Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
f2n
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
61.
▲
Handycipher: A Low-Tech, Randomized, Symmetric-Key Cryptosystem [pdf]
(eprint.iacr.org)
2 points
by
f2n
9y ago
|
0 comments
62.
▲
by
f2n
9y ago
But Microsoft is saying that they wont push updates without user's consent.
63.
▲
by
f2n
9y ago
So it's okay to have a fingerprint reader as long as you claim to do something to the effect of hashing the fingerprint?
64.
▲
Samba: Authenticated users can change other users' password
(samba.org)
96 points
by
f2n
9y ago
|
13 comments
65.
▲
by
f2n
9y ago
PSA: Don't do this. Secrets don't belong in docker images, they belong in proper secret management tools.
66.
▲
by
f2n
9y ago
I would love to see an open source meetup alternative, maybe one that I can host myself for my meetup.
67.
▲
by
f2n
9y ago
My .io (finn.io if you want to look it up) says: Owner Addr : Obfuscated whois Gandi-63-65 boulevard Massena Owner Addr : Obfuscated whois Gandi-Paris Owner Addr : WA Owner Addr : FR and my full name. Seems obfuscat
68.
▲
by
f2n
9y ago
Meh, I prefer something I can operate/monitor. The guy who runs that is very secretive about all of his setup, to "prevent abuse" (unclear what sort of abuse he's afraid of), but highly opposed to others building their o
69.
▲
by
f2n
9y ago
Interesting. I have a DID that routes to nowhere on all my domain's whois, maybe I should route it somewhere and see what happens.
70.
▲
by
f2n
9y ago
Where? I went to https://www.symantec.com/ in Chrome Stable 63.0.3239.140 and didn't see any entries in the dev console about the CA being untrusted or anything like that. EDIT: I'm an idiot, it didn't occur
71.
▲
by
f2n
9y ago
Yes, but it hasn't made sense in a long time
72.
▲
by
f2n
9y ago
Thank god. I get somewhere between 2 and 10 spam emails to my dedicated whois address every day . Requiring the publication of email addresses with every domain is absurd and serves no purpose.
73.
▲
by
f2n
9y ago
I'd imagine I would have thought the same thing before I actively used a messaging tool that supports message editing (I use Slack for work) Further, the goal of Signal is not to work well for people who are accustomed to the various q
74.
▲
by
f2n
9y ago
Because one is human and one mistypes... I'm normally on the Signal side of this argument, Telegram is trash and should not be used, but basic features like message editing are legitimate requests. I use Signal heavily and a number of
75.
▲
Voting-machine makers are already worried about Defcon
(engadget.com)
2 points
by
f2n
9y ago
|
0 comments
76.
▲
by
f2n
9y ago
If the details in the post are correct, a tool like driftnet[0] should make abusing this pretty easy. Go forth and do bad things [0] http://www.ex-parrot.com/~chris/driftnet/
77.
▲
by
f2n
9y ago
Because if shit like this gets magically patched and no one gets hurt, most people will continue to not care and groups like Tindr can continue to be lazy and do shit like this.
78.
▲
by
f2n
9y ago
1. Okay so print out a bunch for your locality 2. How much validation of signature is there? Do other police officers memorize each others signatures? That seems unlikely 3. I'm sure it'd be pretty easy to get a list of a large nu
79.
▲
by
f2n
9y ago
Definitely do that too
80.
▲
by
f2n
9y ago
Sounds like a great opportunity for some IRL trollin. Get it on film + name and shame the venue.
81.
▲
by
f2n
9y ago
The picture doesn't make it look too difficult to reproduce, why don't you just print a bunch of cards? That was my first thought upon seeing these.
82.
▲
by
f2n
9y ago
It says Authorization, but this is really more of an anti-CSRF token, not an actual authorization credential, and anti-CSRF tokens are completely legitimate to return over an unauthenticated HTTP endpoint.
83.
▲
by
f2n
9y ago
Well, the two undocumented blocked ports that I've found are ports 25 and port 587, for sending mail. They claim that this is how they control spam problems. But I can't really take them seriously after spending hours debugging th
84.
▲
by
f2n
9y ago
Pretty sure they still just give out a /128, and also silently drop outbound TCP connections on some ports over IPv6 (without documenting it)
85.
▲
by
f2n
9y ago
I've been comparing DO and Linode, and quickly finding out that Linode is missing things that are super handy for automated infrastructure building like a metadata service and userdata required for cloudinit. Does vultr offer such opti
86.
▲
by
f2n
9y ago
What does "supports jitsi" mean? Jitsi is an XMPP client, last I checked, are you just saying Matrix supports XMPP?
87.
▲
by
f2n
9y ago
I think what you're missing is that if you don't use AMT , all of the other boot security built into the system can be bypassed. Presumably this is important because if you don't want to use AMT you probably would assume tha
88.
▲
In Vermont, lawmakers lead the way on legalizing recreational pot
(beta.latimes.com)
3 points
by
f2n
9y ago
|
0 comments
89.
▲
by
f2n
9y ago
Quite the opposite, actually: Everyone should expect to be backdoored by proprietary products if they use them, and take appropriate security measures.
90.
▲
by
f2n
9y ago
>First, open source doesn't start and end with GitHub. I didn't mean to imply it is, but if an open source project finds it easier to use one platform (such as github), trying to subvert that by emailing patches sounds like a v
More ›