Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jamieweb
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
17 ms
·
61.
▲
by
jamieweb
6y ago
How the Internet actually works from the ground-up. There are lots of videos that stop once they get to the IP/network layer. There is very little content that goes further down the stack than this and talks about the backbone, trans
62.
▲
by
jamieweb
6y ago
I mean a policy against contacting them outside of their duties of work. This is fairly standard practise for anybody with access to personal data as part of their job. I'm sure there's all sorts of problems, ranging from simple n
63.
▲
by
jamieweb
6y ago
I wonder whether there were any negative repercussions for the postman? I'd be surprised if there isn't a policy against personally contacting mail recipients. Surely it'd be some sort of data protection violation for him to
64.
▲
by
jamieweb
6y ago
I'm not talking about gaining persistence via a legitimately-installed system service. Instead I'm talking from a malware point of view. If a malicious Snap has read/write access to non-hidden files within someone's home
65.
▲
by
jamieweb
6y ago
> Why are you downloading random crap from teh snap store to begin with? I'm not, but the fact that there's the potential for junk to exist on the store in the first place is the problem, especially when there isn't adequa
66.
▲
by
jamieweb
6y ago
Another point is that when installing Snap packages from the command-line, the verification tick only appears after the install has finished, by which point it is already too late. You can view package info prior to installing, but if we&
67.
▲
by
jamieweb
6y ago
I was specifically talking about the default, trusted Ubuntu Apt repositories, not custom PPAs which are of course inherently untrusted. > You install it, at worst it will cryptomine that is it. If that happens then I have no choice but
68.
▲
by
jamieweb
6y ago
What do you mean? I'm assuming that this is a Snap Store feature? My concern is really more about the command-line, as that's how I (and probably most technical users) install packages.
69.
▲
by
jamieweb
6y ago
> The only 'con' is the pushing of Snap packages. It looks like deb files only can be installed via the terminal. My main concern with Snap is security. Using the default Ubuntu Apt repositories, I can `apt install` pretty much
70.
▲
by
jamieweb
6y ago
But certain packages are migrating to Snap-only, e.g. Chromium. I understand why they're doing this (primarily to save on build times), but the way they've gone about it (using a transitional Apt package that just installs the Sna
71.
▲
by
jamieweb
6y ago
You're right regarding the sandboxing. Snaps use 'plugs' to add sandbox exceptions that can be configured by the package author and enabled at install time, e.g. to allow access to your home area or the network. Even if the s
72.
▲
by
jamieweb
6y ago
Sqlectron [1] is a great open-source GUI SQL client that allows you to see what you're doing in real-time, which helps massively with practising. You can also use it to validate what you've done using other tools. E.g. if you writ
73.
▲
by
jamieweb
6y ago
* Improved access to the democratic process, e.g. allowing testimonials in formats other than attending a town hall in-person * Improved version control and auditability of all Government documents - the authoritative source of all bills&#x
74.
▲
by
jamieweb
6y ago
Other commenters have already covered the political/financial difficulties of this, so I won't mention those. However, the journey of CertSimple may be marginally relevant to what you're proposing. They were a small CA focusi
75.
▲
by
jamieweb
6y ago
They most likely didn't actually 'turn on' RPKI, but just began filtering the test range that Cloudflare are using. This will allow them to pass Cloudflare's test page, without actually validating and rejecting invalid r
76.
▲
by
jamieweb
6y ago
For those who don't have their own Autonomous System, but want to play with RPKI validation, you can join DN42 [1] and validate routes there. Netravnen kindly provides a route export compatible with GoRTR and Routinator [2], which has
77.
▲
by
jamieweb
6y ago
I remember reading about Individual Validation (IV) certificates, which I believe were similar to Extended Validation (EV) certificates, but for individuals. I don't think they ever really took off (or even existed), and there isn'
78.
▲
by
jamieweb
6y ago
Some devices that claim not to have a browser do actually have a browser, as it is used solely for Wi-Fi captive portals. I seem to remember that the Nintendo Switch has one of these 'hidden' browsers.
79.
▲
by
jamieweb
6y ago
Is this because of habit or is there a particular attack scenario that you're trying to mitigate? If you're using a local password manager app such as KeePassXC, the password is almost a moot point as an attacker would need access
80.
▲
by
jamieweb
6y ago
The new web-based Outlook 365 is a lot better, but still quite buggy and massively lacking compared to Fastmail.
81.
▲
by
jamieweb
6y ago
It would also be interesting to analyse the domain name registrars and DNS hosting providers used. Based on my experience with the HN crowd, I'd predict that Gandi + Cloudflare would be a common one, with NameCheap closely behind.
82.
▲
by
jamieweb
6y ago
https://publiccode.eu/
83.
▲
by
jamieweb
6y ago
For 'consumer' registrars, it's probably because 95% of their customers are small non-tech businesses who just want a website and don't know what DNS is, etc. Nowadays, name server changes for well-maintained TLDs usuall
84.
▲
by
jamieweb
6y ago
This is exactly how it worked in Photo Booth on OS X over 10 years ago. It was good enough for short clips, but not reliable for long sessions. Random example clip: https://youtu.be/T5uqB1Kqukw
85.
▲
by
jamieweb
6y ago
Another +1 for Cutter from me, it's absolutely brilliant. $365 per year is still prohibitive for most hobbyist/home use. I was hoping it'd be $100 one-off, or $60 per major release + 2 years of updates, or something like that
86.
▲
by
jamieweb
6y ago
Why would you want a video feed anyway? If you're just having a talking meeting, I don't really need to see your face, and also don't want you to see mine. Edit: Maybe I'm antisocial, but I have talking meetings all of t
87.
▲
by
jamieweb
6y ago
For those interested, my own solution to this was to use AWStats with an anonymization script [1]. It provides high-level analytics such as unique visitors, referring sites and most viewed pages, without having to store any personal data su
88.
▲
by
jamieweb
7y ago
Would it be possible to support returning a larger excerpt of the article within a single TXT record? You should be able to get up to 64 KiB (minus a few bytes for headers, etc) within a TXT record. The lookup will have to use TCP though.
89.
▲
by
jamieweb
7y ago
I think what you're asking about is security threats such as RCE, information disclosure, etc, rather than threat vectors based on social engineering. Modern mobile phones do send/receive call data in a digital format (albeit over
90.
▲
Connecting to Decentralized Network 42
(jamieweb.net)
2 points
by
jamieweb
7y ago
|
0 comments
More ›