Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
johnsoft
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
121.
▲
by
johnsoft
14y ago
Cheating probably isn't a crime, but I would imagine unauthorized access to someone else's network probably is. (I am not a lawyer, no less an Australian lawyer)
122.
▲
by
johnsoft
14y ago
I peeked at the code behind s2png, and this doesn't do what you might think from the title. It just copies the data byte-for-byte into the pixels of a PNG image, and when you want the original file back, you need to use the same utility to
123.
▲
by
johnsoft
14y ago
I vaguely recall seeing a mailing list thread where `{-}` was proposed. I think it was rejected based on parsing ambiguity, i.e. `{-1}` vs `{-}`. (Or it's possible I might be losing my memory)
124.
▲
by
johnsoft
14y ago
>Vendor stores database IDs in cookies which are easily spoofed (USERID_COOKIE), allowing all user information to be accessed. If this means what I think it means, why did it take until 2013 for this to be discovered?
125.
▲
by
johnsoft
14y ago
Here's a link to the "Experiment No. 11" he mentioned: http://www.raptitude.com/experiment-log-no-11-an-attack-on-p...
126.
▲
by
johnsoft
14y ago
Clients emit a warning in the GUI (and IIRC disable the RPC interface, which would be the fail-safe for merchants) when this kind of issue is detected (namely, conflicting blockchains of significant length received from different peers). So
127.
▲
by
johnsoft
14y ago
They didn't catch this because it wasn't a bug in the client code itself, rather it was a bug in a third-party library, which is currently being migrated away from. Further (as far as I'm aware) it's only happened by chance, never deliberat
128.
▲
by
johnsoft
14y ago
vin = the source of coins that are being spent, plus some auxiliary data. The source consists of a (txid, vout) pair, where vout is an output index. If the client comes across an identical pair as a source in multiple transactions, all but
129.
▲
by
johnsoft
14y ago
There are services out there that will absorb transaction risks for you. One example is https://bitpay.com/
130.
▲
by
johnsoft
14y ago
You would need to find a very localized, specific class of bug in a piece of software that has been highly scrutinized over many years by cryptography and security experts who know there are millions of dollars at stake, and this bug would
131.
▲
by
johnsoft
14y ago
Sadly, I have to agree with you. I have a fair amount of money in bitcoin right now, but if I didn't understand the ins and outs of the protocol and like debugging, I can think of a few incidents which would have caused me to lose money (or
132.
▲
by
johnsoft
14y ago
This was only possible because of an obscure bug in a database library used by the reference client, which the developers are in the process of migrating away from. The latest 0.8-beta release inadvertently caused a size restriction on some
133.
▲
by
johnsoft
14y ago
assertTrue() recently did a series on this. If you're interested in this kind of thing, it's worth a read. Here's one of the posts (ignore the linkbait headline) - http://asserttrue.blogspot.com/2013/03/how-to-live-30-longer...
134.
▲
by
johnsoft
14y ago
I had the same experience. I tried learning Haskell twice and failed miserably both times. I think my brain pieced things together subconsciously after those two attempts though, because the third time I sat down with it, it almost seemed t
135.
▲
by
johnsoft
14y ago
I wouldn't call it laziness. Network setup is something most people just pay their ISP to take care of. It's a commodity service. They don't care how the bits get from here to there, they just want to check their email and go on Facebook. H
136.
▲
by
johnsoft
14y ago
By robust, I mean the language/compiler has a strong test suite and the runtime is known to work reliably in production settings. I've heard horror stories about Sun's HotSpot JIT crashing frequently, but that was what, 10 or 20 years ago?
137.
▲
by
johnsoft
14y ago
Are there any widely-used languages that aren't robust? That seems like kind of shallow praise.
138.
▲
by
johnsoft
14y ago
How would you go about hosting a Tor node, without exposing yourself to problems like this? http://raided4tor.cryto.net/ I've thought about running an exit node, but I'm not willing to sacrifice my own safety and freedom to do it. The onl