Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cottenio
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
cottenio
7y ago
This is the first thing that came to mind for me too! I loved VistaPro so much. I got a copy in one of those old programming books you used to buy with the CDs. It also came with PolyRay and some old-school VRML tutorials.
32.
▲
by
cottenio
7y ago
The trinsicoin algorithm is really just a minimum bound based on the most efficient rigs known for a given algorithm and the cheapest industrial rates for electricity. The Litecoin Foundation actually helped out with some of the math and da
33.
▲
by
cottenio
7y ago
This link to the list of Ethereum mining pools might help make more sense of that: https://www.poolwatch.io/coin/ethereum As you can see there are ~570k workers contributing to ~79k mining addresses. A lot of the data
34.
▲
by
cottenio
7y ago
That is hilarious and I fixed that :P
35.
▲
Have Google and Bing Gotten Better at Answering Questions? Zedah's Test Queries
(blog.cotten.io)
1 points
by
cottenio
7y ago
|
0 comments
36.
▲
Delaying the Inevitable: Muir Glacier and the Ethereum Difficulty Bomb
(blog.cotten.io)
90 points
by
cottenio
7y ago
|
70 comments
37.
▲
Deploying the Libra Core Blockchain on Amazon EC2
(blog.cotten.io)
1 points
by
cottenio
7y ago
|
0 comments
38.
▲
DeFi: Deposit Account Tutorial in Solidity
(blog.cotten.io)
1 points
by
cottenio
7y ago
|
0 comments
39.
▲
Russia's Bitcoin Hacking Funds: How the Mueller Investigation Ties It Together
(blog.cotten.io)
7 points
by
cottenio
7y ago
|
0 comments
40.
▲
Decentralizing a Certificate of Deposit
(blog.cotten.io)
3 points
by
cottenio
8y ago
|
0 comments
41.
▲
Wash Trading: How Crypto Exchanges Are Faking 67% of Trade Volume
(blog.cotten.io)
2 points
by
cottenio
8y ago
|
1 comments
42.
▲
An Overview of Bitcoin Transaction Types and Methods of Laundering
(blog.cotten.io)
2 points
by
cottenio
8y ago
|
0 comments
43.
▲
Congress on Market Manipulation and Crypto Regulation
(blog.cotten.io)
2 points
by
cottenio
8y ago
|
0 comments
44.
▲
Bitcoin Isn't Dying, but Another Big Crash Is Coming
(blog.cotten.io)
3 points
by
cottenio
8y ago
|
0 comments
45.
▲
Another Bitcoin Price Crash Imminent?
(blog.cotten.io)
3 points
by
cottenio
8y ago
|
0 comments
46.
▲
by
cottenio
8y ago
One suggestion is to allow further segregation of permissions for functions like SLEEP, BENCHMARK, etc. A front-end request has no need for it. It’s the exposition of things that “act” on lax query permission sets that “appear” read-only (b
47.
▲
by
cottenio
8y ago
Yes, thank you - since the most "secure" method of generating UI/UX while still depending on a database at least requires SELECT permission, even if INSERT/DROP/DELETE are enabled, having SLEEP() not require special
48.
▲
by
cottenio
8y ago
It only takes one PHP developer using PDO to read an article like this one to open up SQL injection holes. http://pdo.w3clan.com/tutorial/176/like-clause-in-clause-and...
49.
▲
by
cottenio
8y ago
These are valid points, but don't necessarily reflect the reality of a production web environment whose user ONLY has SELECT access to read caches and view data from the database. Being able to enumerate vulnerable spots or exfiltrate
50.
▲
by
cottenio
8y ago
Heh, one of the most common things I see when reviewing code is PDO users realizing they can't "bindValue" or "bindParam" an array of values coming into an IN() clause. Here's a decent example of doing it right
51.
▲
by
cottenio
8y ago
This is a valuable point: you can absolutely exfiltrate data this way based on timing, and it's fairly automated with tools at this point.
52.
▲
by
cottenio
8y ago
Correct. It's more valuable, especially when trying to exfiltrate data or when trying to inject XSS opportunities. Plus, realistically, SLEEP allows you to scan for thousands of different test cases in a quick period and measure the ha
53.
▲
A Very Sleepy MySQL Attack
(blog.cotten.io)
70 points
by
cottenio
8y ago
|
43 comments
54.
▲
Hacking Node.js “May I Have This Repo?” – The Danger of Upstream Dependencies
(blog.cotten.io)
2 points
by
cottenio
8y ago
|
0 comments
55.
▲
Bitcoin Crashes Below Energy Cost
(blog.cotten.io)
4 points
by
cottenio
8y ago
|
0 comments
56.
▲
Bitcoin Cash Fork – SV is burning $1,500 an hour trying to keep up
(blog.cotten.io)
3 points
by
cottenio
8y ago
|
0 comments
57.
▲
Gmail Vulnerability Allows Anonymous Emails
(blog.cotten.io)
2 points
by
cottenio
8y ago
|
0 comments
58.
▲
by
cottenio
8y ago
Note: this isn't the same set of bugs I previously reported; this one let's you blank out the sender completely in the UX for all views, and affects mobile as well.
59.
▲
Ghost Emails: Hacking Gmail's UX to Hide the Sender
(blog.cotten.io)
7 points
by
cottenio
8y ago
|
1 comments
60.
▲
by
cottenio
8y ago
As @romed notes above, it looks like it is intended as a feature. One which I think sacrifices majority-security for minority-utility.
More ›