Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jarrett
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
jarrett
12y ago
> When you type 'apt-get install opensshd', how do you know if you're getting the package from an uncompromised server? If you don't take any steps to verify the integrity, then you don't know. The big difference
32.
▲
by
jarrett
12y ago
> Packaged in a signed browser extension is a good start. Or packaged in a signed desktop app that runs JS to drive the UI (xulrunner, node-webkit, ...). Those are probably acceptable in principle. I should have been more specific: I was
33.
▲
by
jarrett
12y ago
> Is it like saying that a tank made of paper sheets is insecure Yes, I'd say it's more like that one. The technology is insecure against threat models it is almost certain to face. > or is it like saying that a heavily-armo
34.
▲
by
jarrett
12y ago
> so people can learn to use it properly. That's the part to which I'm objecting. As I asked above, what is the proper use of JS crypto? What real-world application do you have in mind where JS crypto's level of security i
35.
▲
by
jarrett
12y ago
> It still might protect you if you won't access server while it's compromised. The end user can't know when that's the case. > Also you might serve files that do the encryption from different server that's sm
36.
▲
by
jarrett
12y ago
It's not clear to me if the author is endorsing the use of browser crypto in any particular scenario. Regardless, probably the most common reason for wanting browser crypto is to protect the data before it hits the server, thus pro
37.
▲
by
jarrett
12y ago
I would love to hear from the founder of the service about this. I'd seriously consider paying for a high-quality lead-generation service. But if, as the above post asks, the same smallish pool of leads is being pursued by a bunch of f
38.
▲
by
jarrett
12y ago
Yes, that's what I was referring to. Instead of "money," perhaps I ought to have said "value." Analogously, if I had a pound of gold, and I gave it to a broker to sell for me, I'd be trusting that broker with m
39.
▲
by
jarrett
12y ago
I take that to mean cash in the sense of liquid assets, as opposed to something leveraged or what have you. Not cash in the sense of a briefcase full of cash.
40.
▲
by
jarrett
12y ago
If you were the US Marshals, would you entrust the government's money[1] to an unregulated Bitcoin exchange? [1] As to whether the government is morally, ethically, or legally entitled to the seized properties, I have no opinion. I don
41.
▲
by
jarrett
12y ago
I care if it runs a Unix-like operating system. As an engineer, my life is made so much easier when standard Unix stuff is available. And I'm rather miserable when I have to rewrite something to account for the absence of standard Unix
42.
▲
by
jarrett
12y ago
No, you shouldn't give up mutability or in-place algorithms. As you said, performance concerns demand them at times. Haskell has a nice approach to that problem. Data is immutable by default, but mutable primitives are available. The t
43.
▲
by
jarrett
12y ago
It appears we're each partially right: If you generated a new Rails app after August 2012, you get the header by default. If you generated the app before August 2012, you do not get the header by default. So PSA: Updating Rails in an
44.
▲
by
jarrett
12y ago
I'd prefer to try to riddle it out without resorting to cutting the bottle open. That would take all the fun out of it. If you had a reliable way to cut bottles and reassemble them with no telltale marks, then a single trick would expl
45.
▲
by
jarrett
12y ago
Clickjacking is especially scary because most web apps are probably vulnerable. The default httpd.conf that ships with most package managers doesn't include the X-Frame-Options header. (Perhaps it should.) Based on my testing, it appea
46.
▲
by
jarrett
12y ago
I'm pretty sure they didn't. My concern though is that OpenGL will fade away. OpenGL isn't exactly a product. There's no company that "writes" the OpenGL software. Rather, it's a specification published by
47.
▲
by
jarrett
12y ago
OpenGL 2.1 has VBOS and shaders. I've never used immediate mode with 2.1.
48.
▲
by
jarrett
12y ago
True, but as with advanced rendering techniques, not everyone wants to use off-the-shelf engines. In a simple application, there's something to be said for writing your own, simple graphics code.
49.
▲
by
jarrett
12y ago
I'm all for deprecating old OpenGL features. Old apps won't fail to run for a while yet. When they do, the community will no doubt create a compatibility layer like they did with DosBox.
50.
▲
by
jarrett
12y ago
Very happy indeed!
51.
▲
by
jarrett
12y ago
It's somewhat scary to see new graphics APIs being introduced. The fragmentation of OpenGL is enough of a headache, but at least it offers some semblance of "write once, run anywhere." The introduction of Mantle and Metal, pl
52.
▲
by
jarrett
12y ago
Even if the code is sandboxed, it's possible to run outgoing attacks from something like this. The same is of course true of traditional server rentals, EC2, and any other service that gives you an OS instance of your own. The differen
53.
▲
by
jarrett
12y ago
In addition to changing hosts, there are a few ways to dramatically increase the traffic a blog can handle: - Caching aggressively to static files. - Using a static site compiler. - An HTTP caching layer, like Varnish or CloudFlare. All of
54.
▲
by
jarrett
12y ago
There are legitimate concerns with unrestricted access to antibiotics. If you misuse them, you're possibly not just hurting yourself. You might be hurting everyone, because you might be breeding resistance bacteria.
55.
▲
by
jarrett
12y ago
If each user created their own key for a .ngrok.com subdomain, could ngrok then sign those, rather than giving out the private key? Would user agents consider the subdomain's signed cert sufficient in that case? This is an odd little c
56.
▲
by
jarrett
12y ago
Yeah, I'm just thinking one could relax that policy--if there were actually a viable strategy for flagging sites, which there may not be. Unless you're tunneling SSL, you can't know that ngrok doesn't inspect your traf
57.
▲
by
jarrett
12y ago
I wonder if it would be possible to automatically flag ngrok sites for manual review based on certain criteria. E.g. if the phrase "citibank" appeared on the site, it would appear in a moderation queue. Though there may be bulletp
58.
▲
by
jarrett
12y ago
You've convinced me. This seems true for all companies.
59.
▲
by
jarrett
12y ago
On the flip side: Is there ever a situation in which cofounders legitimately want to make it impossible to oust a cofounder without his/her consent? Or should that always be possible for any sane company?
60.
▲
by
jarrett
12y ago
What definition of mental illness do you use for serious mental illness? Substance abuse is formally classified as a mental illness in the DSM.
More ›