Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
hunter2_
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
121.
▲
by
hunter2_
1y ago
> most of the content is just obviously bot generated Either my BS detector is getting too old, or I've subscribed to (and unsubscribed from default) subreddits in such a way as to avoid this almost entirely. Maybe 1 out of 10,000 c
122.
▲
by
hunter2_
1y ago
Browser (and OS) zoom settings are for accessibility; use that to zoom out if you've got the eyes for it. Pinching is more about exploring something not expected to be readily seen (and undersized touch targets).
123.
▲
by
hunter2_
1y ago
Yeah, this is like keeping a sound system equalized for one album and asserting that modern mastering is always badly equalized. Tune the system to the standard, and adjust for the oddball until it's remastered.
124.
▲
by
hunter2_
1y ago
Indeed, the vast majority of things I've flagged or hidden have been the accidental result of skipping that extra step of zooming.
125.
▲
by
hunter2_
1y ago
A bit like the ambiguity of search facets: if I select one facet, I get results that match, but if I add a second facet, should the results expand (OR'ing my selections) or contract (AND'ing my selections)? Presumably they should
126.
▲
by
hunter2_
1y ago
So if my browser auto-completes their domain name and I accept that (causing me to navigate directly to their site and then I click AWS) it's not a report; but if my browser doesn't or I don't accept it (because I appended &q
127.
▲
by
hunter2_
1y ago
Basically it sounds like IaaS is fine (even though someone else manages the hardware and restricts OS choices), and even PaaS is fine (even though someone else manages the hardware, the OS, and the configuration of interpreters such as php
128.
▲
by
hunter2_
1y ago
I'm not super familiar, but it looks like you're subscribing to Roon's metadata but it's "bring your own music" (to quote their FAQ) which can be files you self-host and/or supported music streaming servic
129.
▲
by
hunter2_
1y ago
> you would have no way of telling the difference If only specific individuals are targeted, I agree. But if it's pushed to all users, wouldn't we expect a researcher to notice? Maybe not immediately, so damage will be done in
130.
▲
by
hunter2_
1y ago
I'm not so sure that the family gathering scenario is well-defined, though. If I'm at a gathering in someone's house, and I'm in a room with only the person/people that I'm actively talking to, then I feel reas
131.
▲
by
hunter2_
1y ago
Nice. It's basically a TOFU system (unfortunately disguised).
132.
▲
by
hunter2_
1y ago
Or go ahead and use them, but abort if your password manager doesn't auto fill. Such abort scenarios include not only a password field without auto fill, but also a total lack of password field (e.g., sites that offer OTP-only authenti
133.
▲
by
hunter2_
1y ago
I thought getting code into brew is blocked by some vetting (potentially insufficient, which could be argued for all supply chains), whereas getting code into npm involves no vetting whatsoever.
134.
▲
by
hunter2_
1y ago
I would agree if this were one of those `curl | sh` scenarios, but don't we consider things like `brew` to be sufficiently low-risk, akin to `apt`, `dnf`, and the like?
135.
▲
by
hunter2_
1y ago
For those of us unfamiliar, can you describe the resulting UI pattern? Do you give focus to the password field and then tap a button at the top of the notification shade which automatically types (or gives a choice, if multiple are saved) w
136.
▲
by
hunter2_
1y ago
I agree: any of the potential indicators of phishing (whether it's poor presentation, incorrect grammar, tight deadlines, unusual "from" addresses, unusual domains in links, etc.) can easily have false positives which unfortu
137.
▲
by
hunter2_
1y ago
In terms of presentation, yes. In terms of substance, short deadlines are often what separate phishing from legitimate requests.
138.
▲
by
hunter2_
1y ago
I agree, and this is arguably the best reason to use a password manager (with the next being lack of reuse which automatically occurs if you use generated passwords, and then the next being strength if you use generated passwords). I genera
139.
▲
by
hunter2_
1y ago
That's an even more complicated system. How would we catch them without the type of surveillance or anti-fencing measures that have even more downsides than the amount of theft they eliminate?
140.
▲
by
hunter2_
1y ago
In the early 2000s, even cars with oddball radios (like a CD slot adjacent to climate controls for example) could have an aftermarket head unit installed because dash trim kits were available to replace the proprietary layout with a DIN slo
141.
▲
by
hunter2_
1y ago
I neglected to mention rectifying, but to clarify I meant that the process of stepping down wants to be AC, not that the battery wants AC.
142.
▲
by
hunter2_
1y ago
Would we be able to insulate sufficiently for a new generation of DC fast charging where voltage is so much higher that current is so much lower that the cable isn't thick enough to be worth stealing? Could eliminate active cable cooli
143.
▲
by
hunter2_
1y ago
Indeed, they're talking about L2 AC public chargers in Europe being BYOC. And going back to the idea that cables are de-energized when not charging, this is true for L2 AC also (the EVSE will have a contactor that the car effectively c
144.
▲
by
hunter2_
1y ago
Same idea as birds not getting fried on uninsulated overhead lines, I reckon. Depending on voltage, shoes on the earth wouldn't be nearly as good as a huge air gap, but maybe a tall fiberglass ladder is decent.
145.
▲
by
hunter2_
1y ago
Similarly, I was really excited when I read the headline here on HN and thought this would be about the electrical device. I wonder if the LLM meaning has eclipsed the electrical meaning at this point, as a default in the absence of other q
146.
▲
by
hunter2_
1y ago
Great article! I suppose a similar (yet different) precaution would be needed in data-* attributes or any other part of an HTML document.
147.
▲
by
hunter2_
1y ago
Since JSON is a subset of JavaScript, you can just use a script element, and including the json mime type certainly doesn't hurt: <script type="application/json" id="myJSONData"> { &qu
148.
▲
by
hunter2_
1y ago
There is surely a combination of location and sleep schedule contributing to this, and each have cultural implications: maybe British users gravitate toward certain topics, maybe the best developers tend to be night owls, etc. -- and then y
149.
▲
by
hunter2_
1y ago
I guess they would find it the moment someone in China using a Chinese resolver tries to resolve your rogue record, since that would recurse to one of the root mirrors in China, which presumably feeds this mechanism. Seems like a very minor
150.
▲
by
hunter2_
1y ago
So it's ok to block someone "because you didn't include a session token I gave you in exchange for knowing the password" but it's not ok to block someone "because you didn't stick to manually-operated user
More ›