Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dadrian
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
dadrian
11mo ago
Add a /, e.g. `shortname/`
32.
▲
by
dadrian
11mo ago
Let's Encrypt does not write or maintain certbot
33.
▲
by
dadrian
11mo ago
Non-unique hostnames, which are RFC 1918 space, single-label hostnames, and addresses assigned to mDNS (.local).
34.
▲
by
dadrian
11mo ago
Chrome has shown the HTTP warning in Incognito mode for about a year, and has shown the warning if you're in Advanced Protection mode for about 2-3 years.
35.
▲
by
dadrian
1y ago
Web browsers and operating systems are full of memory safety bugs, and are not written by engineers in crunch these days.
36.
▲
by
dadrian
1y ago
Not clear to me there's a correlation between hours worked and number of memory safety vulnerabilities
37.
▲
by
dadrian
1y ago
I like Zig, although the Bun Github tracker is full of segfaults in Zig that are presumably quite exploitable. Unclear what to draw from this, though. [1]: https://github.com/oven-sh/bun/issues?q=is%3Aissue%20state
38.
▲
by
dadrian
1y ago
Yes, because this is not a security-relevant revocation.
39.
▲
by
dadrian
1y ago
https://dadrian.io/blog/posts/revocation-aint-no-thang/
40.
▲
by
dadrian
1y ago
OCSP stapling, when done correctly with fallback issuance, is just a worse solution than short-lived certificates. OCSP lifetimes are 10 days. I wrote about this some here [1]. [1]: https://dadrian.io/blog/posts/re
41.
▲
by
dadrian
1y ago
Yeah, I assume this means there’s a lot of fraud
42.
▲
by
dadrian
1y ago
This is an unserious article. 1) If you're counting investment, you should count it in dollars, not number of investors or corporate entity locations. 2) This is missing at least two extremely well-known CNE vendors, which makes me dou
43.
▲
by
dadrian
1y ago
No, that is also illegal.
44.
▲
by
dadrian
1y ago
It is illegal for an employer to hack your phone.
45.
▲
by
dadrian
1y ago
I saw someone joke that "once Mistral gets back from their European summer, they'll really be in it", and damn, it does feel like that happened.
46.
▲
by
dadrian
1y ago
Oh nice! That's probably reasonable, although I am pro keeping the accredited investor requirement.
47.
▲
by
dadrian
1y ago
The most basic SaaS companies are not raising $10MM at pre-seed, they’re raising $1-3MM at $10-30MM post.
48.
▲
by
dadrian
1y ago
Most Fund I’s are going to be smaller funds, often $9.99MM to allow for a larger number of smaller LPs due to the $10MM threshold from the SEC. Whereas Fund II-IV are going to be considerably bigger, often hundreds of millions of dollars. S
49.
▲
by
dadrian
1y ago
Are there any good LLM plugins for Obsidian, beyond just throwing Claude Code / Codex at your markdown folder?
50.
▲
by
dadrian
1y ago
It's because GenZ is addicted to nicotine and millennials are all using legal weed. We've just replaced one substance with some others, rather than started abstaining.
51.
▲
by
dadrian
1y ago
You still have to pay taxes on income from non-bug bounty vulnerability markets, be it to law enforcement, brokers, or criminals.
52.
▲
by
dadrian
1y ago
I don't take Gutmann seriously.
53.
▲
by
dadrian
1y ago
hey now
54.
▲
by
dadrian
1y ago
There's a difference between FIPS validation and FIPS-approved algorithms. We can say "you have to use the FIPS-approved algorithms", but skip the useless validation step.
55.
▲
by
dadrian
1y ago
If DOGE had done nothing other than get rid of FIPS validation, the GDP unlock alone would have solved the debt problem.
56.
▲
Sandboxes? In my process? It's more likely than you think
(dadrian.io)
3 points
by
dadrian
1y ago
|
0 comments
57.
▲
by
dadrian
1y ago
That is literally what this proposal is suggesting.
58.
▲
by
dadrian
1y ago
You should absolutely buy a Miata. I have a 2021 Miata and it's one of the best decisions I ever made.
59.
▲
Google's Advanced Protection for Vulnerable Users Comes to Android
(wired.com)
4 points
by
dadrian
1y ago
|
0 comments
60.
▲
by
dadrian
1y ago
I think people are glossing over the fact that Usenix ATC wasn’t even a good academic conference. If you’re submitting high-quality academic work to Usenix, you’re sending it to one of the higher prestige Usenix conferences in a specific su
More ›