Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
asdfghjhgfderty
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
asdfghjhgfderty
4y ago
it's insane to expect the opposite: that traffic in my own network will need to keep reaching to a certificate authorities outside to validate packages from one host to another. if you don't understand why these 3 things are on to
2.
▲
by
asdfghjhgfderty
4y ago
they are simply constructing GET request headers "by hand " based on some xml file downloaded earlier an then sendind that list of GET via `nc`. the example is just over confusing and using file named as 1, 2 I voted up becaus
3.
▲
by
asdfghjhgfderty
4y ago
> In a theoretical future world where 99% of site operators have set this up for protection, and 99% of users are using approved browsers, how would one do something like [compete with apple or google] A: they won't. and that's
4.
▲
by
asdfghjhgfderty
4y ago
sadly, you are completely wrong. just look at captcha usage. yeah, very few follow the original recommendation of showing captcha for ips that already showed signs of being bots etc. but the vast majority shows captchas for absolutely anyth
5.
▲
by
asdfghjhgfderty
4y ago
nothing on the spec prevents arbitrary data on body of a GET. but clients and proxies are implemented by lazy people who make excuses they are preserving some legacy security feature or something and continue to ignore the spec.
6.
▲
by
asdfghjhgfderty
4y ago
didn't see much about security
7.
▲
by
asdfghjhgfderty
4y ago
nonsense. autoconf didn't have a core developer. But it had many distro package managers. there's nobody adding code/fixing bugs, but there are plenty people reading and looking at diffs before packaging it in distros. then t