Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bugmen0t
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
19 ms
·
61.
▲
by
bugmen0t
5y ago
Pretty sure you will be able to opt out via group policy. If you control your network so hard that you can accept CSRF, it even makes sense. But would you swear that none of your smart devices are terribly insecure and incapable of even upd
62.
▲
by
bugmen0t
5y ago
s/security/privacy/
63.
▲
by
bugmen0t
5y ago
Always wondering if there's a standard format for the thing in emails that uses underscore, slashes, asterisks for underline, italics, bold and less/greater than for URLs. Never found it. Always thought it would be a great additio
64.
▲
by
bugmen0t
5y ago
I'm surprised that none of the business who are in direct competition with Google (or in fear thereof) start to contribute & make use of Gecko. It's really mind-boggling how many companies and how much money depends on the imp
65.
▲
by
bugmen0t
5y ago
> We did a hacky image analysis with ImageMagick to survey favicon colors. Here is the dominant color breakdown across our favicons. This isn’t very accurate, unfortunately. I suspect that many multicolored favicons are getting lumped in
66.
▲
by
bugmen0t
5y ago
The intent is to shift the responsibility to the browser. Decades worth of userspace solution have failed us. The browser is pretty good at HTML parsing.
67.
▲
by
bugmen0t
5y ago
If you sanitize on the server, you are sanitizing for a theoretical browser and how _you_ might think it parse HTML. Any kind of parsing ambiguity will lead to XSS. That's why you should be using an API that relies on the browser'
68.
▲
EdgelessDB: A Database Designed for Confidential Computing
(techcommunity.microsoft.com)
3 points
by
bugmen0t
5y ago
|
0 comments
69.
▲
Safe DOM Manipulation with the Sanitizer API
(web.dev)
1 points
by
bugmen0t
5y ago
|
0 comments
70.
▲
by
bugmen0t
5y ago
The pur is to further the mission of the nonprofit, i.e., an open interoperable web. All money earned stays within Mozilla. In contrast to all other browser products, whose main purpose is increasing share holder value.
71.
▲
Phrack Issue 70
(phrack.org)
717 points
by
bugmen0t
5y ago
|
110 comments
72.
▲
by
bugmen0t
5y ago
HEEx looks awesome. How does compilation work? Does it properly & contextually encode/escape to avoid XSS? I'd love to learn more about the inner workings.
73.
▲
by
bugmen0t
5y ago
It's very easy to "make it work" while fencing with compiler warnings by just copying things around instead of developing a clear sense of memory ownership. I've seen myself fall into this trap. The upside, coming from C
74.
▲
by
bugmen0t
5y ago
There is no options for non-standard ports, but you may perform a local scan using https://github.com/mozilla/observatory-cli
75.
▲
by
bugmen0t
5y ago
Regardless of the motivation behind this change, bear in mind in whose interest the company and browser is working: The shareholders. I can only think of one high-quality browser that belongs to a non profit. Mozilla Firefox. All money earn
76.
▲
by
bugmen0t
5y ago
Have you heard of https://deprecate.it/ ? :)
77.
▲
by
bugmen0t
5y ago
Note that a hash collision is not the same as a pre-image attack. Though it seems to me that finding the latter is also feasible.
78.
▲
by
bugmen0t
5y ago
Did they remove it due to low usage numbers? Turns out those "few users" are big aggregator scripts and proxies for hundreds, thousands users each :) Example: https://twitter.com/intenttoship/
79.
▲
by
bugmen0t
5y ago
And Firefox
80.
▲
by
bugmen0t
5y ago
My home town is too small to have a zoo. I bought a domain that makes it look like there is, which makes me proud owner of the veterinarian@ email address. I also had a lot of fun taking a free design template and combine it with Creative C
81.
▲
by
bugmen0t
5y ago
True, that was somehow expected as obvious characteristics when writing this down. There is now an issue on the spec at https://github.com/w3c/webappsec-subresource-integrity/issue...
82.
▲
by
bugmen0t
5y ago
The reasonable approach is to listen for error events of such scripts and switch the `src` to a self-hosted fallback URL.
83.
▲
by
bugmen0t
5y ago
Hi. Firefox developer speaking here. Feel free to take a look at https://wiki.mozilla.org/Release_Management/Release_Process and https://aosabook.org/en/ffreleng.html . The latter is quite outdate
84.
▲
by
bugmen0t
5y ago
Not to be confused with https://en.wikipedia.org/wiki/OpenSearch .
85.
▲
by
bugmen0t
5y ago
Your post seems more nationalist than anything else. I’ve worked at a geo-distributed company for a long while and let me tell you: The diversity of viewpoints and experiences will make your teams stronger, happier and more resilient. That
86.
▲
by
bugmen0t
5y ago
Reminder that Firefox is most easily customized through Firefox Color at https://color.firefox.com/
87.
▲
by
bugmen0t
5y ago
slack
88.
▲
by
bugmen0t
5y ago
Why? It has auto updates for a long while now. Honestly, I've received auto update notification by emails more often before I see any blog posts or news article about the vulnerability itself. I agree it used to be worse, but this? Thi
89.
▲
by
bugmen0t
5y ago
The definition of site in this case is < https://html.spec.whatwg.org/multipage/origin.html#sites >, for both Firefox and Chrome. If you don't like reading specs, this blog post might be interesting to you <
90.
▲
by
bugmen0t
5y ago
The concept of a Site is defined here https://html.spec.whatwg.org/multipage/origin.html#sites It's basically an origin, but disregarding subdomains.
More ›