Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
homakov
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
homakov
6y ago
I can routinely download any torrent in the world on top speed... What problem does it solve? Torrents, as a poor choice for the "killer app", aside, state channels are a curious technology but most traditional implementations [fu
62.
▲
by
homakov
6y ago
I wonder can we do overlay encryption like this: some software encrypts audio and video stream from your camera, then apps like zoom transfer encrypted stream with some noise, and end user software tries to decrypt those streams. This way
63.
▲
by
homakov
6y ago
true, email shouldnt be used when you can identify by unique id. I doubt the bug was even exploitable with most apps. Apple just paid magnitudes more than its severity.
64.
▲
by
homakov
6y ago
Does it rely on a service to log you in with same email that you provide? Because normally services don’t do that. They suggest you to attach new apple account to old account with that email, but allowing outright logging in would be very b
65.
▲
by
homakov
6y ago
Whenever I click "it's spam & unsubscribe" i often keep getting more emails. Then I started clicking "block this address" from another drop-down - never got any new mail. Much recommended approach.
66.
▲
by
homakov
6y ago
one design problem https://medium.com/@homakov/catch-22-of-lightning-network-in...
67.
▲
by
homakov
6y ago
A truly valid problem. Myself i don’t like online communications with friends. It only makes me feel worse. it feels so incomplete and awkward. In person our convo is flowing much better
68.
▲
by
homakov
6y ago
Why there is no sort by rating like on Reddit? I’d prefer reading top comments, not random of 1600
69.
▲
by
homakov
6y ago
Basically better node by creator of node?
70.
▲
by
homakov
7y ago
Have a look at data: URI technique we developed to avoid Apple/App Store altogether for critical apps: https://coins.github.io/secure-bookmark/
71.
▲
by
homakov
7y ago
None of the bugs is critical, not even medium severity.
72.
▲
by
homakov
7y ago
Surprise, you don't need hacker one to get reports. sendbugshere@company.com solves the same issue without introducing a new trusted party.
73.
▲
by
homakov
7y ago
Google Flights as my go-to option. Unparalleled speed, can iterate over 10 days with click of a button.
74.
▲
Airbnb Hunter – find perfect apartments
(medium.com)
2 points
by
homakov
7y ago
|
0 comments
75.
▲
by
homakov
7y ago
How about <img> on the page of the victim that triggers some CsRF with GET
76.
▲
by
homakov
7y ago
Ok I can agree with that. This must definitely be discussed in rails/rails and fixed by design. I probably overplayed my concern with browsers.
77.
▲
by
homakov
7y ago
> The only reason this bug existed is because Rails treated HEAD as GET in some cases but not others It is the main reason, yes, but not the only reason. If it wasn't possible to craft cross-site HEAD (which devs use in real life li
78.
▲
by
homakov
7y ago
> HEAD isn't turned into GET, it's routed the same as a GET request Pardon my poor wording indeed, I intended to mean this too.
79.
▲
by
homakov
7y ago
For a client side code running on 3rd party page, there is no use case to let it send HEAD to you. Only GET and POST should be allowed by default, other methods only through CORS preflight. That was the premise of CORS. They broke it.
80.
▲
by
homakov
7y ago
> I wonder if Rails will fix the default implementation of handling HEAD requests It absolutely should. Nobody expected Rails to covertly turn HEAD into GET. It must be explicit "get_or_head" method in routes.rb
81.
▲
by
homakov
7y ago
There was no proxy view-source: https://not-an-aardvark.github.io/oauth-bypass-poc-fbdf56605... const authUrl = `https://github.com/login/oauth/authorize? client_id=${CLIENT_ID}&scope=read
82.
▲
by
homakov
7y ago
I worked a lot with client side bugs earlier, and clearly this trick has crossed this line. Browsers cannot say in one scenario that "content-type:application/json" are unsafe and in another allow completely unnecessary HEAD
83.
▲
by
homakov
7y ago
Only step 1 is important, that's where the bug is. The rest is routine to get a code for your already authorized app.
84.
▲
by
homakov
7y ago
"should". Real apps are much more complicated than what they are in theory. In theory all CSRF protections must be based on an auth token, in practice they routinely rely on the method or referrer. For this reason browser upgrades
85.
▲
by
homakov
7y ago
You can't achieve a HEAD request with <img> elements, can you? In a rails env the only way to upgrade to non-standard methods (PATCH, PUT etc) were always to supply _method and pass CSRF protection first. This trick is clearly a
86.
▲
by
homakov
7y ago
Wow, why would the browser allow HEAD request in the first place w/o explicit confirmation from github server with CORS headers. This is very strange. It also reminded me of why "match" was removed in the first place -
87.
▲
by
homakov
7y ago
A long boring read lacking arguments.
88.
▲
by
homakov
7y ago
Speaking of "long analyze" have a look at my script - https://news.ycombinator.com/item?id=21420140
89.
▲
by
homakov
7y ago
Airbnb reviews are practically useless. Numerous of times I've been to 10-20 good-reviewed apartments that ended up too dirty or noisy so I had to go to a hotel. Also, for no reason Airbnb prohibits from sorting by reviews or price, s
90.
▲
by
homakov
7y ago
It is a true black swan. I doubt it happens regularly enough to become a reinforcement mechanism.
More ›