Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kro
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
31.
▲
by
kro
6mo ago
Nginx mainline 1.29.x supports it. So once you get that and also the openssl version on your system, good to go. Likely too late for ubuntu 26.04, maybe in debian 14 next year, or of course rolling release distros / containers. But, in
32.
▲
by
kro
6mo ago
The URL does not even need to change, you can pushState with just a JavaScript object, catch the pop and do something like display a modal. (I use this pattern to allow closing fullscreen filter overlays the user opened) Still, requires use
33.
▲
by
kro
6mo ago
It's a valid question how they detect it. As there are valid usages, just checking for the existence of the function call would not be correct. These sites likely pushState on consent actions so it appears like any user interaction.
34.
▲
by
kro
6mo ago
It's very very unlikely to get collisions there, but still not impossible. Whenever you map data of arbitrary length (infinite possibilities) to a limited length collisions are possible.
35.
▲
by
kro
6mo ago
I wonder, what is the impact of this to widely deployed smartcards like credit cards / EID passports? Aren't they relying on asymmetrical signing aswell?
36.
▲
by
kro
6mo ago
The argument to skip hybrid keys sounds dangerous to me. These algorithms are not widely deployed and thus real world tested at all. If there is a simple flaw, suddenly any cheap crawler pwns you while you tried to protect against state ac
37.
▲
by
kro
6mo ago
It will likely display something like a QR Code with signature anyways, otherwise it's just a glorified passport picture? Authorities/anyone could verify that it's not counterfeit. And photo should be checked anyways to match
38.
▲
by
kro
6mo ago
I really don't get this either, I've always removed axios when it was preinstalled in a framework. I use "xhr" via fetch extensively, it can do everything in day to day business for years with minimal boilerplate. (The o
39.
▲
by
kro
6mo ago
In Q2 this year, so very soon, there will be the DNS PERSIST method, which is non rotating.
40.
▲
by
kro
7mo ago
Not advocating for cashless only, but cash also has costs: banks charge for deposits and coinrolls, and you need to protect against robbery
41.
▲
by
kro
7mo ago
Almost certainly it does, as public key auth takes place after setting up the session encryption
42.
▲
by
kro
7mo ago
I have a setup with separated dns and domain since 2021. Using a CSK with unlimited lifetime, I never had to rotate. And could easily also migrate both parts (having a copy of the key material) Register only has public material The master i
43.
▲
by
kro
7mo ago
TPM is good when combined with secureboot and these hashes being part of the attestation, that eliminates initramfs swapping. Still with Physical access being a factor bustapping can happen, ftpm - if available - is much harder to crack th
44.
▲
by
kro
7mo ago
TPM definitely rises the effort by a lot to break it. But by default the communication with it is not encrypted, so especially for modules not built into the cpu wire/bus-tapping is a thing. https://news.ycombinator.com/
45.
▲
by
kro
7mo ago
Good FAQ, clearly stating the weak point of physical access. For a server that threatmodel can work, for a fleet of edge/iot devices in unsecured locations without permanent uptime there is no real solution to be expected without custo
46.
▲
by
kro
7mo ago
In general I'm all for free and European systems, but SEPA payments imo still have pain points: - you can send money to companies and individuals alike. It's easier to trick people into fake shop payments, a card payment provider
47.
▲
by
kro
7mo ago
The title is vague, my first thought was "We already have MLKEM". Which is enough against passive attackers. The article apparently is about the CA/certs for authenticating the server, a part of HTTPS
48.
▲
by
kro
8mo ago
+1, Even if they validate DKIM/SPF+alignment (aka DMARC) that would only verify the domain. There is no local part verification possible for the receiver, the sending server needs to be trusted with proper auth
49.
▲
by
kro
10mo ago
Agree, Google made it really easy here, compared to using service account certificates like with some of their other APIs.
50.
▲
by
kro
11mo ago
A German ISP also has an IP6 issue and confirmed it over the phone but is not fixing it. It persists for years and can be observed on multiple households I checked. Most don't notice it, as refreshing the address or happyeyeballs wor
51.
▲
by
kro
11mo ago
It's seriously infuriating receiving these "Critical vulnerability reports" customers let other agencies do, and having to justify why you have no Referer-Policy header. Nice to read that you are reasonable. Also, they want a
52.
▲
by
kro
11mo ago
Some people also do run Tor exit nodes on their ISP connections, of course receiving tons of abuse complaints, but apparently it's legal enough.
53.
▲
by
kro
11mo ago
I installed them Mint and they said it's better than Windows due to all the built-in free apps (like public TV)
54.
▲
by
kro
11mo ago
Afaik wasm cannot open network sockets. The segfault is unfortunate though
55.
▲
by
kro
1y ago
They allow netbooting to a recovery OS from which the disks can be provisioned via an ssh session too, for custom setups. Likely there are cases that require the remote "keyboard", but I wanted to mention that.
56.
▲
by
kro
1y ago
True, a huge number of games work great with those. Games requiring anti-cheat however are a big issue that still require a dual boot Windows or VM.
57.
▲
by
kro
1y ago
Likely also the in-built Firefox privacy blocking.
58.
▲
by
kro
1y ago
They are in fact public/private keys and use signing a challenge for authentication.
59.
▲
by
kro
1y ago
What is there to fallback to I wonder - 3rd party cookies should be deprecated/blocked by now, so how can the gsi script retrieve google session information?
60.
▲
by
kro
1y ago
Apps can bypass websecurity (CORS fetch), that allows for third party clients for example on video platforms using their internal APIs. I don't think the reddit clients work this way though.
More ›