Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cortesi
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
91.
▲
by
cortesi
13y ago
Thanks, ordered. There's a substantial body of research in this area, and we're just becoming conversant with it now.
92.
▲
by
cortesi
13y ago
Right, this is exactly the kind of thing we're thinking about now. We already have integration with a bunch of services (GitHub, BitBucket, etc. etc.). At the moment, you still have to pick sounds for these on signup, but very soon we&
93.
▲
by
cortesi
13y ago
Please drop your email into the invites queue. We're working hard on Choir and will have a blog with new features up and running soon. When that happens, we'll drop a line to everyone in the queue.
94.
▲
by
cortesi
13y ago
All of this will be possible soon. We're working on the ability for users to completely customize the sound palette.
95.
▲
by
cortesi
13y ago
We're still thinking about which components will be opened, but we're primarily thinking of this as a service. Our pricing model will probably be based on number of concurrent listeners.
96.
▲
by
cortesi
13y ago
So, an API for the player aspect of Choir is not in the works at the moment. We've worked hard on the other end, though, making it as easy as possible to feed data into Choir and get sound out.
97.
▲
by
cortesi
13y ago
This is very, very high on our priority list. We realise that this is a subjective thing, and that we're not nearly talented enough to explore all the possibilities. Creating, editing and sharing sound packs is on the way.
98.
▲
by
cortesi
13y ago
Yes, making that link clearer is one of the things we're thinking hardest about right now. The (inadequate) measure at the moment is the replay-on-hover when you scrub over the feed messages. I'm not sure how instantly recognizabl
99.
▲
by
cortesi
13y ago
Not yet. We will definitely be putting together more realtime demo feeds, and stock market data is an option. Any links to realtime feeds of data you'd like to hear?
100.
▲
by
cortesi
13y ago
The feed is realtime. We only see commits when the user pushes, or when a merge is done, etc.
101.
▲
by
cortesi
13y ago
What you describe is one of our core use cases. The Github stream is indeed a bit crazy, as you say, because we wanted someone who dipped into it for a minute or two to hear sounds from the full spectrum. Our real-world feeds are much more
102.
▲
by
cortesi
13y ago
Gulp - not sure we were ready for HN yet! At any rate, here's a blog post about what we're trying to accomplish with Choir: http://corte.si/posts/choir/intro/choir.html It's very, very early da
103.
▲
by
cortesi
13y ago
That would be nice indeed. Mitmextract uses libnids, which can do stream reassembly on the fly. It's not such a big step going from reassembling a pcap file to doing the same thing on network traffic.
104.
▲
by
cortesi
13y ago
[edit: I actually misread your question. We don't at the moment have reassembly of HTTP flows from pcaps in base, but there's an external project that does this. As another comment noted, transparent mode is probably still your best bet. h
105.
▲
by
cortesi
13y ago
I run plenty of Java every day without breaking out in hives. I don't particularly enjoy _writing_ Java, though, and the most natural way to extend the Java interceptors is to use Java (Jython notwithstanding). I could have been clearer abo
106.
▲
by
cortesi
14y ago
I used to suffer from quite acute RSI. I am naturally suspicious of anecdotal reports of miracle cures, but for me at least a Kinesis keyboard pretty much solved my problem entirely. I'm much more conscientious than I used to be about postu
107.
▲
by
cortesi
14y ago
Chillingo is the publisher of the original Angry Birds, and it's their social network (which is integrated with Angry Birds and therefore on millions of devices) that had the vulnerability.
108.
▲
by
cortesi
14y ago
Weev's AT&T adventure had nothing to do with UDIDs, and involved only about 100k records.
109.
▲
by
cortesi
14y ago
I found vulnerabilities in two social gaming networks that let you take control of people's Facebook and Twitter accounts using _just_ the UDID. I never published the details of these vulnerabilities, but you can find an official acknowledg
110.
▲
by
cortesi
14y ago
Sorry, I don't think this strategy is workable. Consider - 74% of apps I tested sent the UDID to one or more upstream servers. Furthermore, Flurry alone received UDIDs from 15% of apps I tested. That's just one aggregator, and they surely h
111.
▲
by
cortesi
14y ago
Have a quick read through the posts linked in the article this story points to. I show that using just a UDID, you could access the user's geolocation, games they played, private messages and friends lists on many of the affected social net
112.
▲
by
cortesi
14y ago
Sorry, I don't think this strategy is workable. Consider - 74% of apps I tested sent the UDID to one or more upstream servers. Furthermore, Flurry alone received UDIDs from 15% of apps I tested. That's just one aggregator, and they surely h
113.
▲
by
cortesi
14y ago
Yes, sorry - I'm on the road at the moment, and wrote that in a rush. Part of the problem is that there's not much users can do at this stage. The ecosystem of companies that use and abuse UDIDs is fragmented, and each service that relies o
114.
▲
by
cortesi
14y ago
This is huge. I've been fearing this kind of leak for a long time. If you're unsure why this is huge, here are some posts of mine on this issue showing de-anonymization, complete takeover of social media accounts, and more: De-anonymizing U
115.
▲
Pathod 0.2: the pathological web daemon gets an evil twin
(pathod.net)
2 points
by
cortesi
14y ago
|
0 comments
116.
▲
by
cortesi
14y ago
Yes, this is something I've pondered too. The language is ugly for a number of reasons - not least the constraint of avoiding syntactically significant characters for both URLs (because of pathod) and shells (because of pathoc). At the mome
117.
▲
by
cortesi
14y ago
This is already covered. Have a look at the anchor feature for pathod. For instance, starting pathod like this: pathod -a /foo=200:b@100 Will result in an HTTP 200 response with an body of 100 random bytes if you hit the path /foo.
118.
▲
by
cortesi
14y ago
No, thanks for posting! Just upvote again when you see the release notice next week. :)
119.
▲
by
cortesi
14y ago
One difference is that pathod (and pathoc, the client-side equivalent) works hard to make it possible to violate the HTTP protocol specs at will, in pretty much arbitrary ways. The next version of pathod also moves away from Tornado to let
120.
▲
by
cortesi
14y ago
I started work on pathod to improve the testing of mitmproxy ( http://mitmproxy.org ). It's since become a very capable Swiss army knife with many creative uses. I now routinely use it in pen tests (it's great for exploit delivery), and pat
More ›