Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jamieweb
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
jamieweb
6y ago
I'm interested to know whether the SHA256 hashes are just done on a TOFU basis, or whether they actually verify the Authenticode/GPG signatures of the EXE files to get an 'authoritative' or 'trusted' hash.
32.
▲
by
jamieweb
6y ago
Most users will click straight through the approval though, like when they granted it full permissions at install. And is the signing actually effective anyway? There's very little mention of it online, and as far as I can see it isn&#
33.
▲
by
jamieweb
6y ago
To be honest that problem exists for essentially any software that auto-updates. You just have to hope that the built-in integrity checking (if any) works and is effective. That's why I like software distribution methodologies that rel
34.
▲
by
jamieweb
6y ago
A pair of $5 cloud servers and a Cloudflare load balancer for resiliency. Ansible is used to build and maintain both servers, and the actual web content is in Git. I use `receive.denyCurrentBranch=updateInstead` in the repo config on the se
35.
▲
by
jamieweb
6y ago
I can see where you're coming from on the privacy bit, but from a security point of view, Chrome/Chromium is generally a well-secured browser. Yes it's not written in a memory-safe language, but drive-by exploits and attack
36.
▲
by
jamieweb
6y ago
It's a challenge to weigh up the risk of not using an adblocker versus the risk of the extension getting compromised. I guess that solutions like DNS-level blocking or custom hosts files are a fair balance, but I still like the DOM-bas
37.
▲
by
jamieweb
6y ago
There are 4 species of damselfly named after each of the band members of Queen. https://en.wikipedia.org/wiki/Heteragrion_freddiemercuryi
38.
▲
by
jamieweb
6y ago
Often the reason for having the user and password fields on separate 'screens' is to facilitate federated logon. I.e. if someone has an account where they 'Logged in with Google' or it is connected to an IDAM solution li
39.
▲
by
jamieweb
6y ago
Yeah, there are 500 and 503 errors in the dev console. Twitter is usually first to report this stuff: https://twitter.com/search?q=youtube%20down&src=typed_query&...
40.
▲
by
jamieweb
6y ago
Perhaps something like IPFS or Dat? If the site gets more than a few visitors per day it should remain cached.
41.
▲
by
jamieweb
6y ago
I definitely agree with you in regards to the "everything is a text file" thing, but the average computer user doesn't know how to properly utilise text files and manage them effectively. This is similar to the fact that basi
42.
▲
by
jamieweb
6y ago
I was surprised to see that the web server for www.microsoft.com reports via the 'Server:' header that it runs on IIS 10. To me that just seems weird... even though it's their product.
43.
▲
by
jamieweb
6y ago
Slack and Trello. I'd love to be able to have a '#trello' channel where I can see my full board without having to leave the Slack interface.
44.
▲
by
jamieweb
6y ago
I'm interested to know what the majority of the Windows machines are used for. I can't think it'd be anything other than 'big enterprise' applications, where there seems to be a lot of bespoke stuff built specifical
45.
▲
Using SPF Macros to Solve the Operational Challenges of SPF
(jamieweb.net)
1 points
by
jamieweb
6y ago
|
0 comments
46.
▲
by
jamieweb
6y ago
My own solution is AWStats combined with a custom log file anonymizer that I wrote. https://gitlab.com/jamieweb/web-server-log-anonymizer-bloom-... This will provide stats on unique visitors, most viewed pages, referri
47.
▲
by
jamieweb
6y ago
Does anyone know of an equivalent product/solution for the cryptographically-linked social media identities feature of Keybase? Technically the cryptographic links can still be verified even if Keybase doesn't exist anymore, but t
48.
▲
by
jamieweb
6y ago
I'm delighted to see that they have a vulnerability disclosure program for the app too [1]. That's fairly rare for the public sector - the UK Gov and NCSC are really leading on this sort of stuff. [1] https://github.com
49.
▲
by
jamieweb
6y ago
Free for personal and small team use to gain brand and product awareness, then charge for support, additional features, higher usage limits, etc. Basically the same as Slack, Trello, etc. Be careful with per-user billing though, as this put
50.
▲
by
jamieweb
6y ago
I've had a good experience with Zare.com. Support is very fast and the pricing is fair.
51.
▲
by
jamieweb
6y ago
AMI BIOS?
52.
▲
by
jamieweb
6y ago
My own solution to this is to store the server key fingerprints in a public Git repository, which can then be pulled from on all devices that need to be able to connect. This works nicely for my own personal setup with a few servers. It may
53.
▲
by
jamieweb
6y ago
I'm not seeing much mention in this thread of the cryptographically-linked identities feature of Keybase, i.e. where you can link your Website, Twitter, Reddit, HN, etc. As far as I know, that was Keybase's initial offering, which
54.
▲
by
jamieweb
6y ago
As someone who has been through this process, I strongly agree with the advice of Lammy and nikivi posted in this thread. Unless you have a high-traffic blog with lots of user engagement, I think it's best to keep your blog clean and h
55.
▲
by
jamieweb
6y ago
Just a pointer, but something like Plainsight[1] may give you some ideas. You could agree on a source text with your friends in an out-of-band way, then everyone just has to go and download whatever book/song/etc that you agree on
56.
▲
by
jamieweb
6y ago
Be aware that the [trusted=yes] config disables GPG signature verification for the repository, which does slightly break the security model of Apt (where repositories can be untrusted/HTTP-only as long as all packages are signed by tru
57.
▲
by
jamieweb
6y ago
For blogs that really don't have RSS, I use Versionista[1] in order to monitor the page for changes. [1] https://versionista.com/
58.
▲
by
jamieweb
6y ago
For those wondering, the domain tpc.int was registered before `.int` domain registrations required an established international treaty. It was grandfathered in when this requirement was added.
59.
▲
by
jamieweb
6y ago
For my own reference and for anybody who just Googled it, the SHA256 hash of pop-os_20.04_amd64_intel_5.iso is 5478241142930dbd95143773d53be079087024d3112614a901edc2829040f996, verified using GPG key 63C46DF0140D738961429F4E204DD8AEC33A7AFF
60.
▲
Pop OS 20.04 LTS
(pop.system76.com)
269 points
by
jamieweb
6y ago
|
170 comments
More ›