Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dh997
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
dh997
11y ago
Exactly. That's the risk to mitigate. Here's scrypt for js using emscripten on actual scrypt C source... the site has to provide and adjust/migrate the three factors over time to ensure a sane amount of cpu/memory is u
32.
▲
by
dh997
11y ago
You're wrong because it's a strawman since if an attacker can intercept the hash they could as easily intercept the plaintext in your traditional server-side architecture. The attacker cannot replay a TLS unless there is a proble
33.
▲
by
dh997
11y ago
Most websites with any sense dont store actual passwords, they usually store salted PBKDF hashed that are compared in constant time.
34.
▲
by
dh997
11y ago
Even awesome, thoughtful Boosted boards catch on fire now and then. I think even with the beginning of honest alternative transport devices pushing technology to break new ground inevitably results in some teething issues that will get fix
35.
▲
by
dh997
11y ago
Investing in many startups requires a great deal of judgement and some due-diligence, far more than either IBM or Yahoo were capable... If direct investment were in-house scalable, institutional investors wouldn't invest in VC funds, b
36.
▲
From EOD blindness to gold medal to promoting a cool watch
(touchofmodern.com)
1 points
by
dh997
11y ago
|
0 comments
37.
▲
by
dh997
11y ago
Most likely cheap consumer devices wouldn't get it, but prosumer, enterprise and industrial gear should think twice about cutting corners on peripherial protection circuits and make sure to test vcc ground reversal and application to d
38.
▲
by
dh997
11y ago
Dangerous tasks should have the most safety interlocks, but not require manual, needy attention that makes it harder to automate deployments. This edge-case functionality may still be useful for self-destructing / remote bricking sens
39.
▲
by
dh997
11y ago
Reinvention without purpose often appears to take credit for fixing "old==bad" and dodging blame for churn, usually ortogonal of understanding of users' needs: enterprise, industrial embedded, IoT, desktop, mobile, etc. and t
40.
▲
by
dh997
11y ago
Wow, this is still even a thing. The form, all its js assets and form api endpoint all have to be secured. And https for everything that contains code. Deploying SRI for web pages over https is also another layer of defense against js tam
41.
▲
by
dh997
11y ago
Dragon NaturallySpeaking could transcribe continuous speach in the late 90's at nearly full speed, it was amazing. But then it disappeared, this explains it. Moral of the story: don't ever pay upfront for deal advice because inte
42.
▲
by
dh997
11y ago
Linux installs (apart from grub boot blocks and partitioning) are JBOF (just a bunch of files). Mostly, the non-user parts are /etc /boot /usr and /var (for package management), and things aren't always in the same
43.
▲
by
dh997
11y ago
Basically efficient, low-latency caching for html and css content is over unless there's SRI for them. It makes sense to have a mini webpage delivered securely that lists hashes for all static assets, and then serve some static assets
44.
▲
by
dh997
11y ago
HN could do its part: for example, start marking all http:// links red. For our content sites, we can also announce to users this change and roll something out.
45.
▲
by
dh997
11y ago
Pretty much. Q @ anyone whom chimes in: what format(s) do sites use for silent, live-action backgrounds to make their websites and apps seem friendlier?
46.
▲
by
dh997
11y ago
Waiting for the cost to reduce, performance and battery tech of semiautonomous drones to improve to the point where crowdfunded watchdog groups could begin to afford to follow every police officer with a camera, live streaming and recording
47.
▲
by
dh997
11y ago
Yup. Buddy deals are the best way to waste your time, lose money and damage relationships.