Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bqe
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
91.
▲
OpenSSL DSA key recovery attack
(eprint.iacr.org)
184 points
by
bqe
10y ago
|
17 comments
92.
▲
Meditations Redux
(seancassidy.me)
3 points
by
bqe
10y ago
|
0 comments
93.
▲
by
bqe
10y ago
That would help, but an attacker being able to deliver an arbitrary website by MITM is still something that should be avoided.
94.
▲
by
bqe
10y ago
This explanation makes the most sense to me. I've moved away from friends in the past few years, and we use a combination of methods to keep in touch, but however you do it, it seems like they just get farther away because some things
95.
▲
by
bqe
10y ago
This is exactly wrong. Profiling does not increase safety whatsoever. Bruce Schneier argues it much better than I would: > If the choice is between random searching and profiling, then random searching is a more effective security counte
96.
▲
by
bqe
10y ago
Sometimes I worry about a dystopian future of tech where each startup is making small incremental improvements on various minor aspects of life ("It's slightly easier than sending a text!") only to be disrupted by a newcomer
97.
▲
by
bqe
10y ago
Can someone who uses Snapchat routinely tell me why you use it routinely? I've been using it for a few weeks to send a picture or two to the few people I know who use it, but it seems pretty limited. I follow a few "famous" p
98.
▲
by
bqe
11y ago
No, it is perfectly acceptable to ban the most extreme members. Just because they don't ban everyone with extreme views doesn't mean they need to keep all of them. I am tired of these all-or-nothing discussions that seem commonpla
99.
▲
by
bqe
11y ago
Why not? If I suppress the notification, you won't see it. You will then click "Log in" and I'll redirect you to your 2FA screen. I think it's ineffective at what it's trying to do.
100.
▲
by
bqe
11y ago
Sean here: the mitigation you speak of (notifying the user that they've typed in their master password) is actually another vulnerability. A malicious page can detect the fact that LastPass put that notification, and then it knows exac
101.
▲
by
bqe
11y ago
For those that missed the sarcasm, Telegram is not open source: https://telegram.org/faq#q-why-not-open-source-everything
102.
▲
by
bqe
11y ago
My favorite Turing tarpit is FRACTRAN, devised by John Conway. It's flabbergasting that it is actually Turing complete, but it is. A FRACTRAN program is a list of fractions, rational numbers. You input an integer and then you find the
103.
▲
by
bqe
11y ago
Gmail will warn users for this, but not for soft failing SPF. That doesn't make sense.
104.
▲
by
bqe
11y ago
There's nothing inherently wrong with that password as long as your code isn't vulnerable to SQL injection, which is trivial to do nowadays.
105.
▲
by
bqe
11y ago
Praesidio – Seattle, WA We're looking for software engineers looking to work with Elasticsearch, PostgreSQL, Java/Javascript. We build a cloud security product for financial institutions. Keeping them and their customers safe is o
106.
▲
by
bqe
11y ago
When I submitted it, the s was automatically capitalized. Maybe dang can fix it.
107.
▲
by
bqe
11y ago
CircleCI is still missing crazy important features like: building downstream dependencies when libraries change and scheduled builds. Until it gets basic features like that, Jenkins it is.
108.
▲
S/party/hack like it's 1999
(openwall.com)
77 points
by
bqe
11y ago
|
31 comments
109.
▲
Privilege
(seancassidy.me)
3 points
by
bqe
11y ago
|
0 comments
110.
▲
by
bqe
11y ago
Next generation is indeed a vague term, but I would use HEVC as a good example of a next generation codec. For another codec to be next gen, it should have the same or better compression than HEVC: about half as many bits to encode the same
111.
▲
by
bqe
11y ago
- Issues that span multiple projects - Searching all issues for an organization - Voting on issues (not just :+1:) - Public issues for private repos - Attaching files (repros, necessary files, etc.) - Dependencies/links - Priority (you
112.
▲
by
bqe
11y ago
It's actually very surprising how little visible improvement GitHub has had in the past few years. What are they working on?
113.
▲
by
bqe
11y ago
This is a really cool product. I am surprised at both the quality of translation and the seamless integration into the page. I am definitely going to be using this. Great job!
114.
▲
We, the Weapons
(seancassidy.me)
1 points
by
bqe
11y ago
|
0 comments
115.
▲
by
bqe
11y ago
About midway through the article, the author mentions the titular film.
116.
▲
by
bqe
11y ago
Many modern blood pressure medicines have almost no side effects for the gross majority of those taking them. I had a very similar experience to the person you're replying to. I am active, eat healthy, and have tried to go off of my hi
117.
▲
by
bqe
11y ago
Could you expand on why it's so much better than HipChat? I haven't used Slack yet, but I'm interested in trying it out. It sounds like it's the same thing as HipChat.
118.
▲
The Practice Startup
(seancassidy.me)
2 points
by
bqe
11y ago
|
0 comments
119.
▲
by
bqe
12y ago
I am skeptical of the quality claims without evidence. Previous third-party studies on VP8 and VP9 have said that both H.264 and HEVC (formerly H.265) outperform VP9 on video quality and encoding speed[1]. [1]: http://iphome.hhi.
120.
▲
by
bqe
12y ago
My favorite query builder for SQL is jOOQ, works on the JVM. It has a great, fluent syntax and lets you get real objects back while writing what is essentially SQL. http://www.jooq.org/
More ›