Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
davekt
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
davekt
10y ago
https://typing.io/lessons let you type through code, which exercises the right pinky more than prose. The site also requires backspacing to correct typos. This adds realistic overhead not normally captured in wpm measuremen
2.
▲
by
davekt
13y ago
Some amex cards have a 3 digit cvv [1]. [1] http://ecommerce.shopify.com/c/shopify-discussion/t/heads-up...
3.
▲
by
davekt
13y ago
The home page of this article has a section comparing text inputs vs drop downs [1]. [1] http://creditcardjs.com/#drop-down-for-expiration
4.
▲
by
davekt
13y ago
One scenario where immediate detection is helpful is for unsupported card types. The server detection would require users first fill all their card data only to discover they need to start over.
5.
▲
How to Correctly Detect Credit Card Type
(creditcardjs.com)
162 points
by
davekt
13y ago
|
65 comments
6.
▲
Autocomplete and the Three Algorithms
(base2.io)
1 points
by
davekt
13y ago
|
0 comments
7.
▲
by
davekt
13y ago
For a production ready alternative, take a look at http://creditcardjs.com , which was posted on HN a while back. The web site points out common mistakes when implementing credit card forms and delves into the motivation behind e
8.
▲
Running X server without root
(plus.google.com)
1 points
by
davekt
13y ago
|
0 comments
9.
▲
Nginx 1.5.8 adds TCP Fast Open
(nginx.org)
2 points
by
davekt
13y ago
|
0 comments
10.
▲
Java 7u40 released with commercial feature Mission Control
(oracle.com)
1 points
by
davekt
13y ago
|
0 comments
11.
▲
VP9 codec bitstream finalized, soon enabled in Chrome
(groups.google.com)
3 points
by
davekt
13y ago
|
0 comments
12.
▲
Faster curve25519 with precomputation
(imperialviolet.org)
2 points
by
davekt
13y ago
|
0 comments
13.
▲
Plans for Vim 7.4
(groups.google.com)
205 points
by
davekt
13y ago
|
83 comments
14.
▲
Nginx switches from SVN to Mercurial
(hg.nginx.org)
3 points
by
davekt
13y ago
|
0 comments
15.
▲
Heart rate tracking with webcam and OpenCV
(quantifiedself.com)
1 points
by
davekt
13y ago
|
0 comments
16.
▲
Securing ZeroMQ: draft ZMTP v3.0 Protocol
(hintjens.com)
1 points
by
davekt
13y ago
|
0 comments
17.
▲
by
davekt
13y ago
Thanks for responding. I would argue the opposite, that the browser is the safest place to sanitize because it better understands the context where user generated strings will be inserted. An example where the server may not understand the
18.
▲
by
davekt
13y ago
Correct. If the 3rd party js properly sanitizes user input, this xss attack is moot. However, browsers love to eval stuff ( http://html5sec.org/ ), and sandbox iframes provide good defense in depth. Secure programs like qmail have been usin
19.
▲
by
davekt
13y ago
An example attack iframes would make more difficult is XSS in the comment fields, e.g. an attacker bypasses sanitization and injects js into a page. With a sandbox iframe, the comments section could be restricted from compromising the top l
20.
▲
by
davekt
13y ago
For 3rd party widgets, I actually prefer iframe for security. The same domain policy makes it more difficult for xss in the iframe to compromise the parent page. For HTML5 sandbox iframes, the security boundaries are even more strict and tu