Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jusob
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
jusob
7y ago
The project started as a 64-bit version for Windows (was supposed to be faster). Then, when Firefox changed the add-on framework, it became the "Firefox" version you can use to keep all your old add-ons working. They are merging a
32.
▲
by
jusob
7y ago
Same project. It kept the old extension API from Firefox, this is why I use it.
33.
▲
by
jusob
7y ago
"Five Asian Countries Dump More Plastic Into Oceans Than Anyone Else Combined" [1] We should help these countries first to recycle and reduce their plastic usage if we want to make a real difference. [1] https://www.for
34.
▲
by
jusob
8y ago
I use both Paypal and Stripe on my website. I've had companies using Paypal to pay $1,000 a couple of times. Both work fine for me. But dispute resolutions are random with Paypal (never had any with Stripe). I just had a few on Paypal:
35.
▲
by
jusob
8y ago
On your server, send "X-Content-Type: nosniff" and make sure the right Content-Type is returned by the server. This will prevent browsers to load an image file (Content-Type: image/png) as anything else than an image.
36.
▲
by
jusob
8y ago
> use CSP's disown-opener to fix this globally Except no browser supports it yet (see table at https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP )
37.
▲
by
jusob
8y ago
There are plenty of unfilled positions in security. Typically, a large SaaS company will have have several security teams: application (Product Security), Infrastructure Security, Network Security, Device security (company laptops, phone, e
38.
▲
by
jusob
8y ago
In 2017 or 2016, there was a Blackhat talks that explained how to trick the web cache on main popular website (including Paypal) into caching any web page. The trick is that many web cache just do a check on the extension (.jpg, .png) to c
39.
▲
by
jusob
9y ago
Interesting, this is what the Referrer-Policy header is supposed to do, site by site. It make sense to enable it private browsing mode, though... and then you'll see how many sites break because they use the Referrer as some kind of au
40.
▲
by
jusob
9y ago
Good starting point, but these headers won't protect your site from data breaches (just a bit with not caching confidential information).
41.
▲
by
jusob
9y ago
if you want to outsource, WordPress is the best choice. Make sure you use different domains for WordPress and your app. Sucuri (recently bought) provided a good managed WAF & security monitor for WordPress.
42.
▲
by
jusob
10y ago
But you see the Host header after the TLS handshake, after the certificate was sent. The poitn of SNI is to indicate the host header during the TLS handshake so that you get the right certificate. HTTP with the host header is one layer up.
43.
▲
by
jusob
10y ago
If this is an explicit proxy, this is true. But with a transparent proxy, SNI would still be needed to know what domain name is going to be requested.
44.
▲
by
jusob
10y ago
It does not have to be. Done correctly, SSL interception can pass through all the errors to the client: * certificate issues (expiration, domain mismatch, etc.) * OCSP/CRL verification * validation of HPKP header I understand that few
45.
▲
by
jusob
10y ago
I have tried https://dexi.io/ (free account) about a year ago and it looks very good. One downside is that it was issuing requests from Europe by default, so you had to bring your own proxy for the US, for example.
46.
▲
by
jusob
10y ago
I spent a year in US as a foreign student. From my previous experiences (internships in UK and Germany), I knew it would be difficult to make friends with "locals". In UK, I was in a dorm during the summer with a private room, sha
47.
▲
by
jusob
10y ago
It is part of the RFC: if a certificate is signed by a root certificate that is trusted in your private store (meaning it was added later on), HPKP is ignored. Unfortunately, this is required in the enterprise world where corporate MiTM is
48.
▲
by
jusob
10y ago
I've just looked at it. The concept seem to be the same. SeaweedFS is much simpler. You have only 2 services: master and volume, both speak HTTP only. MogileFS seems to offer more control and more tools (rebalancing, for example).
49.
▲
by
jusob
10y ago
You can (should) have multiple masters. But each volume has a primary master. I did see other masters loose the volume state information after the primary master has gone down and been taken out of the cluster.
50.
▲
by
jusob
10y ago
I use it to store many small files (JSON and images). My requirements were: 1. predictable read time 2. read/write access through LAN 3. server easily installable on VPS 4. simple API The main downsides I found so far: 1. Master splitt
51.
▲
by
jusob
10y ago
You are correct, it is not really a file system. It is used with the HTTP API (upload, download, etc.).
52.
▲
by
jusob
10y ago
I've been using SeaweedFS (previously WeedFS) in production for a couple of years. I needed to share files on a LAN, including small VPS, so distributed file systems(like GlusterFS) that require a kernel module did not work for me. I s
53.
▲
by
jusob
10y ago
2 minutes to apply. Approval is manual, so it depends on the day and time and the availability of the Google employee. Less than 48 hours for me.
54.
▲
by
jusob
10y ago
No, you need to get the keys from your browser: "It turns out that Firefox and Chrome both support logging the symmetric session key used to encrypt TLS traffic to a file."
55.
▲
by
jusob
10y ago
I have a very small SaaS and I was approved. I don't send hundred of e-mail to other e-mail addresses daily, but I do send a lot of e-mails to myself (server alerts and notifications). Approval process is very easy and takes 2 minutes,
56.
▲
by
jusob
10y ago
From my research, if a LLC has a single person behind it, the protection offered is lower. "In many cases, the court will agree and the single member becomes personally liable for the business debts." ( http://markjkohle
57.
▲
by
jusob
10y ago
Browshot ( https://browshot.com/ ), a screenshot service.
58.
▲
by
jusob
10y ago
Most of the CSP directives can be included as a meta tag, not necessary a HTTP header. Also, CSP is not dedicated to XSS protection. Some directives, like frame-ancestor and the referrer policy are much easier to manage. But it is hard to p
59.
▲
by
jusob
10y ago
I disagree with the premise of the first paragraph. In the US, we had to buy large books for all classes. At best, we studied 10% of the content. In France, all teachers create their own "book" containing the material we actually
60.
▲
by
jusob
10y ago
CSP is not supported by IE, unfortuantely. But you an do 2 things around HTTPS: * set up a report-only policy saying taht all assets must be loaded over HTTPS. You can receive a report when this is not the case. * use upgrade-insecure-reque
More ›