Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
leftcenterright
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
91.
▲
by
leftcenterright
3y ago
> reliable operations and support is something I trust them more than most others With a poor security track record [0], miserable support for office 365 products and lack of transparency on issues in general, I doubt this is something t
92.
▲
Cyprus confidential: Top German journalist received €600000 from Putin ally
(theguardian.com)
10 points
by
leftcenterright
3y ago
|
2 comments
93.
▲
by
leftcenterright
3y ago
Most likely this is being abused for SMS pumping fraud where rogue network providers/small providers complicit in fraud use the traffic to generate revenue. - https://support.twilio.com/hc/en-us/articles/
94.
▲
Extend GitHub's CNA scope to manage CVEs for projects on GitHub
(github.com)
1 points
by
leftcenterright
3y ago
|
0 comments
95.
▲
Grafana repository private signing key and passphrase leaked
(grafana.com)
6 points
by
leftcenterright
3y ago
|
2 comments
96.
▲
by
leftcenterright
3y ago
On Aug. 24, the GPG private key and passphrase with the ID of 0E22EB88E39E12277A7760AE9E439B102CF3C0C6 was unintentionally shared. As a best practice, we have revoked the exposed certificate on our full GPG public keychain and issued a new
97.
▲
by
leftcenterright
3y ago
I worked at a small company with about 50 employees where self-organizing teams was the norm in tech departments. It was comprised of mostly senior developers and researchers though so they mostly were able to avoid rabbit-holes themselves
98.
▲
by
leftcenterright
3y ago
> I'm afraid that would be me. I think a lot of us are that, personally speaking: honest sincere analyses and investing time into critical analysis almost always will bring out more than what we hear in a talk. It does take a big am
99.
▲
by
leftcenterright
3y ago
I believe at least part of the reason for calling Harari pseudo-intellectual is the use of misleading statements in favor of storytelling in the books and also building up on others' work with better storytelling. More on this: https:
100.
▲
by
leftcenterright
4y ago
It is not hard to understand, I am all for it. Please see my response here: https://news.ycombinator.com/item?id=35392323 I think for career advancement, getting paid more is not the only motivation for a lot of world class
101.
▲
by
leftcenterright
4y ago
I think it boiled down mostly to fear of being compromised by the CIA/NSA vs fear of being compromised by a mildly competent attacker while using an insecure "Made in EU" provider. Practically speaking: the first one winning
102.
▲
by
leftcenterright
4y ago
A risk assessment and threat analysis typically requires a definition of who the adversary is and what the risk of using any service is in regard to that adversary. Reasons I heard for a lot of companies to not use GCP/AWS/Github
103.
▲
by
leftcenterright
4y ago
This does not surprise me at all. I worked in Italy for 2 years and in Germany for 4 years. A sense of `US/CIA/NSA-phobia` is strong among many companies and is often used to justify not using US datacenters, cloud-services and Sa
104.
▲
by
leftcenterright
4y ago
Congrats to the team! Could you give an idea about the tech stack powering citymapper?
105.
▲
by
leftcenterright
4y ago
Related discussion: > Peter Thiel’s fund wound down 8-year Bitcoin bet before market crash: https://news.ycombinator.com/item?id=34444980
106.
▲
by
leftcenterright
4y ago
Can you please share possible salary ranges?
107.
▲
by
leftcenterright
4y ago
My comment was in response to "Google just doesn't do this with OSS projects." Also the source code link I provided was to vanilla Android, not to a commercial version running on someone's phone.
108.
▲
by
leftcenterright
4y ago
Genuine question: How did android turn out to be such a privacy nightmare while still being an open-source project? "I am sure it will be phoning home about all sorts of things." is 100% true in case of Android.
109.
▲
by
leftcenterright
4y ago
> Google just doesn't do this with OSS projects. So, android being an open source project, how does one turn off these nefarious repeated connectivity checks (phoning home)? Or how does one modify `/etc/hosts` like we do o
110.
▲
by
leftcenterright
4y ago
Thanks for the suggestion, that does look like an interesting read! I will check it out.
111.
▲
by
leftcenterright
4y ago
Visual thinking! [1] I had read a bit about different types of thinking but I didn't really understand it so well until I saw a kid who had amazing visual thinking capability and could visualize years' old memories in a very detai
112.
▲
by
leftcenterright
4y ago
Magnitue of strain and sustained concentration are really good points! Totally agreed on that. I would however expect similar fundamental brain functions to be at play. For debugging and instinct driven tasks, I would co-relate that with hi
113.
▲
by
leftcenterright
4y ago
Are programmers any different from mathematicians or physicists in this aspect of using brain functions? It takes similar logical skills like: - Not knowing end result/solution of an equation - Performing multiple operations to solve d
114.
▲
by
leftcenterright
4y ago
I said "mobile apps" to exclude browsers which do similar validation anyways. And it is the same process for mobile apps, only apps designed in an insecure manner (to choose to ignore cert warnings, use custom TLS clients etc) wou
115.
▲
by
leftcenterright
4y ago
What does it have to do with app store? Insecure apps which might not respect server TLS certificates / settings or communicate over plain HTTP will be insecure to use over a VPN as well. A VPN is not an alternative to not using proper
116.
▲
by
leftcenterright
4y ago
TLS validation is enforced in all mobile applications unless you have spyware/malware which would use insecure CAs or self-signed certificates. Please see my comment above https://news.ycombinator.com/item?id=34159195
117.
▲
by
leftcenterright
4y ago
While public Wifi providers may try to MITM, TLS effectively prevents that from happening unless you are prone to accept "insecure certificate/connection" warnings. Leaked keys or keys obtained/accessible by law enforc
118.
▲
by
leftcenterright
4y ago
I guess the point is about MiTM which you have not really answered, MiTM requires the man in the middle to present a webpage / api to the user over https with a valid certificate so that the browser or the android app would make conn
119.
▲
by
leftcenterright
4y ago
> Don't connect to random public WiFi. If you do, don't login to any online account on it, or send confidential information. While this is good advice in general, I have seen that people do end up having to connect to public Wi
120.
▲
by
leftcenterright
4y ago
- Use 2fa everywhere - Showed them how to use ublock origin, they love it - If you have to enter your PII and the site/service doesn't really need it, try to not give them correct information (fictitious date-of-births for examp
More ›