up-voted, but others might care more about what they've saved, and maybe letting them give it to you an
85.
▲
by
Xk
16y ago
> industry's leading tech publications I hope you're joking. Sometimes, sure, they're good. But that article is ... I'll hold my tongue. They're making it out to be some amazing feat. While I don't want to take away from the authors who
86.
▲
by
Xk
16y ago
Don't use a blacklist to filter out XSS attacks. Here's a valid title: "></title></head><body onclick="a" ondblclick="a" onload="alert(1)" onmousedown="a" onmousemove="_onmousemove_" onmouseout="a" onmouseover="asdf"
87.
▲
by
Xk
16y ago
That would be Toccata and Fugue in D Minor.
88.
▲
by
Xk
16y ago
Assuming OS as in operating systems, here's UC Berkeley's CS162: http://webcast.berkeley.edu/course_details_new.php?seriesid=...
89.
▲
by
Xk
16y ago
Reminds me of http://xkcd.com/628/
90.
▲
by
Xk
16y ago
Save some characters: filter even [1..4] I've found most of the time when you're trying to get incredibly short expressions that aren't obfuscated, haskell wins.
More ›