Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jf
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
jf
2y ago
If they have a Google or Apple account on their Android or iOS device, then nothing happens.
62.
▲
by
jf
2y ago
Except in this case, the smart card generates a new key _per domain name_
63.
▲
by
jf
2y ago
An alternative viewpoint to consider is how much pain and suffering passwords cause large companies or identity providers. One example: Large organizations often spend $1m/yr on password resets alone.
64.
▲
by
jf
2y ago
Does PAKE protect against scenarios like "password written on sticky note", "fake login page hosted at login.nnicrosoft.com", or "scammer impersonating IT staff"?
65.
▲
by
jf
2y ago
I presume that you are familiar with it already, but in the off chance that you are not. Check out the Recurse Center
66.
▲
by
jf
2y ago
Not any more than you need to in any public forum
67.
▲
by
jf
2y ago
I beg to differ. A Deepness In The Sky is the best sci-fi book ever.
68.
▲
Curl -v HTTPS://Google.com
(youtube.com)
23 points
by
jf
2y ago
|
2 comments
69.
▲
by
jf
2y ago
I've long wanted to have a way to see what actually happens inside a CPU when a set of instructions are executed. I'm pretty excited after skimming this paper as it looks like they developed a technique to automatically determine
70.
▲
by
jf
2y ago
A Smalltalk VM: https://github.com/Zag-Research/Zag-Smalltalk
71.
▲
by
jf
2y ago
WebAuthn and related variants
72.
▲
by
jf
2y ago
Why choose between PHP and JavaScript when you can write code in CASSIS, a language that runs in the syntactical intersection of both languages? For example: if (js()) { /* javascript */ } else { /* PHP */
73.
▲
by
jf
2y ago
I'm not sure if there's a source online as I learned about it from Otavio directly. The slightly longer story, as I recall it, is that their team basically built a "game" to help humans unshred documents, and was using t
74.
▲
by
jf
2y ago
Yes. Though not in the traditional way that we think of "pipe" working. A good example of this was the "zoom lens" in Omar Rizwan's Geokit: https://omar.website/posts/notes-from-dynamicland-geok
75.
▲
by
jf
2y ago
> You can't take a Cat from one program and a Dog from another program and have the dog interact with the cat. This is obvious in software - that's why we design APIs - but it's frustrating when all your programs exist in
76.
▲
by
jf
2y ago
Woah! I never considered that until now. I'll bet you're right.
77.
▲
by
jf
2y ago
Ah, noted! With that in mind, did you know that those printer dots are what the team that won the 2011 DARPA Shredder Challenge used to win? https://en.wikipedia.org/wiki/DARPA_Shredder_Challenge_2011 Fun fact: Otavio
78.
▲
by
jf
2y ago
Correct, that doesn't work in the system as implemented. But my understanding is that there has been a goal from the start to _eventually_ get physical code editing to work. I recall hearing the researchers talking about wanting to eve
79.
▲
by
jf
2y ago
I'm pretty sure that I mentioned the printer tracking dots to the researchers at the lab and certainly mentioned DataGlyphs. So they were aware of alternatives. The trick is to get a workable system with cameras that have the resolutio
80.
▲
by
jf
2y ago
If you’re in the SF Bay Area and like secondhand stores, you owe it to yourself to visit Urban Ore. It’s a secondhand store with a focus on building material. Things to check out include: - a section for doors, if you want it, they have it
81.
▲
Lego Modular Streetscaper
(modularstreet.net)
2 points
by
jf
2y ago
|
0 comments
82.
▲
by
jf
2y ago
The main issue that I have with XmlDSig is that the signatures are stored inside of the document being signed. Because of that, you can’t properly implement the standard without writing enough of an XML parser to do the canonicalization nee
83.
▲
by
jf
2y ago
Remember to make sure your XML parser doesn’t fetch remote DTDs. You’ll also want to make sure that the code which validates the signatures in the SAML assertion reports to you which specific parts were signed. You will also want to validat
84.
▲
Fun with SAML SSO Vulnerabilities and Footguns (2020)
(workos.com)
2 points
by
jf
2y ago
|
0 comments
85.
▲
by
jf
2y ago
As someone with a decade of hands-on SAML experience, I highly recommend against implementing SAML. Use OIDC instead. This article covers many of the reasons to avoid SAML: https://workos.com/blog/fun-with-saml-sso-vuln
86.
▲
by
jf
2y ago
It’s hard enough to debug SAML as it is, I can’t imagine debugging artifact binding without having full control of both the SP and IdP.
87.
▲
by
jf
2y ago
The idea that Texans don't like government regulations isn't really backed by evidence. For example, the Cato Institute ranks Texas #17 in terms of overall freedom versus nearby states like Arizona which ranks #4 and Nevada which
88.
▲
by
jf
2y ago
You are 100% correct... SAML is one case where ignorance truly is bliss.
89.
▲
by
jf
2y ago
I regret learning nearly everything that I know about SAML.
90.
▲
by
jf
2y ago
Try implementing XMLDsig yourself and you'll quickly learn how awful it is. Aside from the other comments mentioned in these replies, one of the horrible things about XMLDsig is that it requires you to mutate ("canonicalize")
More ›