Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jamieweb
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
22 ms
·
181.
▲
by
jamieweb
8y ago
Thanks for the info - it sounds like you've got things locked down pretty well already. The key bit as you say is the fact that the emails are stored on a system that is not publicly accessible. My biggest worry with anything like this
182.
▲
by
jamieweb
8y ago
This looks really good, and I've been interested in setting up a system like this for my blog for a while. My main concern with anything these days is security. Do you have any further info on how you secure the email list that you sto
183.
▲
Ask HN: Do you like to see “Back to top” buttons on websites?
17 points
by
jamieweb
8y ago
|
32 comments
184.
▲
by
jamieweb
8y ago
Not sure how I missed out the "Ask HN", thanks for reminding me. Regarding the DNS, have you run into any issues with people using your DNS server for DoS amplification attacks? Also would you be able to share which DNS server sof
185.
▲
Ask HN: Is it feasible to run your own DNS name servers nowadays?
5 points
by
jamieweb
8y ago
|
8 comments
186.
▲
by
jamieweb
8y ago
This is a famous one from 1999 - "Why Johnny Can't Encrypt" [1] There's a couple of follow-ups too, such as "Why Johnny Still Can't Encrypt" [2], and "Why Johnny Still, Still Can't Encrypt"
187.
▲
by
jamieweb
8y ago
That's how it works - you can enable advanced protection without actually having the keys set up yet. It is then automatically disabled (along with 2FA) 14 days later if you don't register the keys within the timeframe. I agree th
188.
▲
by
jamieweb
8y ago
There is the <noscript> tag, but its usage seems extremely low. I'm half surprised that it made it into the HTML5 spec to be honest, similar ones such as <noframes> were left out.
189.
▲
Sec-Metadata
(chromestatus.com)
2 points
by
jamieweb
8y ago
|
0 comments
190.
▲
What's the deal with sites that require JavaScript to render any content at all?
8 points
by
jamieweb
8y ago
|
8 comments
191.
▲
by
jamieweb
8y ago
Good point actually, I might look into this and see.
192.
▲
by
jamieweb
8y ago
Sounds like a question for https://worldbuilding.stackexchange.com/
193.
▲
by
jamieweb
8y ago
I like those examples. Another downfall is when you want a more modern answer to a previously posted question. It will no doubt be marked as a duplicate, even though the original from 8 years ago doesn't have any answers useful in 2018
194.
▲
by
jamieweb
8y ago
Using www probably helps for the newer gTLDs, as the average non-technical user may not realise that something like ".productions" or ".hockey" is a valid domain. In the past I've heard of non-technical users adding
195.
▲
by
jamieweb
8y ago
I've been picking up the basics in the past few months - I started out with playing around with some open source tools (radare2/Cutter), and then watching Josh Stroschein's introductory course on PluralSight [1]. The course i
196.
▲
by
jamieweb
8y ago
Maybe! Windows seems to be activated just fine in the VM.
197.
▲
by
jamieweb
8y ago
In my case, the first time I fully booted the Windows 10 disk was in the VM. I wonder if this counted as a 'change' or does it think that the VM is the original hardware now?
198.
▲
Booting a physical Windows 10 disk on Linux using VirtualBox
(jamieweb.net)
25 points
by
jamieweb
8y ago
|
15 comments
199.
▲
by
jamieweb
8y ago
I've been finding the opposite - where they are too clickable... Depending on which Google version loads, sometimes the green URL displayed under the blue title is also clickable. You expect hyperlinks on the WWW to be blue and under
200.
▲
by
jamieweb
8y ago
I've seen similar emails in my DMARC rejected email reports. The unique thing about these ones is that they send it from your own address. I.e. they spoof your address so that it looks like your account really has been compromised. Lik
201.
▲
by
jamieweb
8y ago
I'm doing that at the moment - it's a good-enough solution for now. Is there a reason that the Trello philosophy is moving cards rather than ticking them off? Why not have both available?
202.
▲
by
jamieweb
8y ago
Right yeah that's what I was thinking. The problem is that the process of creating a HackerOne bounty program can take a short while to get to the stage where you can invite hackers - if you have an active hacker on the line like OP do
203.
▲
by
jamieweb
8y ago
Try to check the SPF and DKIM against Yahoo's to help determine whether the email is real or not. To answer your point though, it is unfortunately very common for organisations to use alternate domains for services you'd expect to
204.
▲
by
jamieweb
8y ago
In my experience, most of these are just low-level extortion attempts where they run a point-and-click vulnerability scan and ask for money to see the results. Before I had a bounty program I'd politely reply asking for information on
205.
▲
by
jamieweb
8y ago
Is it possible to give a bounty to a user on HackerOne even if you don't run a bounty program? I thought that the only way to pay them was if they submit a report to your own program. Obviously this is a problem is you don't have
206.
▲
by
jamieweb
8y ago
I looked at this originally, as well as GitHub's Project Boards and GitLab's Issue Boards. I was hoping for a solution in one of these to save having to have another service to use and maintain. The boards are not really designed
207.
▲
by
jamieweb
8y ago
Looks good - I think that their "Lightweight To-do's" feature is what I'm looking for. Thanks
208.
▲
by
jamieweb
8y ago
Thanks for the links - the Imgur image is exactly the sort of thing I'm looking for I think - ideally arranged in a board or columns layout like Trello. Is this feature implemented yet or just at PoC stage?
209.
▲
by
jamieweb
8y ago
This one looks nice, I'm having a look into it. Thanks
210.
▲
by
jamieweb
8y ago
Yeah that's the problem I'm having - I want to be able to see all of the checkboxes without having to drill down into the card.
More ›