Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
arde
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
91.
▲
by
arde
12y ago
Regarding item 4, a VPN solution is considerably more complex and error prone than port knocking plus SSH. What do you do if/when your VPN service fails? I think you would usually have a VPN service AND a port knocked SSH backdoor.
92.
▲
by
arde
12y ago
That is equivalent to limiting SPA to a 16-bit password.
93.
▲
by
arde
12y ago
This. Obscurity has too much bad press. It's not to be depended on, but it can be a useful addition sometimes.
94.
▲
by
arde
12y ago
Yes, an AES-CTR transformation would be more secure than any port knocking variety such as SPA, at the cost of being more complicated. But the point in port knocking is not its intrinsic security, which is not worth to talk about: its point
95.
▲
by
arde
12y ago
Well, that's exactly what I meant with my edit: carry it yourself so "they" don't get their hands on it. Sorry I didn't make it clear.
96.
▲
by
arde
12y ago
Hmm. How about having a firewall consisting of two distinct servers placed in series, one made in the US and the other made in China, both running some open-source OS. I know, the surface attack is still huge but at least you are not automa
97.
▲
by
arde
12y ago
Snark and sarcasm somewhat aside, it's not like they could tell the users about the remediation progress through their intranet, so they probably didn't have many options besides posting it on the Internet for all to see.
98.
▲
by
arde
13y ago
Yeah, and who cares about shared folder performance anyway?
99.
▲
by
arde
13y ago
What, no Erlang? Sheesh! Amazing work.
100.
▲
by
arde
13y ago
It depends on what you compare it to. I meant complex in the context of the use case I have in mind. It certainly IS much more complex (and powerful) than a simple GIF creator. But if you only need a one-way, low quality stream, RFB is over
101.
▲
by
arde
13y ago
For my use case I'm not worried about the client's security (in fact, he's the one I'm interested in protecting the server from). We probably are assuming very different tolerance thresholds on security. But even so, I don't think you can a
102.
▲
by
arde
13y ago
For this use case I don't trust implementations that I have source code for, due to their complexity. This is intended to share screens that lie behind a firewall. It wouldn't make sense to trust third-party code with closed source code and
103.
▲
by
arde
13y ago
This nicely solves a problem I've been asked about: how to share a screen securely (read-only). VNC protocol and implementations are too complex/sloppy so I don't trust them. An endless GIF, on the other hand...
104.
▲
by
arde
13y ago
Same here. Specifically, I'm not buying one until I can print circuit boards.
105.
▲
by
arde
13y ago
"We certainly have something to learn here about the best way to ensure dialog with clients about this kind of issue. [...] We [...] invite them to contact our commercial team (in french)." To ensure dialog, why not start by being able to c
106.
▲
by
arde
14y ago
This one wasn't one of the reasons I considered, but I find it interesting: Suppose you upgrade any old OEM Windows XP or later that's bound to the hardware that you bought it with. Once you upgrade, you are no longer bound by the old licen
107.
▲
by
arde
14y ago
More easily said than done, though.
108.
▲
by
arde
14y ago
Windows 8's UI is noticeably faster than its predecessors. And if you have a Windows 7-based tablet like I do, you'll appreciate the new touch UI because Windows 7's was not very good while Windows 8's is more reasonable. Also, Windows 8 do
109.
▲
by
arde
14y ago
New wave of "Beat the stock market" strategy books in 3, 2, 1...
110.
▲
by
arde
14y ago
Indeed. Furthermore a study has found that moth's memories are retained from one stage to the other ( http://news.nationalgeographic.com/news/2008/03/080305-moth-... ).
111.
▲
by
arde
14y ago
Sure, but those who inherit PHP systems may not belong to the PHP's target audience that I was referring to. Neither must all people who choose to use PHP necessarily idiots, because PHP does have some legitimate use cases. But all in all I
112.
▲
by
arde
14y ago
I don't think you got to the real problem here. Weak types are quite useful for some tasks, and of course they are nothing new. Languages that convert between integer and string types automatically are well suited for text processing in gen
113.
▲
by
arde
14y ago
Perhaps it was not like this when PHP was created, but it surely has been for a long while now: Idiots are now PHP's target audience be it by design or by its own faults. So if Rasmus Lerdorf still maintains PHP then he should not get angry
114.
▲
by
arde
14y ago
It's bad code alright. But I would argue that any code you write in a bad language turns into bad code, no matter how you do it. It might be good enough for your application, so that's fine. But it would be bad nonetheless. And PHP is not a
115.
▲
by
arde
14y ago
Pointing to the documentation does not work in this case. The documentation shows the user was not sticking to the function specs, yes, but neither does PHP most of the time. If PHP were a consistent (serious) language, I might see your poi
116.
▲
by
arde
14y ago
They probably only care about the presentation aspect of it, and not doing any calculations with uninitialized variables. The users are probably worried about showing NULLs instead of zeroes on empty fields.
117.
▲
by
arde
14y ago
Well, of course they must be addressing security changes! It's PHP, remember? ;)