Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
lonestar
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
31.
▲
by
lonestar
17y ago
He said he put his ego aside in regards to redesigning his webapp to appeal to a wider audience, rather than what he wanted. It doesn't seem terribly egotistical to want to correct people who are spreading an inaccurate representation of hi
32.
▲
by
lonestar
17y ago
These interview questions were about Ruby, not Rails. If you are hiring for a position where the developer will work primarily with Ruby, it makes sense to ask Ruby-specific questions or have a Ruby coding exercise. That shouldn't be the wh
33.
▲
by
lonestar
17y ago
If you're not a Ruby/Rails dev, it doesn't seem reasonable to expect that all the framework's errors will make sense to you. If you took the time to learn how requests are routed in an MVC framework, this particular error would probably mak
34.
▲
by
lonestar
17y ago
The problem with this system is in the sorting. The list of "Highest Rated" teas is dominated by results where 1 person rated the tea 100. Steepster should use a Bayesian average ( http://en.wikipedia.org/wiki/Bayesian_average ) so that the
35.
▲
by
lonestar
17y ago
I don't understand your point about chaining and evaluation order. The example in the article is straightforward method chaining. Can you explain what you mean?
36.
▲
by
lonestar
17y ago
By the same legal argument, couldn't anyone buy one of AggData's datasets and then publish it for free on the internet?
37.
▲
by
lonestar
17y ago
Really? This is just a standard printf-style format string, something which all programmers should be familiar with. Even the '%' syntax isn't unique to Ruby; Python uses it as well IIRC.
38.
▲
by
lonestar
17y ago
Voight-Kampff, presumably. http://en.wikipedia.org/wiki/Voight-Kampff_machine
39.
▲
by
lonestar
17y ago
To anyone with any level of web security experience, the real fix for this (proper escaping) should be obvious. For every really trivial vulnerability like this that Twitter can't fix, there must be scores of slightly more subtle vulns that
40.
▲
by
lonestar
17y ago
As you just noted, the account is still anonymous, so there doesn't seem to be a point in requiring it.
41.
▲
by
lonestar
17y ago
http://en.wikipedia.org/wiki/Coin_flipping See the section "Coin flipping in telecommunications" for a cryptographic scheme for verifiable coin flipping across the internet. This is a specific example from the category of commitment schem
42.
▲
by
lonestar
17y ago
From main.php: $keyLength = 256; I'm assuming most people who would choose to use this library will just copy his example code and use 256 bit keys, which are very easy to factor.
43.
▲
by
lonestar
17y ago
I don't see how showing each letter individually is more secure than showing the whole password in the clear. Anyone looking at your screen is still going to see every character in your password. The only reason this approach makes sense on
44.
▲
by
lonestar
17y ago
I'm not sure you understand how poker works. It is not negative expectation gambling like all casino games. A skillful player has a positive expectation over time, and will be profitable. You're playing against other people, not against the
45.
▲
by
lonestar
18y ago
Ran a quick test, and it looks like Twitter has already enabled frame-busting on the status submit page.
46.
▲
by
lonestar
18y ago
Maybe I've missed something, but it seems like you could completely eliminate the security flaw of letting your user's decide how much to pay for your software very easily. Just have the server send the price with an HMAC, check the HMAC on
47.
▲
by
lonestar
18y ago
No, they were stored as unsalted MD5 hashes.
48.
▲
by
lonestar
18y ago
If I recall correctly, the ~27k were not the easiest to lookup, but just the first 27k that the attacker looked up. He said he just got bored after that many.
49.
▲
by
lonestar
18y ago
Since I use PHP at work, I've been waiting eagerly for closures since I first heard they'd be in 5.3. Hopefully this stable release will have fewer issues than 5.1, and we can all upgrade quickly. I'm getting a little tired of cursing PHP's
50.
▲
by
lonestar
18y ago
I assumed you were choosing location based on IP, but I guess I'm just lucky to live in North Austin. It wasn't clear to me what I could do once I created an account until I read deep into the site; some text on the homepage like "Create an
51.
▲
by
lonestar
18y ago
I agree that it always pays to do things the Right Way the first time through, but I completely disagree with the second half of the article where he argues that you should make your code as generic as possible from the get-go. In my experi
52.
▲
by
lonestar
18y ago
Why? Assuming you're using CBC mode within each sector, you wouldn't lose any additional data due to a sector error compared to an unencrypted disk.