Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Xk
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
91.
▲
by
Xk
16y ago
Would you tell me how to enter my moves so that I can play it? I've been trying to figure out the correct format but can't seem to get it.
92.
▲
by
Xk
16y ago
Alright. I had checked ten minutes later and it was ~30, and I wasn't sure if anyone else had taken a count right after the change was made.
93.
▲
by
Xk
16y ago
Message to the future: there were ~30 people who had voted 11-20 by the time the switch was made to break it up into two sections. To figure out the actual distribution of people, you'll have to subtract 30 from the 16-20 range and then com
94.
▲
by
Xk
16y ago
There's no Lisp/Scheme option. This wasn't my first, but I know many who learned Scheme from SCIP as their first language.
95.
▲
by
Xk
16y ago
I find irony in the fact that if the populous were better educated, the state would get less money. While not strictly true (a better educated populous would probably earn more, and give more taxes to the state, among other reasons), I find
96.
▲
by
Xk
16y ago
In some states, the lottery accounts for more than 5 percent of education funding. Am I the only one who finds this ironic? Edit: Except, of course, for those who learn to predict 19 of 20 tickets correctly.
97.
▲
by
Xk
16y ago
As several others asked last time, have you considered posting under a name other than "g0atbutt" for a more professional look?
98.
▲
by
Xk
16y ago
XSS prevention cheat sheet: 1) Never send untrusted data to the client. How you do that isn't terribly important. It just matters that you do. Which is what that page is talking about: what you can do in order to never send untrusted data t
99.
▲
by
Xk
16y ago
I don't know of any attack. However, my point is just that HMAC means using hashing for a message authentication code. Encrypting hashes makes more sense as to what's going on.
100.
▲
by
Xk
16y ago
From that link: HMAC(K,m) = H((K ⊕ opad) ∥ H((K ⊕ ipad) ∥ m)).
101.
▲
by
Xk
16y ago
There is a difference between a HMAC and encrypting a hash, or a HMAC and a salted a hash. HMAC means Hash based Message Authentication Code. http://en.wikipedia.org/wiki/HMAC
102.
▲
by
Xk
16y ago
Hashing doesn't have much of a use when there are only 10k possible inputs. Even using bcrypt set to take 1 second to verify a hash wouldn't be great -- it'd take about two hours and 45 minutes to break a PIN. And yes, while this is signifi
103.
▲
by
Xk
16y ago
HMAC's verify the integrity of a message; they don't have any use in this setting.
104.
▲
by
Xk
16y ago
Sanitize both input and output. Make sure everything outputted is encoded. < to > > to <, " to "e;, etc. As long as all they can write is normal characters then you're safe [1]. [1] Or rather, safer. There are
105.
▲
by
Xk
16y ago
I would disagree. Go to google, search anything. Notice that clicking a link is what sets safe search. It's a GET request. It's not all that unusual.
106.
▲
by
Xk
16y ago
There's no reason to bookmark the "Delete this email" link (a la SquirrelMail, RoundCube). Sometimes links make sense to use, and it's possible to safely make GET requests change state when you need to. Edit: Now that I think about it, why
107.
▲
by
Xk
16y ago
The example there is one of a cross-site request forgery (CSRF or XSRF). They pose a solution for POST requests, namely, the "Anti-Forgery Token". This is the right way to stop CSRF on post forms. However, this is a defense which works just
108.
▲
by
Xk
16y ago
So let me say first that Java was my first language, and I don't believe I've been corrupted in any nasty ways. I was 10 when I learned Java, and it always threw me off having to copy those first two magic lines which I never understood. Wh
109.
▲
by
Xk
16y ago
Or give an option. Only integers / Only rationals (with denominator something reasonable) / Only reals / Only Gaussian integers / Only Gaussian rationals / All complex numbers.
110.
▲
by
Xk
16y ago
Java is strongly typed. As a counterexample, here's some valid java: String str = ""+5;
111.
▲
by
Xk
16y ago
> Z: Oh yeah, totally. http://autho.me/start.html . BREAK IT MY BROTHER! I'll buy you a beer for each flaw you find. :-) http://news.ycombinator.com/item?id=2035617 I'm not yet of the legal drinking age, so I'll pass on the beer.
112.
▲
by
Xk
16y ago
First of all, let me say this is a significantly better question than many I've seen. However, It disturbs me when someone is interviewing me and they are looking for a particular answer and they consider everything else wrong. Even when I
113.
▲
by
Xk
16y ago
The key difference here is one between a message authentication code [1] and digital signature [2]. A digital signature uses public key cryptography: one person can generate and sign messages, everyone else can verify. A common one is the D
114.
▲
by
Xk
16y ago
You're really quite quick at fixing these things -- as I'm creating a demo page to email you, I'm noticing every time I refresh, one of the old attacks doesn't work any more.
115.
▲
by
Xk
16y ago
If you're considering developing this app further, you might want to take a look at the security of your app. A few minutes and I found quite a few XSS attacks on it. If you'd like, I can email you all of the attacks I've found so you can f
116.
▲
by
Xk
16y ago
Yeah, my "they" was really unclear. I'm sure that no developer in his or her right mind would ever call anything "invulnerable." That's just asking for it. I guess it makes sense that the media would call something like that invulnerable th
117.
▲
by
Xk
16y ago
newly created passwords remain invulnerable to a similar disclosure, as they employ SHA-512 with per-user salts to store hashes. I don't know how long it will take for people to figure this out. SHA-512 with a salt is not the right way
118.
▲
by
Xk
16y ago
Need I point out the irony of an authentication site containing an XSS attack? Login Name: " onfocus="alert(1)" foo=" Submit form. Get error. Click input box again. XSS. Now, if I was an attacker, I would create a form which does this by my
119.
▲
by
Xk
16y ago
It's not totally impractical. Paillier, for example, has nice applications in electronic voting (since you can sum votes without reading who those votes were for). http://en.wikipedia.org/wiki/Paillier_cryptosystem But yeah, anything more
120.
▲
by
Xk
16y ago
Ah, alright. Yeah, seven is just coincidental. But, it appears that you are correct in one respect: seven seems a bit high to me. I don't have the time to do the probability distributions out, if someone cares would they do the calculation
More ›