Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dgl
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
20 ms
·
181.
▲
by
dgl
6y ago
I really like that zsh can be set to expand globs on tab, both useful for editing when a glob is “close enough” and for checking the result quickly. I think a lot of the value of a script like this is you don’t have to switch contexts or th
182.
▲
by
dgl
7y ago
I switched over to Gsuite and I use qmail style addresses, it’s not as friendly as using + addressing (as in it just works) but you can use regexp rewrites on the paid versions of Gsuite to fake it. (Disclosure: xoogler, but still happy wit
183.
▲
by
dgl
7y ago
I find the assumption that software rots after months a sad thing. Most of that is poorly versioned libraries that change quickly. Something like the Go 1 compatibility promise means code written just against core Go should be fine if someo
184.
▲
by
dgl
7y ago
It seems like this is relying on the server to delete the message when accessed? I made a pastebin years ago that does similar using an anchor tag for the key, except it doesn’t guarantee deletion. https://paste.sh I’ve been thi
185.
▲
by
dgl
7y ago
Chrome will disable key pinning for CAs that are user installed rather than system provided (to support companies/schools who want to MITM for slightly less draconian reasons). I do wonder if Chrome will go to requiring CAs for this pu
186.
▲
British Airways faces record £183m fine for data breach
(bbc.co.uk)
12 points
by
dgl
7y ago
|
1 comments
187.
▲
by
dgl
8y ago
Yes, “451: Unavailable due to legal reasons” and then some details about the GDPR (but not saying why). My guess is a local news outlet that’s big enough to know about the legal requirements but doesn’t actually see any value in doing the c
188.
▲
by
dgl
8y ago
https://youtu.be/ENVvwAT25Jk
189.
▲
by
dgl
8y ago
It’s a nice write up and the part on system call interception is only serving as an example, but be careful if you’re considering ptrace in something where security matters. See the answer on https://stackoverflow.com/questi
190.
▲
by
dgl
9y ago
Sounds like you've gone to a lot of effort to use a HSM (good) but then put all your trust in github. At least github supports two factor auth, but you're still placing trust in a third party.
191.
▲
by
dgl
9y ago
The thing I think it is trying to do is enforce that TLS is used for the known domains. Starttls as implemented in most SMTP servers normally allows fallback to non-encrypted delivery (it's opportunistic). This kind of agreed upon enfo
192.
▲
by
dgl
10y ago
Gigabit Ethernet is interesting to me, I've ended up using rather more expensive devices than raspberry Pis because their network performance is poor (particularly on the Pi as the Ethernet is attached via USB).
193.
▲
by
dgl
10y ago
They really should write that it has USB-C charging in bigger letters (see http://www3.lenovo.com/medias/ww-lenovo-laptop-thinkpad-x1-c... for the evidence).
194.
▲
by
dgl
12y ago
I wish more sites would use this (even with a fallback). Twitter right now is showing me timestamps in Pacific time because they trust their geolocation too much.
195.
▲
Vim blowfish encryption
(dgl.cx)
36 points
by
dgl
12y ago
|
17 comments
196.
▲
by
dgl
12y ago
The Powerdns geo backend as mentioned by the article is used by wikipedia among others. I have some additions (e.g. Google Public DNS), see the files at https://gist.github.com/dgl/8344c3ebe405a1400e2d (which also has
197.
▲
by
dgl
12y ago
The very site the (downvoted) parent references points out that WTFPL is actually a perfectly fine licence: https://tldrlegal.com/license/do-wtf-you-want-to-public-lice... See also GNU's site: https://w
198.
▲
by
dgl
12y ago
Because I can't post on stackoverflow either, here's my variant in C (requires glibc, and a deprecated function at that). #include <printf.h> #include <stdio.h> #include <string.h> int d_cb(FILE *strea
199.
▲
by
dgl
13y ago
It gets worse, see http://www.tedunangst.com/flak/post/analysis-of-openssl-free... Essentially the code mistakenly relies on the freelist being LIFO and not being scrubbed.
200.
▲
Track the GOCE satellite
(feed.matthewkeys.net)
1 points
by
dgl
13y ago
|
0 comments
201.
▲
by
dgl
13y ago
This seems to use base64, DNS is case insensitive so really it should use base32 or some other encoding scheme. However DNS is usually case preserving so it will likely work. Unless the recursive nameserver in use happens to implement this
202.
▲
by
dgl
13y ago
In zsh you could use noglob to make this nicer: zmodload zsh/mathfunc _calc() { echo $[$*] } alias c='noglob _calc' Then: % c 2 * atan(1, 0) 3.1415926535897931 (Although this works with any command, using
203.
▲
by
dgl
13y ago
Presumably they learnt from their mistake, the Pentium Pro was the first generation where the microcode could be updated. (An ancient /. article, byte article it links to is dead: http://slashdot.org/story/00/
204.
▲
by
dgl
13y ago
I wouldn't call it pointless, I think it's better than not having it at all.
205.
▲
by
dgl
13y ago
Thanks, I'd meant to set Strict-Transport-Security to solve that, now done.
206.
▲
by
dgl
13y ago
Did you read the about section? The fragment is never sent to the server.
207.
▲
by
dgl
13y ago
I linked to that from https://paste.sh/about -- creating pastes only works on browsers with crypto.getRandomValues (or with the command line client). Okay, there are still issues with the JS environment but this does elimin
208.
▲
Paste.sh - client-side encrypted pastebin
(paste.sh)
21 points
by
dgl
13y ago
|
14 comments
209.
▲
by
dgl
13y ago
It doesn't look resolved to me, check the key fingerprint on any Ubuntu 12.04 x64 server droplet: ECDSA key fingerprint is 97:d7:21:81:9b:77:34:bb:f1:8e:86:25:b0:47:6b:ff. Also: -rw------- 1 root root 227 Apr 25 2012 ssh_host_ecdsa
210.
▲
by
dgl
13y ago
I want to like DigitalOcean but it seems their attitude to security is rather lax, see e.g. http://digitalocean.uservoice.com/forums/136585-digital-ocea... which they said they'd look at in February but haven'
More ›