Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
codexon
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
151.
▲
by
codexon
5y ago
> - Move sshd to a non standard port to avoid the nmap/bot noise. There are scanners like shodan that will scan every single port you have now so moving it to a non-standard port doesn't stop all the attackers.
152.
▲
by
codexon
5y ago
The mac addresses on the ethernet layer are rewritten at each hop. You would only see the mac address of the router your router is connected to, not a chain linking back to the origin.
153.
▲
by
codexon
5y ago
Blocking outgoing spoofed packets requires time and money. No carrier will shut down an ISP paying them 100k/month just because of some spoofed traffic.
154.
▲
by
codexon
5y ago
If you ran an email server 8 years ago your ip would have accrued enough reputation to bypass filters. It also seems to depend on how much email you send.
155.
▲
by
codexon
5y ago
The view is that most emails are becoming centralized to come from a few places. So email hosts like microsoft and google take shortcuts to stop spam by untrusting any IP they haven't seen sending emails for 5 years (this is just a ran
156.
▲
by
codexon
5y ago
Why is everyone complaining about taxes being regulatory capture when email is becoming also becoming a monopoly? It is literally impossible to start up your own email server now and have it accepted by major email hosts like microsoft and
157.
▲
by
codexon
6y ago
> You've already started to add new things, like a TOTP-ish element, to stymie replays. Then the server has to check what it's been fed, having stored neither the original password nor the hash of the password it's been pa
158.
▲
by
codexon
6y ago
How exactly is asking for my password to be hashed "reinventing password hashing and salting"? Seems like the opposite, no? If your password is properly salted, it can't be used to guess passwords on other sites, that's
159.
▲
by
codexon
6y ago
Then just add a time sensitive seed to it? I don't think it is equivalent to leaking plaintext. It can't be used to guess passwords on other websites. If your SSL layer is compromised, you can't trust the client-side encrypt
160.
▲
by
codexon
6y ago
Why not hash the password instead?
161.
▲
by
codexon
6y ago
If you've ever try reporting vulnerabilities, you'll see that some companies won't ever fix the problem until it is widespread.
162.
▲
by
codexon
6y ago
Hackerone has non-technical people screening your exploits. They will often mark them as out of scope. Companies will routinely downgrade the severity of your exploit so they can pay you less.
163.
▲
by
codexon
6y ago
I'm not going to name the billion dollar company on HackerOne I have an issue with, but they routinely downplay bug reports, take over 1 year to deal with some of them (if ever). And just recently one report HackerOne screeners closed
164.
▲
by
codexon
6y ago
HackerOne has people screening reports that don't seem very technical. They closed one of my reports for being a "denial of service" attack when it was a crash caused by malformed input. I've also heard of others having
165.
▲
by
codexon
6y ago
All the inflation went into healthcare, education, housing, stock market, all things conveniently not measured or heavily weighted by the PCE.
166.
▲
by
codexon
6y ago
They are not allowed to buy stocks. By buying bonds they force bond holders to get out of them and into stocks.
167.
▲
by
codexon
6y ago
Sometimes it isn't as nefarious as convincing people to buy a product they wouldn't normally buy, and simply just showing the right people that your product exists.
168.
▲
by
codexon
6y ago
Ads really work. I have a hard time believing there's any company that put effort into having decent ads and found that they did nothing. The only question is if they are fairly priced. It could be argued that they were overpriced due
169.
▲
by
codexon
7y ago
I tried it a few times after that and it still seemed like it was many years away from being competitive with C++/Java/Go
170.
▲
by
codexon
7y ago
I don't remember, I tried it out a little before it was renamed from Nimrod I think.
171.
▲
by
codexon
7y ago
I used it a few times before but I stopped once I realized it was a long way off from being worth using. The lack of tooling, libraries, and numerous compiler bugs meant that it would be easier for me to write the same thing in C++ even tho
172.
▲
by
codexon
7y ago
How about providing web access through remote desktop that has a browser with websockets, flash, and non-GET requests disabled and only retrieving pages through a squid cache?
173.
▲
by
codexon
7y ago
They are very likely real and OVH has a very good system. You can thank them for making free DDoS protection mainstream, dragging all other hosts kicking and screaming into providing DDoS protection. In the past providers like Linode were h
174.
▲
by
codexon
7y ago
I can't find any evidence showing that OLAP means it is okay to lose data from unexpected shutdowns. How can you have correct analytics without a complete set of data? > For good reason. It's not a simple matter of choosing one
175.
▲
by
codexon
7y ago
As I mentioned, there's only 1 place where it says anything about fsync, and in that page, it says that is only for creating .sql files. https://groups.google.com/d/msg/clickhouse/cjJ6v8uzu0Q/jGV59..
176.
▲
by
codexon
7y ago
This is not the implication at all. Clickhouse can easily add fsync, they just choose not to do it. Mongodb also did not use fsync and was ridiculed for it, yet no one mentions this about clickhouse.
177.
▲
by
codexon
7y ago
Fsync is not synonymous with transactions. Not using fsync anywhere means there's a wide window that can be over 10 minutes long when data can be lost when a server gets an unplanned shutdown.
178.
▲
by
codexon
7y ago
What do you mean clearly laid out? This is the only mention of fsync I could find through google or their own search function. https://clickhouse.yandex/docs/en/operations/settings/settin...
179.
▲
by
codexon
7y ago
One thing I haven't seen anyone note about clickhouse though which would be really important to many for data durability, is that it does not use fsync anywhere at all.
180.
▲
by
codexon
7y ago
For such a highly valuable website like hackerone, IP binding should be done, the extra security is worth the slight annoyance at having to relog when your IP changes.
More ›