Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bluetooth
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
by
bluetooth
13y ago
Although this might not be the right way to do it, I think the goal of the project is to exemplify bitcoin's "distributedness" and minimize the reliance on a single exchange (ie MtGox).
62.
▲
by
bluetooth
13y ago
If a customer was hacked, why reset everyone's password? Unless there is something Linode is not telling us, there is no reason they should be doing this. Think about it like this: what if Google reset everyone's passwords whenever a gmail
63.
▲
by
bluetooth
13y ago
What did I say wrong? I'm just stating my plans after hearing about another security blunder on Linode's part. Did what I say come off as sarcastic?
64.
▲
by
bluetooth
13y ago
But here, it's not a customer that was hacked. It was linode that was hacked, and used to access a specific customer's data.
65.
▲
by
bluetooth
13y ago
> It's good that Linode is taking security seriously From what it seems, the only thing they take seriously is responding to incidents like these and letting customers know. If they were actually serious about security, these things wou
66.
▲
by
bluetooth
13y ago
Welp, it looks like it's time to move to Amazon EC2. It's cheaper and hasn't (to my knowledge) been hacked yet.
67.
▲
Google Operating System blogger Alex Chitsu has a post removed due to bogus DMCA
(googlesystem.blogspot.com)
2 points
by
bluetooth
13y ago
|
0 comments
68.
▲
by
bluetooth
14y ago
Good point.
69.
▲
by
bluetooth
14y ago
It won't work in this situation. Multiple commands here are separated by newlines (like pressing enter on your keyboard) and putting # will only comment out the first one.
70.
▲
by
bluetooth
14y ago
This is really just an extension of clickjacking - modifying the UI to trick the user into performing an undesired action. This is a pretty novel idea, and considering how many websites make use of this to slap their permalinks into copied
71.
▲
Bitcoin shoots past $150 today
(bitfloor.com)
39 points
by
bluetooth
14y ago
|
49 comments
72.
▲
by
bluetooth
14y ago
Some of the new HTTP headers are just a mess. Did you know that X-Frame-Options' Allow-From option only allows you to whitelist one URL? Not a domain - a URL. The RFC actually expects you to communicate via another channel to determine whet
73.
▲
by
bluetooth
14y ago
> For the same reason that we don't call out to JS to require HTTPS but rather use HSTS, XFO is right way to block CJ. I think this is the best point in your argument. If you're going to half-assedly block framing (via JS, not using XFO
74.
▲
by
bluetooth
14y ago
Ah okay, I didn't mean to belittle your work (I actually think it's quite great) I was just hoping you knew this wasn't exactly new material.
75.
▲
by
bluetooth
14y ago
This is old news. http://media.blackhat.com/bh-ad-11/Lundeen/bh-ad-11-Lundeen-... These guys used html5 sandbox to break facebook's javascript frame breaker. Two years ago.
76.
▲
by
bluetooth
14y ago
That should be your motto all the time, for everything.
77.
▲
by
bluetooth
14y ago
I expect nothing less from Instawallet. Previously, they used to keep private keys in the URL and allowed google to index these URLs. It took a lot of pestering and hand-holding to get this fixed. I should have figured this would have happe
78.
▲
by
bluetooth
14y ago
I was speaking anecdotally, both from my experiences and the many experiences I've read about online. Modafinil is a great replacement for sleep once in a while, but repeated usage ends up making it useless. It's not that you don't notice t
79.
▲
by
bluetooth
14y ago
In this case, you end up paying for the tolerance that builds up extremely quickly when you take Modafinil multiple times.