Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jabbany
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
21 ms
·
181.
▲
by
jabbany
4y ago
But the moment the attacker knows the password is correct, you/the platform would also know the password is compromised assuming they cannot get past 2FA. There is an extremely limited amount of situations that end up with "passed
182.
▲
by
jabbany
4y ago
Based on a certain recent high profile hack, getting just one 2FA auth this way could already be enough ;-) I doubt most people would be suspicious if their system prompted them to touch their key, they touched it, the software kept waiting
183.
▲
by
jabbany
4y ago
This is not a huge deal in practice and can be a good honeypot/alarm system. Most services today have fairly low "lockout" + "notify" thresholds on wrong passwords so brute force spraying passwords is already out of
184.
▲
by
jabbany
4y ago
An alternative that preserves some privacy also doesn't seem that hard to imagine... though it probably has its own can of worms*. Basically, the core problem is digital identities (accounts, IPs, phone #s etc.) are cheap to create (ev
185.
▲
by
jabbany
4y ago
If the computer is compromised you're screwed either way. Even though WebAuthN can't be easily MITM'd like TOTP codes, someone compromising your computer could just use the UI to lie to you. I think the main reduction in secu
186.
▲
by
jabbany
4y ago
Yeah this kind of move seems like an easy way to speed run getting kicked off your payment processor...
187.
▲
by
jabbany
4y ago
Their PSUs are actually quite decent quality and are usually good value for the money. Not a big fan of their motherboards though (hardware is largely fine but the BIOS can be rather flaky).
188.
▲
by
jabbany
4y ago
Kind of curious about this actually. IIRC ethernet cable side is only magnetically coupled to the port/device side via small transformers. So running DC would probably just melt the cable or transformers but is not really likely to dam
189.
▲
by
jabbany
4y ago
This sounds like it would give rise to perverse incentives. If this were the case, Google would now be incentivized to cause problems (e.g. lock you out for "suspicious behavior") so that you'll then pay to get it "fixed
190.
▲
by
jabbany
4y ago
This. There are relatively few visual cues for laypeople to detect counterfeit older (and even moderately recent) US dollar bills. There are no UV sensitive areas, the watermark line is rather faint and there's no special stuff like ho
191.
▲
by
jabbany
4y ago
This... is not a good idea. I used to think this, but then I started interacting with actual end users (normal, non-engineering people). There are 2 main problems with exposing more barebones stuff to non-engineers: 1) Problem solving (thin
192.
▲
by
jabbany
4y ago
Actually, this seems rather important for computer graphics if you want to transform vector-defined strokes into vector-defined closed polygons (outlines). See: https://youtu.be/F2oSR0Oh25c?t=70 For "corners" on n
193.
▲
by
jabbany
4y ago
The "perpendicular to that point" is rather better defined as "perpendicular to all tangents at that point on the source curve".
194.
▲
by
jabbany
4y ago
Though the circle case is a little bit misleading, since it's only the same as scaling in that one case. In general, finding the parallel curve can't be approximated by affine transforms like scaling or translation, which is why i
195.
▲
by
jabbany
4y ago
This seems like an easy way for money and stuff to start going "missing". One has to remember that many large companies don't have an in-house set of software engineers to kludge things together, or a set of people to audit a
196.
▲
by
jabbany
4y ago
Does it help though? I feel like bootleg recording hasn't really been affected much...
197.
▲
by
jabbany
4y ago
Persistent marks as copy protection doesn't work for media mainly because they deal with the consumption rather than copying side, so just one single non-compliant legacy device spoils the entire thing. As for fingerprinting, that'
198.
▲
by
jabbany
4y ago
There is a little bit of difference here though. Console copy protection usually doesn't prevent making copies of the media, rather it prevents _using_ those copies. It's more of an authentication mechanism. OTOH, video is just pi
199.
▲
by
jabbany
4y ago
Not a hardware person but it seems it wouldn't be that much of a difference? Assuming bit flips happen at a fixed rate (cosmic rays whatnot), then wouldn't the likelihood only depend on the actual amount of memory used rather than
200.
▲
by
jabbany
4y ago
IDK, anecdotally at least I broke the 100G RAM barrier earlier this year by upgrading to a Ryzen 5900X with 4 x 32G sticks. RAM has largely become quite affordable with a 32G stick of DDR4 going for around ~$100 (and you can occasionally se
201.
▲
by
jabbany
4y ago
I'd probably guess it's too expensive? IIRC the original Thunderbolt spec was a fiber standard and they moved it to copper because people wanted to power stuff and adding copper cabling for power + power negotiation was infeasible
202.
▲
by
jabbany
4y ago
Considering things like wildcards and glob matching these don't seem far off from what you'd use in a graph db query language. (E.g. something like neo4j)
203.
▲
by
jabbany
4y ago
Doesn't pass power? A huge chunk of the newer USB protocols has also been support for higher wattage faster charging.
204.
▲
by
jabbany
4y ago
Kind of like with code right? Open schematics for electronics, parts blueprints for mechanical components. Anything with code/firmware should also have open sourced code with related toolchain to program it either freely available or o
205.
▲
by
jabbany
4y ago
You pay taxes to both. If there are treaties, then best case is you end up with a tax burden that is equal to whichever is higher. Treaties will usually let you claim credits for foreign taxes paid. Navigating how to apply for the treaty be
206.
▲
by
jabbany
4y ago
I think it also has to be a problem that is able to be constructed in a way where incorrect solutions destructively interfere with each other while correct ones don't. Think of it as being able to simultaneously calculate a bunch of in
207.
▲
by
jabbany
4y ago
This does make some sense. Games are big (file size wise) and prone to updates. Steam helped handle this distribution in a reasonable way. It's also why people prefer app stores or package managers, because they give a predictable dist
208.
▲
by
jabbany
4y ago
No, the other forms require sites to opt-in whereas this just sends the information whether the site wants/needs it or not. There is plenty of harm in just this fact alone, because tracking via the other methods is transparent: you kno
209.
▲
by
jabbany
4y ago
Even theoretically, quantum doesn't make _all_ math problems easy... Can't they just avoid the things (like factoring) that are potentially vulnerable and just use other math?
210.
▲
by
jabbany
4y ago
Frankly at this point I'd happily accept it if certbot required docker or k8s over snap. At least then I know I'll have to run it in a container (and give up then) instead of waste hours figuring out why I get a snap error message
More ›