Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
asjfkdlf
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
asjfkdlf
2y ago
It states that it doesn’t require major changes because it all happens under the SSH protocol. A new program is needed on the client to sign in and you can already run a custom program on the server to authorize the key.
2.
▲
by
asjfkdlf
2y ago
I bought these and they are great. They strike a balance of programmable, but have a kit. Relatively simple for a novice
3.
▲
by
asjfkdlf
2y ago
I am looking for a similar service that turns any document (PNG, PDf, DocX) into JSON (preserving the field relationships). I tried with ChatGPT, but hallucinations are common. Does anything exist?
4.
▲
by
asjfkdlf
2y ago
Aren’t they using a NoSQL store? They migrated from Casandra to Scylla DB
5.
▲
by
asjfkdlf
2y ago
The prize is very underwhelming. If they really want people to spend effort on it, they need to make the prize worth it.
6.
▲
by
asjfkdlf
2y ago
How does this compare to other GCM alternatives such as AES-SIV and AES GCM-SIV?
7.
▲
by
asjfkdlf
3y ago
To be a deterrent, it just needs to curb some percentage of behavior. Not stop it completely. Do you think people are murdering at the same rate as if there was no punishment? It could be, but I would bet the numbers would go up significant
8.
▲
by
asjfkdlf
4y ago
There are some really good findings about TikTok APK used in many apps. In addition I agree that better privacy laws that would affect all companies, even US ones, would be the ideal. The statement that this ban won't help is completel
9.
▲
Fidelity asks for login password via telephone keypad
3 points
by
asjfkdlf
4y ago
|
1 comments
10.
▲
by
asjfkdlf
4y ago
I envy your experiences. I personally have had the opposite experience. It’s important to remember that your personal experience may not be the same as others. As this movement is very popular in the general public, my guess is many others
11.
▲
by
asjfkdlf
4y ago
Don’t attribute to malice what can be equally be explained by stupidity
12.
▲
NY Sabotages Right to Repair Bill [video]
(youtube.com)
427 points
by
asjfkdlf
4y ago
|
331 comments
13.
▲
by
asjfkdlf
4y ago
This is a horrible abuse of the DMCA. HackerRank does not own the copyright to independent solutions.
14.
▲
by
asjfkdlf
5y ago
There is some useful information here, but saying docs are more secure than introspection makes no sense. The person can learn about your file upload endpoint through docs. Security through obscurity is not a reasonable security strategy.
15.
▲
by
asjfkdlf
5y ago
Had this exact thing happen in production when we turned off an audit DB replication slot. We got lucky and caught it before our entire app went down. It’s one of the many foot-guns we have found with Postgres.
16.
▲
by
asjfkdlf
7y ago
I have implemented something similar, but used 12 characters. 6 is way too few for a secure URL
17.
▲
by
asjfkdlf
7y ago
It looks like the code is running in iframes, so yes it would do hard navigation, but it would not change the domain the user sees.
18.
▲
by
asjfkdlf
8y ago
"There is no universal solution for the Year 2038 problem"
19.
▲
by
asjfkdlf
10y ago
No, that is not possible. Extensions in Chrome run in a different execution context than the website. The website's document.creatElement is different from the extension's. If the website could override extension functions, attack
20.
▲
by
asjfkdlf
10y ago
You can do it with google apps too, but it's a little more difficult. Login into an account and setup an alias. There is a limit to the number of aliases, but you can just create more accounts with aliases that forward to your email.
21.
▲
by
asjfkdlf
10y ago
I am not sure what you are getting at. Those don't occur on the web and are not an issue with desktop apps you install. If a desktop app wants to run a bash command, it can do it. It doesn't need to find a bash injection. There is
22.
▲
by
asjfkdlf
10y ago
That would be a good first step. It would have to be a subset of CSP. Don't allow inline scripts or eval.. Only on https is another step I see as very important.
23.
▲
by
asjfkdlf
10y ago
I am not sure I agree "browsers generally have a better permission model than desktop apps". Yes, browsers ask the user if they would like to allow, but do desktops apps have rampant XSS vulnerabilities? If you allow a site to use
24.
▲
Node February 2016 Security Summary
(nodejs.org)
1 points
by
asjfkdlf
11y ago
|
0 comments
25.
▲
by
asjfkdlf
11y ago
I strongly disagree. People don't appreciate unwanted email to their personal accounts. That is why we don't put our email places where bots, recruiters, etc can easily access it. You generally only want to give your email out to
26.
▲
by
asjfkdlf
11y ago
This isn't about contacting people or communicating the status of a Github project. Github issues are fine way to communicate. If the repo owner isn't responding to issues, I don't think sending email to someone's person
27.
▲
by
asjfkdlf
11y ago
Yes, it is a GIT feature/issue. Github does nothing to protect users (by default) from using their personal email in commits. It is definitely not well known though because almost everyone is using their private email address. Go to a
28.
▲
GitHub exposes everyone's email address in GIT commits
(taylorhakes.com)
4 points
by
asjfkdlf
11y ago
|
12 comments
29.
▲
by
asjfkdlf
11y ago
Where does it say anything about encryption?
30.
▲
New Relic Major Outage
(status.newrelic.com)
6 points
by
asjfkdlf
11y ago
|
0 comments
More ›