Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ircmaxell
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
ircmaxell
12y ago
That's fair. But that's also the vast minority of these results that I can tell...
32.
▲
by
ircmaxell
12y ago
Can you please provide just one? No other comment does that. And to be clear, I'm talking about providing at least one legit use for passing user input directly to exec without any kind of filtering...
33.
▲
by
ircmaxell
13y ago
Interesting choice of questions. Neither of which have an answer. Unless you want to discuss the fine details of the problem. In which case I'll hire your site to do the architecture for free next time I have a major project. Questio
34.
▲
by
ircmaxell
13y ago
Check it out for yourself. Here's the random generating parts, pulled out for you: http://stackoverflow.com/questions/14673005/how-does-phps-pa...
35.
▲
by
ircmaxell
14y ago
The response would seem warranted if you had been a participating member of the PHP internals list for any significant length of time. Stas is pretty well known for jumping into threads and completely derailing, and shooting things down wit
36.
▲
by
ircmaxell
14y ago
Well, first, let me say thanks for the compliments! As far as the missing parts, yes, we know those are missing. The Zval implementation was a place-holder to let it work. Now that it's working for basic code, the goal is to refactor in an
37.
▲
by
ircmaxell
14y ago
A lot of them are installed via composer (see the PHP-Parser project for most of them): https://github.com/nikic/PHP-Parser
38.
▲
by
ircmaxell
14y ago
I've updated the readme with the above... Thanks!!!
39.
▲
by
ircmaxell
14y ago
I'm the author of this library. I figured I'd answer a couple of questions as to why I wrote this. First, it was something that I always wanted to do. For no particular reason other than I wanted to do it. I knew it was possible, but poss
40.
▲
I Am Not A Programmer. And Neither Are You
(blog.ircmaxell.com)
2 points
by
ircmaxell
14y ago
|
0 comments
41.
▲
by
ircmaxell
14y ago
> The patent they sued samsung over can be considered silly but what choice they had? I bet if this verdict was not given, next galaxy series would've been like iPhone 5. You mean the way that iOS 3, 4, 5 and 6 have stolen things from A
42.
▲
by
ircmaxell
14y ago
> But considering everything, they had no other choice legally. Patents are not Trademarks. Patents are valid and legal even if you don't enforce them (where trademarks become invalid if you don't enforce them). So no, they did have a c
43.
▲
by
ircmaxell
14y ago
Well, that depends. If the patent was found to not be valid because of invalid intent by the "inventor" (such as known prior art, knowingly stealing an idea, knowingly patenting something that's unpatentable), it actually is the inventors f
44.
▲
by
ircmaxell
14y ago
> This is the only question I was asking, and you haven't really addressed it in any detail. I thought you meant the function in its entirety. So, to your specific point, it's not bad . That doesn't mean it can't be improved upon. For
45.
▲
by
ircmaxell
14y ago
I wanted to go down the OOP route initially. Then I decided against it for a number of reasons. Here's a breakdown of that reasoning... http://www.reddit.com/r/PHP/comments/zrprk/the_new_secure_pa... Additionally, the general drift hasn't
46.
▲
by
ircmaxell
14y ago
I did a breakdown on a similar snippet here: http://www.reddit.com/r/PHP/comments/zrprk/the_new_secure_pa... But for this case, the salt generation is much better (assuming that `mt_rand` is a good enough source of entropy, which may or m
47.
▲
by
ircmaxell
14y ago
The main reason that I didn't provide bindings to PBKDF2 is that I didn't want to create a new output format. There's presently no crypt(3) format specified for PBKDF2. So that means that I would need to invent one. That's not something I'm
48.
▲
by
ircmaxell
14y ago
Here's an explanation of my rationale for not making it an object instead of a function: http://www.reddit.com/r/PHP/comments/zrprk/the_new_secure_pa... Here's the last paragraph (in case it's TLDR, or you don't want to click through): &#
49.
▲
by
ircmaxell
14y ago
> The query in this case is "GPL site:X". Site 1 and 3 have no page with the term GPL inside. GPL has no requirement that the site make any mention of the license. It says the license must be included with the distribution. So check the
50.
▲
Reinvent The Wheel
(blog.ircmaxell.com)
4 points
by
ircmaxell
14y ago
|
0 comments
51.
▲
by
ircmaxell
14y ago
Where did he refuse to fix it? I'm confused. I've talked with him directly, and we're in progress on a complete fix for that issue (the cryptography issues in the session class)...
52.
▲
Framework Fixation - An Anti-Pattern?
(blog.ircmaxell.com)
3 points
by
ircmaxell
14y ago
|
0 comments
53.
▲
by
ircmaxell
14y ago
Before anyone else brings it up, there are some issues with the session handler function. I'm working on a write-up and pull-request for them to fix the broken cryptography used there.
54.
▲
by
ircmaxell
14y ago
Ok, you have me confused. I half want to raise the BS flag... Could you explain something here? How can a block cipher that has 128 bits of output be attacked 8 bits at a time (where 1 bit change in the input will change on average 64 bits
55.
▲
by
ircmaxell
14y ago
That's fair. However I'd argue that someone implementing their own algorithm would not use a library like keyczar. They would just write their own. So while it's possible to write your own and be secure, IMHO it'd be better to stick to vett
56.
▲
by
ircmaxell
14y ago
Ok, I'll bite. Why would it be more secure? Would the following block cipher be more secure than AES? function encrypt(block, key) { return block XOR key; }
57.
▲
by
ircmaxell
14y ago
One point: this list/pledge is for average developers, not crypto experts... > This abets a hugely widespread misunderstanding about the security of crypto. You could in fact invent your own block cipher core, and if you dropped it into
58.
▲
The Secure Programmer's Pledge
(blog.ircmaxell.com)
59 points
by
ircmaxell
14y ago
|
41 comments
59.
▲
by
ircmaxell
14y ago
Very simple. Either: $copy = $original; Or, if you must have a function, function array_copy(array $a) { return $a; } Arrays use the normal copy-on-write semantics of PHP. They are not passed by reference or ob
60.
▲
by
ircmaxell
14y ago
That wasn't my intention at all. I'm sorry if that's how it came across. It's just that I got tired of seeing people refer to code as procedural because it uses functions, and refer to code as OOP because it uses classes. I was just trying
More ›