Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
devrand
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
151.
▲
by
devrand
6y ago
Thankfully most let you skip the UI entirely by having direct input selection IR commands. Get yourself a generic universal remote that either has these buttons, or custom ones you can program. With this I basically never see the UI on my L
152.
▲
by
devrand
6y ago
Isn't the Pixel "a" line similar to the old Nexus line? Granted there was a decent gap in time since it didn't exist until the 3rd generation Pixel.
153.
▲
by
devrand
6y ago
Got it! Thank you for that context. I'm pretty sporadic about updates so I more than likely missed the gap when it was enabled by default and not available to be disabled. Not cool to do that :(.
154.
▲
by
devrand
6y ago
Is it not? I disabled diagnostic and analytics reporting, though it does occasionally ask me to turn it back on. Is there additional telemetry that cannot be disabled?
155.
▲
by
devrand
6y ago
Heck, Amazon doesn't even ask for a CVV.
156.
▲
by
devrand
6y ago
Additional training != new type rating. Additional training may just be a couple hours of instruction. A new type rating would involve both ground school instruction and dozens of hours in a sim. It'd probably take a couple weeks to ge
157.
▲
by
devrand
6y ago
Downside of this is that you could end up in a different broken state: ex. What if the original firmware now has too old of a CA bundle? This could be avoided by using your own PKI for updates (and bundle your own root), but I assume most d
158.
▲
by
devrand
6y ago
The domain was registered with MM.
159.
▲
by
devrand
6y ago
Companies hire MarkMonitor to safeguard their protected marks, which generally involves registering these marks under basically every TLD available. MarkMonitor themselves is an ICANN registrar so companies generally don't need to worr
160.
▲
by
devrand
6y ago
Yeah, and I checked a few whois history sites and the domain had been registered with Mark Monitor as the registrar. That's a major mistake on their [MarkMonitor's] part. Edit: clarified that I meant the error seems to be on MM&
161.
▲
by
devrand
6y ago
I'm not sure that's correct. The system worked like [1]: * Worker is shown a $5 guaranteed paid. * Behind the scenes DD picked some base pay. Let's say $1. * If the customer tipped < $4 then the worker got paid out exactly
162.
▲
by
devrand
6y ago
Not exactly. The $5 will always go to the delivery driver, not Tony Xu the CEO. The problem is that they use the tips to obscure what the base pay actually is so workers didn't really know how much they'll make above the guarantee
163.
▲
by
devrand
7y ago
It reduces risk since revocation is broken. Therefore the potential time that a compromised or misissued cert can be used is reduced by a year.
164.
▲
by
devrand
7y ago
LE is actually following the rules outlined by the Baseline Requirements. "Traditional CAs" have a tendency to just ignore them when convenient. For example, Sectigo has misissued nearly every certificate since 2002, including ~11
165.
▲
by
devrand
7y ago
And what timing! Just today it was announced certs trusted by Safari issued after Sep. 1st must have a lifetime of 1 year [1] [1] https://twitter.com/chosensecurity/status/123025334823601357...
166.
▲
by
devrand
7y ago
How is that simpler? That seems like it doesn't scale and incredibly error prone. If you only have one certificate you may get away with it. But if once you have hundreds or thousands this is absolutely going to break down the human fa
167.
▲
by
devrand
7y ago
What do you use to automatically rotate the certificates from Sectigo? This doesn't seem to be a set it and forget it solution. Also, with Sectigo you're more likely to get an actual broken certificate. They misissued nearly ever
168.
▲
by
devrand
7y ago
Biggest difference IMO is that Nebula is going with the Netflix-model for their network of content creators. I'm not sure how they're going revenue sharing, but I'm guessing it's based on proportional viewership. Nebula
169.
▲
by
devrand
7y ago
They're not trying to compete with Youtube -- like at all. It's seems like they're going for a closed-network of pre-approved creators with a existing sizable subscription-base. They pretty explicitly said this is a platform
170.
▲
by
devrand
7y ago
My hunch is that they turned down the endpoints that the clients are trying to connect to.
171.
▲
by
devrand
7y ago
Nothing. The plans for the deprecation and removal of support for v2 have not been announced yet, see: https://developer.chrome.com/extensions/migrating_to_manifes...
172.
▲
by
devrand
7y ago
> This is a step in the right direction, but YT's system is extra-judicial in nature, and they've decided to be more copyright holder friendly than the law itself requires (likely so the law isn't used, which is cheaper fo
173.
▲
by
devrand
7y ago
Project Zero does not accept bounties. They generally ask for the money to be donated.
174.
▲
by
devrand
7y ago
All DLP products are like this. They impose basic limitations that can easily be bypassed by anyone remotely technically inclined. I've come to the conclusion that these products are just to cover the low-hanging fruit situations of so
175.
▲
by
devrand
8y ago
And that alarm has constantly been going off. CAs have consistently failed to abide by BR policies which would have otherwise gone unnoticed. Things like certlint have come about to help prevent misissuance, but I would wager that most CAs
176.
▲
by
devrand
8y ago
I disagree. CT has exposed a ton of issues in PKI and held CAs accountable. If you're hostnames are sensitive then Web PKI is not the correct solution, like you have identified. At that point you should be running an internal PKI and b
177.
▲
by
devrand
8y ago
I think it happens a lot more often than you think, though often it's more directly presented as a particular market being sold to another ISP. However, it really is just an ISP closing up shop in that market and selling off its networ
178.
▲
by
devrand
8y ago
This isn't made by Google.
179.
▲
by
devrand
8y ago
Or the lack of anyway to monetize your content other than link to a method for accepting donations.
180.
▲
by
devrand
8y ago
Have you tried simple Wikipedia? I find it way easier to conceptualization the topics there and then move onto the main Wikipedia to get more detail, as needed.
More ›