Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
just2n
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
18 ms
·
121.
▲
by
just2n
13y ago
Isn't a schemaless database just a filesystem?
122.
▲
by
just2n
13y ago
I'd think it's also an issue of the 4th. Consider sharing a machine with different user accounts. Asking me to decrypt a drive just might be an unreasonable search, because outside of logical partitioning, there's no concept
123.
▲
by
just2n
13y ago
It does add something: users can use any password they want. Any unicode string. You just UTF-8 encode then locally hash into a constant size. This alleviates the issue mentioned in the grandparent that supporting arbitrary length passwords
124.
▲
by
just2n
13y ago
It doesn't remove any security, either. If you perform a hash on the server that sends an arbitrary input size to a fixed number of bits, the attacker needs only to try O(2^n) different inputs where n is the number of bits of that hash
125.
▲
by
just2n
13y ago
I built an extension to use PBKDF2 and some other cleverness to generate predictable passwords for websites because I was tired of needing "random" passwords for every site and some kind of password keeper that stored them. I'
126.
▲
by
just2n
13y ago
You could really support an arbitrary password size by locally hashing the password to a length at least as long as the one you store in the database to preserve entropy, then send the fixed length hash as the user's "password&quo
127.
▲
by
just2n
13y ago
I have to say that this article is actually quite terrible, as is the opinion that any option that might ever be confusing to a user is an option that shouldn't ship with the product. The thesis of the article is: "Well, we have m
128.
▲
by
just2n
13y ago
I did this for a long time, but it's really annoying: 1. If your provider goes down, you lose mail. 2. If you are conversing with people who are using an insecure mailer, such as gmail, Yahoo, etc (which is probably > 99.9% of all e
129.
▲
by
just2n
13y ago
Well of course it was initially passed by Congress. However, because of the nature of the checks and balances between parts of our government, all 3 are equally guilty here since the Executive has enforced the law, and the Judicial since it
130.
▲
by
just2n
13y ago
I have a few thoughts after reading this article: 1. This (re: citizens violating classified laws or legal interpretations) is definitely a situation where any sane judge/jury would find against the ignorantia juris non excusat princip
131.
▲
by
just2n
13y ago
Have you tried spending some time learning how it works and reading through the manpages? In my experience, as long as you hold onto the cognition that a repository is a collection of files and commits are, in effect, diffs, git won't
132.
▲
by
just2n
13y ago
Additionally, jQuery is not known for its performance, especially regarding animations. For me, on Chrome Canary, the animation "chugs" every 20-30 frames (from 60 fps to a frame that takes 200ms). It's almost entirely in ren
133.
▲
by
just2n
13y ago
English, specifically whatever dialect that is, is a horrible medium for encoding laws. Further, the diffing format used there is atrocious. Law is code. Why haven't we fixed this yet?
134.
▲
by
just2n
13y ago
From "it's only to catch terrorists, guys" to potentially "it's also used to prove guilt in minor domestic cases." I, for one, hope this succeeds. Maybe then we'll have a way to get the masses to understan
135.
▲
by
just2n
13y ago
The tokens would be signed with an expiration, so if they backed up to a time when they had a valid "access" token, the verification would fail (assuming the device has an internal chronometer that the user can't modify). If
136.
▲
by
just2n
13y ago
Not really, I just didn't include obvious details for brevity. Of course you verify cryptographically that the transferring console has received the disable notification and has marked the game as disabled before continuing the process
137.
▲
by
just2n
13y ago
What a terrible article. First, the analogy is completely wrong. Second, Microsoft is realizing people are getting seriously tired of the bullshit "always on" concept. It's hard to justify and is widely rejected as a valid te
138.
▲
by
just2n
13y ago
Acknowledgement of the leak demonstrates knowledge that the US government is actively violating the constitutional rights of citizens. Assuming it is the most "just system" in the world where one is "guaranteed the right to a
139.
▲
by
just2n
13y ago
I still see that as dissonance. On the one hand, they believe in the US, in our rights, in the freedom of speech, and in the need for us to blow whistles on government actions that violate those rights. But on the other hand, someone who se
140.
▲
by
just2n
13y ago
Polls that touch a wide audience should be taken with a grain of salt. When you ask someone who doesn't really know what's going on "do you care?" their response doesn't mean much. This is true of just about everyth
141.
▲
by
just2n
13y ago
Yes. And on their website they have pop-ups to nag you to do it constantly.
142.
▲
by
just2n
13y ago
What if someone steals a copy of my file, then uploads it to TPB? Now do I get sued for millions? Am I presumed guilty, since it's clear there's "evidence" to show that I was the source of the now widely spread copy? Do
143.
▲
by
just2n
13y ago
The secrecy of the information FOIA is supposed to help alleviate (it doesn't really because it's a catch-22) bothers me a lot. If the government is amassing information on individuals to prove guilt of some crime, by withholding
144.
▲
by
just2n
13y ago
Potentially. So we agree there's nothing hip about Disney.com? I was trying to provide a counter example to the general thesis of the article. The reason it really doesn't hold at all, in general, is because many websites (and par
145.
▲
by
just2n
13y ago
I think this is a bit misleading. We're drawing the conclusion from age based metrics that if a lot of young people use a service, relative to older adults, it must be "hip" or "new." Consider Disney.com. Nothing ne
146.
▲
by
just2n
13y ago
Not quite. Having someone's private SSL key doesn't necessarily let you read the contents of their SSL traffic due to forward secrecy. It does let you sign messages as if you were them, or MITM their traffic. http://en.
147.
▲
by
just2n
13y ago
> Then your answer should have been "no". Remember, the very first example is a paragraph, and it asks you if it makes a request for an image, I don't see you getting into the same rage about that. There's a fairly hu
148.
▲
by
just2n
13y ago
The question makes no sense, in that case. The verbatim question is: > Does the above trigger a request for the current page (a reload without user interaction) in any of the following: The "without user interaction" as present
149.
▲
by
just2n
13y ago
Resize the window.
150.
▲
by
just2n
13y ago
I really like the presentation of the problems. I hope this is developed much further. It could, however, benefit a lot by having separate quizzes at different levels, and moving the edge-cases and browser-specific questions into their own
More ›