Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dimman
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
by
dimman
10y ago
If they could just focus on producing good movies than focusing on technical details. Just take the Dumb & Dumber movies for instance. IMO, one of the reasons the new movie isn't as good as the old is due to the image quality. I do
62.
▲
by
dimman
10y ago
> Sadly, the Quake engine is irrelevant today, and I wish someone would write a similar serious of articles about their development efforts and battles. The original one perhaps, but there are several updated and improved versions out th
63.
▲
by
dimman
10y ago
Well one could argue that in C a string is not a string unless it's NUL terminated... It's a choice they made to make it easy to detect truncation. If you don't care about the return value of strlcpy you can modify it to skip
64.
▲
by
dimman
11y ago
I think (I still don't know the details of their implementation) the confusion is caused by them using the term P2P servers. I think thats actually STUN/TURN servers that they use as help to get P2P (direct) connections between ca
65.
▲
by
dimman
11y ago
"This is insecure, of course." No really it's not insecure per se. I _can_ be insecure if not done properly just as well as it can be safe if done properly.
66.
▲
by
dimman
11y ago
If the device can't communicate outbound then no you're completely safe. There's no magic into this, hole punching is just a silly name for a simple technique. Hole punching works when both A and B are behind NAT. It also all
67.
▲
by
dimman
11y ago
What I described is a safe method (except ofc if you have someone in your network that can spoof adresses or your other endpoint has been compromised, however those are factors that we can't do much about). I'm not saying that the
68.
▲
by
dimman
11y ago
Yeah I noticed that it sounded like I misunderstood you, however I did not. Lets just get it straight: I agree with you and him that it would be a lot nicer to let the user choose to enable this, and definitly not make it impossible to disa
69.
▲
by
dimman
11y ago
I don't know where your getting the first part from? As I said earlier I don't know how they've chosen to protect themselves, I do hope they use certificates to authenticate camera/client to verify that the client has ac
70.
▲
by
dimman
11y ago
Hole punching is nothing spectacular, let me explain simply: You're on your computer connected to a regular home router. You hit google.com in your browser. What happens is that you create an outgoing request towards google.com port 44
71.
▲
by
dimman
11y ago
I do fully understand how the technology works. Let me explain: "punching holes through firewalls" <-- This _simply_ means that the device does a connect() call towards the clients IP:port while the client does a connect() towa
72.
▲
by
dimman
11y ago
This sounds basically like a STUN/TURN + P2P solution which in itself _does not_ mean it's unsafe! It can be unsafe just as anything else out there if it's made unsafe. As explained by the company representative (including my
73.
▲
by
dimman
11y ago
Searching for 'sweden' on the page gives me one hit, which is the context of old bands like Opeth. What am I missing?
74.
▲
by
dimman
11y ago
Funny that Sweden ain't mentioned there with atleast bands like At the Gates, In Flames and Dark Tranquillity (I saw some mention of Opeth)...
75.
▲
by
dimman
11y ago
But '>' > '<'?
76.
▲
by
dimman
11y ago
Anyone else than me (as a C programmer) that felt like: "Nice, most things mentioned are how I prefer to do it anyway"?
77.
▲
by
dimman
11y ago
joke Let's hope you won't get systemd'd now instead end joke
78.
▲
by
dimman
11y ago
From the MS blog mentioned I find this section, or how it's formulated, rather interesting and disturbing: "3. Advertising Data We Don’t Collect Unlike some other platforms, no matter what privacy options you choose, neither Windo
79.
▲
by
dimman
11y ago
A swede goes nuts and builds a cat door with built in face recognition, heating, lights, rfid etc based on raspberry pi: Pictures and story: http://joakimsoderberg.github.io/catcierge/ Code: https://github.c
80.
▲
by
dimman
11y ago
Yep, it's as simple as that; almost. There's good ways to do it and there's bad ways to do it. 1) Figure out what's wrong at an early stage, why it's wrong and come up with a proposal of how it could be improved. Fi
81.
▲
by
dimman
11y ago
To everyone who's interested and programming and are thinking; what should I do/program? I'm sure there are a lot of small things or applications you can do to help other people in need. See it as a learning experience and so
82.
▲
by
dimman
11y ago
>I find it more likely that the blog was (maybe still is) compromised. That would be my thought too if it were someone else, but it's Oracle so it's most likely real.
83.
▲
by
dimman
11y ago
Sure, but what else could they say publicly? Of course the most reasonable thing would be not to say anything at all and work together with the credible sources and provide something better than a threatening legal letter. Lets just hope th
84.
▲
by
dimman
11y ago
Afternoon laughter, thanks :D
85.
▲
by
dimman
11y ago
Again, delaying the PoC exploit code release gives people some time to patch their systems. How much time depends on the skill of the attacker and complexity of the exploit, but some time is better than no time.
86.
▲
by
dimman
11y ago
No, analyzing a released patch and then write an exploit takes time. Compare that with taking a pre-written exploit and executing it, so it has nothing to do with "false sense of security". Fact is that it gives people more time t
87.
▲
by
dimman
11y ago
They sure are valuable, he never said otherwise. His point was that the PoC exploit was released before or right at the time that patches became available and delaying the exploit PoC would give people a bit time to patch their systems.
88.
▲
by
dimman
11y ago
That's true, however you would still need to possess the private key to be able to validate.
89.
▲
by
dimman
11y ago
This tool makes as much sense as most project managers I've met. (It doesn't, it's just a joke)
90.
▲
by
dimman
12y ago
Quick note: Looks like you've checked in your swap files filename.c~ in the repository. These should probably be deleted and add an entry to ignore *.c~ in the gitignore file.
More ›