Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dlitz
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
dlitz
11y ago
It's not a mistake, it's a feature! 100% Arduino compatibility can make things much more approachable for casual enthusiasts. I've seen some non-programmer _artists_ get Arduino stuff working---barely---which is awesome! If
32.
▲
by
dlitz
11y ago
What RSS reader do you use?
33.
▲
Dan Bricklin invented the spreadsheet–but don’t hold that against him
(qz.com)
2 points
by
dlitz
11y ago
|
1 comments
34.
▲
by
dlitz
11y ago
That was my first thought. My second thought was that it's not much different from what we do all the time anyway, including when we download source tarballs and then run './configure'.
35.
▲
by
dlitz
11y ago
Yup. You're relying on selective enforcement. So, as long as you're white and middle-class, you're fine. Others' mileage may vary.
36.
▲
by
dlitz
11y ago
> And Windows has been infamous for apps reinventing standard UI elements with skinned monstrosities. This becomes painfully obvious when you start working with any kind of GUI automation tools (e.g. AutoIt). I imagine users of screenre
37.
▲
by
dlitz
11y ago
Well, really, it should just work or OSX should prevent this from happening in the first place. Emoji are common among non-technical users---exactly the market that Apple supposedly caters to---and why would anyone expect a non-technical us
38.
▲
by
dlitz
11y ago
> (CTO) Look, we're a startup; we don't have time for the perfect solution here. You should consider being more pragmatic...
39.
▲
by
dlitz
11y ago
The right way to handle this is to recognize that sometimes, technology that has all of the magical properties that you want simply does not exist, or cannot exist. Secure, global key escrow is one of those things.
40.
▲
by
dlitz
11y ago
I used OS X Server in 2008. It had major quality issues that seemed to only get worse with subsequent releases. Several advertised features accessible from the UI didn't work or straight-up broke things. I doubt Jobs paid much atten
41.
▲
by
dlitz
11y ago
Wow. Translation: Not Invented Here.
42.
▲
by
dlitz
11y ago
One potential way to solve this would be to include the origin in the challenge, which the server could check: ssh demo-ssh.bob.com -l 7d7662f63f70de7714 -p 2222 https://www.bob.com Mallory's attack then would have t
43.
▲
by
dlitz
11y ago
Neat idea, but I think there's a confused deputy(?) attack possible here. Specifically, I think there's a missing binding between the SSH session used for authentication and a user's web session. Let's say that Alice has
44.
▲
by
dlitz
11y ago
You don't enforce STARTTLS receiver-side (smtpd). You enforce it sender-side (smtp) by looking up the receiver's policy using DNSSEC/DANE. This is allowed by the RFC and is implemented in Postfix. I've been running th
45.
▲
by
dlitz
11y ago
I wish we could find a way to fix this "old SSL library/configuration" category of bugs across the board. Neither OS distributors, nor app makers, nor sysadmins seem to be uniformly good at (or interested in) staying on top o
46.
▲
by
dlitz
11y ago
AES-NI and RDRAND are different beasts. AES-NI is deterministic, and thus much more difficult to practically backdoor.
47.
▲
by
dlitz
11y ago
Employees: Don't sign a non-disparagement or release agreement when your employer burns you out. It takes time to realize the true cost of a past employer's abuse on your career and your mental health. I've heard it can take
48.
▲
by
dlitz
11y ago
Yes, and if you're running an older browser, then the webserver can provide arbitrary code that just reads the history directly. :)
49.
▲
by
dlitz
11y ago
It would be fairly cheap if we got our secure-connection APIs right. Upgrading the protocol should be as simple as upgrading any system library.
50.
▲
by
dlitz
11y ago
No, MAC-then-encrypt is very, very hard to get right, because you have to avoid creating side-channels (including timing side-channels) between the decryption operation, the padding check (if you're using a block cipher mode that requi
51.
▲
by
dlitz
11y ago
> Facebook, Google and Twitter Aren't these the companies all terrible at taking outside contributions, except for the projects that they don't manage in their monorepos?
52.
▲
by
dlitz
11y ago
> This is also handy if you're security conscious and like to use a different private/public key pair for each host you have an account with! That's an odd definition of "security conscious". This looks more li
53.
▲
by
dlitz
11y ago
I'm not sure of the timing, but today T-Mobile provides IPv6 and 464XLAT.
54.
▲
by
dlitz
11y ago
More useful tech destroyed by DRM. How long are we as an industry going to keep this up? The only DRM that's even remotely defensible is like what KDE's PDF viewer has: a checkbox that says "Enforce DRM restrictions".
55.
▲
by
dlitz
11y ago
What about payroll taxes? In most places, your employer pays additional tax on top of your pre-tax salary.
56.
▲
by
dlitz
11y ago
Wow. Colin, are you just trying to win an argument online or are you really that flippant when it comes to firing an employee? Keep in mind that we're talking about people's livelihoods, here---it's the sort of thing that c
57.
▲
by
dlitz
11y ago
Something like 60% of enterprise IT projects are considered failures, too. If you don't write tests, then you're throwing away your investment. It's that simple. Telling me that the code works today tells me nothing about
58.
▲
by
dlitz
11y ago
Oops, I thought I'd also tried that correction, but I must have made a typo. :)
59.
▲
by
dlitz
11y ago
Broken link?
60.
▲
by
dlitz
11y ago
> ...but that doesn't make it practical... If I had a dime for every penny of damage caused when people downplay the practicality of attacks against deployed crypto... 75 hours is enough time to attack a laptop left plugged in at th
More ›