Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
g_p
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
by
g_p
3y ago
The problem with fancy variants on trying to "better protect" a QR code is that users don't know what to expect, and the lowest common denomenator of social compliance means they'll (have to, if they want to not be stran
62.
▲
by
g_p
3y ago
Worth being aware that, as well as keyfobs being super fragmented, many are woefully insecure. Think "they just say their ID number when you put them in a reader field". That means you can trivially clone them. Not hugely exciting
63.
▲
by
g_p
3y ago
If you do go down this route though, be sure to read up on what you're deploying, and understand what your libraries are doing (and more importantly, not doing). You don't want to end up with a naive implementation of OAuth2 (like
64.
▲
by
g_p
3y ago
Partly that, and partly because they were/are built with constrained functionality (do one thing well) that significantly limits the interfaces exposed, and are designed to be secure under the assumption of physical attack (which most
65.
▲
by
g_p
3y ago
I guess a good example of a moat in consumer email could be the fact that once you have the user, their email address is forever tied to your service. They can try to forward emails or fetch them, but they can't retain that email addre
66.
▲
by
g_p
3y ago
Yes, there's a mobile app for iOS (on the app store), and iCloud based sync between desktop and mobile.
67.
▲
by
g_p
3y ago
No, and the standard (RFC 6844) says they must not . That's because, in the eyes of the standard, a CAA record is applicable at time of issuance, but a valid certificate could have been previously issued (and still be valid), even tho
68.
▲
by
g_p
3y ago
You could bind your disk unlock to also include a PIN entered at boot-time (TPM+PIN). This gives you the benefit of system integrity verification at time of boot, but also requiring your input to release the keys (and meaning you can't
69.
▲
by
g_p
3y ago
My guess is that someone saw the value (rightly) in being able to do "good" digital signatures on the web (better than docusign in terms of integrity/proof), and that meant (in their head) those certificates have to work in t
70.
▲
by
g_p
3y ago
Or, proliferation of the English (US) or English (UK) versions of browsers, which refuse to (and are not obliged to) include any of these CAs... I suspect if this ever does play out, it could result in fewer people using "EU spec"
71.
▲
by
g_p
3y ago
I believe that the stated/claimed intent is to create cross-country, bloc-wide digital signature interoperability and acceptance standards. The theory being that you can "digitally sign" things with a national ID (e.g. a smar
72.
▲
by
g_p
3y ago
I wonder if we will see "zero trust" going full circle, and back to isolating privileged systems from the internet, on the basis of endpoint compromises stealing user session cookies. Just making the authentication and service end
73.
▲
by
g_p
3y ago
Some versions of the Mobile Apps Distribution Agreement (MADA) have found their way into being accessible through previous lawsuits. The versions available are almost 10 years old now (e.g. https://www.vox.com/2014/5&#x
74.
▲
by
g_p
3y ago
Not really - the cellular protocols are designed around there being a base station to coordinate radio resource access and time slots and similar. Everything in a mobile network assumes there's a base station and core network to handle
75.
▲
by
g_p
3y ago
Indeed - there are even UPRNs for bus stops, defibrillators, and post boxes. I have also seen lamp posts, EV chargers and fibre infrastructure street cabinets receive them. No need to be a house or building!
76.
▲
by
g_p
3y ago
If you're on Mac or iOS (which you will be if you use Safari), the team from Kagi also develop Orion. It's a browser, heavily focused on keeping to WebKit principles, and obviously supports custom Search engines by default. It
77.
▲
by
g_p
3y ago
I think you answered it yourself - other search engines know which clicks result in the longest dwell on page (as they run analytics and redirect search result clicks through their own referral page). They could optimize their results for b
78.
▲
by
g_p
3y ago
I think their previous pricing was very much a short term reaction to Bing massively changing their pricing model for search crawl index access. When the prices hiked with very short notice, they were potentially going to lose money on ever
79.
▲
by
g_p
3y ago
Just tried that same query without the quote marks on Kagi. The first result is an info box from Stack Overflow showing use of the + operator to join two lists (with a link to source). Then 4 more relevant SO posts (which are more nuanced a
80.
▲
by
g_p
3y ago
For this use-case I think you'll be pleasantly surprised - Kagi seems to be pretty good at prioritizing stack overflow and similar (but not the endless content clones), official documentation pages, and small, niche, focused tech blogs
81.
▲
by
g_p
3y ago
This is an interesting challenge. Part of the difficulty in doing this at early stage (without VC) is that your costs often don't scale in proportion to customer ability to pay. A big chunk of the costs of running Kagi will come from e
82.
▲
by
g_p
3y ago
Interestingly, Docker on Mac actually runs lightweight VM, which then runs a whole Linux OS inside it, to then run your containers. From an isolation perspective, that's giving you hypervisor level isolation which is a step above most
83.
▲
by
g_p
3y ago
Indeed, and TPM + secure boot broadly define how these built-in firmware TPMs (fTPMs) implement verification and validation of system components. TPM is the specification and standard for a predictable way this is implemented, and most mode
84.
▲
by
g_p
3y ago
The ability to do auto-enrolment would break the per-site uniqueness of credentials (which makes them pretty strongly phishing resistant under most sane threat models where the browser isn't totally compromised) Right now, the public k
85.
▲
by
g_p
3y ago
I think this comes down to Apple's envisaged window management paradigm being centered around full-screen windows. In Apple's UX view, it seems like you're meant to maximize windows to "spaces", and switch between w
86.
▲
by
g_p
3y ago
And (unless you manually fix your verification approach) they trust the (unverified at that time) header to declare the signature method used... Which at one point many implementations would accept as "null". So you could take a s
87.
▲
by
g_p
3y ago
When I studied my engineering degree (not in the US) at a pretty high-ranked institution, textbooks were rarely used. I think I only actually purchased and used one, and it was approx $50 (brand new, used was cheaper). Often a course text w
88.
▲
by
g_p
3y ago
Many major browsers expect CT, and won't accept a certificate from a default CA without it being in CT. Therefore it matters a little less whether such a certificate can be issued, but rather whether it can be accepted by a browser (wh
89.
▲
by
g_p
3y ago
There is an API available for haptic feedback through the touchpad, but I can only recall it being used when the pad is "pressed" (i.e. when you are dragging) - many graphics or design tools use it to create a "notch" wh
90.
▲
by
g_p
3y ago
This is probably because that implementation of multiple apps is using the built-in Android Work features. That isolates contacts by default. If you sync contacts into work mode, it should work.
More ›