Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bugtodiffer
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
bugtodiffer
2y ago
Today I value web stuff for one thing and one thing only: they run in the best sandbox we have. I can run untrusted programs from hackernews folks without worrying! I wouldn't do that with native code of course, way too easy to hack me
62.
▲
by
bugtodiffer
2y ago
5) is the only valid reason, the rest has comparable alternative shitty things when using whatever framework
63.
▲
by
bugtodiffer
2y ago
Oh I think it is very much "just fine", but people have requirements which make things too complicated. I find it way harder to work in a React app than a few .html and .js files. TypeScript's cool though.
64.
▲
by
bugtodiffer
2y ago
> anyone who starts a website allowing public posting needs to hire moderators fluent in the hundreds of languages that will be used there? In the EU, that's how it goes. I think there's a minimum amount of visits/users th
65.
▲
by
bugtodiffer
2y ago
There wasn't a single KZ guard that did not know what they were a part of. > But being a nazi guard in a concentration camp is fine as long as you're a nice person I guess. The enemy of my enemy...
66.
▲
by
bugtodiffer
2y ago
Did you know we almost had a lisp style language in our browsers? But Sun's marketing budget on "Java" made something that sounded similar (JavaScript) favored more people wouldn't have these weird questions if we had us
67.
▲
by
bugtodiffer
2y ago
Sadly, most users should have Play Store and nothing else IMO. I respect the Play security team. What I could see: make Play Store and Play Services uninstallable like any other app.
68.
▲
by
bugtodiffer
2y ago
I really do not see how Android should be opened up more. I can install 3 different app stores in 3 minutes.
69.
▲
by
bugtodiffer
2y ago
I bet they somehow analyze it to learn something. And then they use that knowledge to make money.
70.
▲
by
bugtodiffer
2y ago
They surely do not use this usage data, no way :)
71.
▲
by
bugtodiffer
2y ago
maybe response based trickery then? :D What happens to the response after that one, are the first 100 bytes cut of, or what? I'm pretty sure something like this can cause some form of HTTP desync in a loadbalancer/proxy setup.
72.
▲
by
bugtodiffer
2y ago
reading files from sdcard or a million other things
73.
▲
by
bugtodiffer
2y ago
Did you see if you could turn this into HTTP Request Smuggling? Or something else with security impact? Sounds like a powerful bug you have, potentially.
74.
▲
by
bugtodiffer
2y ago
> then their data is not being used for ads maybe, just maybe this is half true as in: they do not use this data _directly_
75.
▲
by
bugtodiffer
2y ago
I always say: the most qualified people in the world are currently trying to get one more second or one more interaction out of you
76.
▲
by
bugtodiffer
2y ago
Having it unregulated as fuck was, I can go bet anywhere anytime and get drunk there too. It should be way more serious, then people wouldn't go there to chill.
77.
▲
by
bugtodiffer
2y ago
Humanity isn't ready for communism yet :(
78.
▲
by
bugtodiffer
2y ago
I trust Mullvad more than others, because IIRC they were one of the few that actually had RAM only infrastructure when they were audited
79.
▲
by
bugtodiffer
2y ago
I wouldn't, especially not having looked at the VPN at first. It might expose you to even more attackers than could fit in your Starbucks
80.
▲
by
bugtodiffer
2y ago
Please give me a link, I highly doubt that.
81.
▲
by
bugtodiffer
2y ago
Really depends on the devs. I've seen it go both ways. But you are right, most retests I have done after the pentest issues were fixed is weird. They actively engineer around our suggested fixes instead of actually doing the work they
82.
▲
by
bugtodiffer
2y ago
My personal blog certainly has, it's good to show you actually do security research if you want a job that offers some time for that
83.
▲
by
bugtodiffer
2y ago
lol you don't talk to the police. I would do anything I can to avoid calling them myself, unless I needed to for insurance reasons
84.
▲
by
bugtodiffer
2y ago
desperate. not shady. I can totally see me trying everything to get rid of my timeshare, I've watched too many cartoons not to fear having a timeshare
85.
▲
by
bugtodiffer
2y ago
You're confidently wrong, dangerous :)
86.
▲
by
bugtodiffer
2y ago
There have been cases? I see this kind of stuff all the time. I once saw an app that had a popup warning me that the TLS cert is wrong but still let me connect...
87.
▲
by
bugtodiffer
2y ago
Okay, but you are aware that "public" means everyone? e.g. the blocked persons friend or frankly second account? What you want is a list of friends that you share your posts too, but then you wouldn't need social media if you
88.
▲
by
bugtodiffer
2y ago
I do not side with the person who has been blocked, but it is very obvious to me that nothing in the world would prevent them from seeing my public posts
89.
▲
by
bugtodiffer
2y ago
yeah on their screen? How can blocking influence the ranking?
90.
▲
by
bugtodiffer
2y ago
Obviously. One can create a new account anyways. So it's never been hidden from them... It's just a feature to reduce interactions, not keep things secret
More ›