Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
marcinw
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
marcinw
15y ago
No, "someone who creates web apps" is a web application developer.
32.
▲
by
marcinw
15y ago
Mike Rowe is also an Eagle Scout if that matters anymore to you.
33.
▲
by
marcinw
16y ago
I remember working with several of the Parallax PINK modules back in the day as well. http://www.parallax.com/Store/Accessories/CommunicationRF/ta... If memory serves me correctly, some peers at my university had wrote a web interface to
34.
▲
by
marcinw
16y ago
Not to mention, government TLA's do their own "research."
35.
▲
by
marcinw
16y ago
Tipfy looks to be as well: http://code.google.com/p/tipfy/source/browse/tipfyext/wtform...
36.
▲
by
marcinw
16y ago
That's great until the person you're selling to immediately jumps on that. At this point, you are left wondering, "Gee, was my offer that good? Was it too low? I wonder what he was expecting to pay. Damn, I could have made 20% more had he m
37.
▲
by
marcinw
16y ago
Many would also argue that the majority of people that hang out here are not "hackers" but instead "developers that (mostly) know how to get shit done." In their eyes, hacking is exploiting a weakness in a system to do something the system
38.
▲
by
marcinw
16y ago
Unfortunately, for a lot of us working in locked down environments, this code makes use of the py-bcrypt module which uses the bcrypt C implementation. If you're running on GAE, you're out of luck. I keep telling myself to port to pure Py
39.
▲
by
marcinw
16y ago
Sorry for the confusion, I meant "non-idempotent". I had two separate thoughts in my head at once and munged the two, leaving out the "non-".
40.
▲
by
marcinw
16y ago
Being a software developer and being an exploit developer are two entirely different things. Professional exploit developers DO NOT ship unless it's perfect. Malware authors will ship even if it's not perfect, because the target is not te
41.
▲
by
marcinw
16y ago
In addition to tzs' comment above, POST parameters do not get logged by the web server either (default Apache logging, etc), unless you're using a module like mod_security to log POST data. Besides, don't use GET for non-idempotent requests
42.
▲
by
marcinw
16y ago
We did this on VCR tapes too. Little electrical tap over the broken tab, and bam -- you've got re-writable media!
43.
▲
by
marcinw
16y ago
It was funny, but not that funny...
44.
▲
by
marcinw
16y ago
"Perhaps it's worth noting that my kids generally prefer prepackaged foods over our cooking. So maybe it's a cyclical thing, in some subset of each generation. But I'm hoping that teaching them to cook will change that." Trust me, as they e
45.
▲
by
marcinw
16y ago
We have several positions available in New York City AND London. If you have an interest in breaking stuff, can code in C, Java, C#, Python, or whatever, come talk to us! Send me an email at <my yc username> @ gdssecurity.com http:
46.
▲
by
marcinw
16y ago
Cute, but damn onmouseover on the iPad.... :(
47.
▲
by
marcinw
16y ago
There's a saying that goes, "Abs are made in the kitchen, NOT the gym." I can't stress enough how much portion control (eating less) plays an important in your dieting. Don't believe me? Look at the serving size on the nutrition facts la
48.
▲
by
marcinw
16y ago
Right, and the people who are running malicious Tor exit nodes won't tell you that either. Good luck with that.
49.
▲
by
marcinw
16y ago
What about "..%2F..%2F" or "..\..\" or "..%5C..%5C"? In Java, you also need watch out for NULL (%00) in the path as well since java.io.File disregards anything after the null (most just test to see if filename ends with "ext" where ext is
50.
▲
by
marcinw
16y ago
That's okay, leaves more to surprise :)
51.
▲
by
marcinw
16y ago
It's actually a very common practice for companies to do this. Just whois xcompanysucks.com
52.
▲
by
marcinw
16y ago
In a traditional for loop fashion: def known_edits2(word): L = [] for e1 in edits1(word): for e2 in edits1(e1): if e2 in NWORDS: L.append(e2) return set(L)
53.
▲
by
marcinw
16y ago
Sorry for not explaining, maybe the following will convince you. When an application generates a password, about how long/secure are these passwords? (on average, and remember, we're staying user friendly...) Probably about 8-10 character
54.
▲
by
marcinw
16y ago
At any moment, you can have two valid passwords used to access your account. Do all the A/B testing you want, this is NOT how you handle password resets.* * Note that even my proposed solution is not the best way to handle password resets.
55.
▲
by
marcinw
16y ago
This approach would introduce more complexity than it's worth, in addition to being less secure. Instead of just one password that can be used to login to your account, you now have two valid passwords.
56.
▲
by
marcinw
16y ago
A better way for Hacker News to handle password resets is to send the original email address associated with the account an email containing a one-time, expiring link allowing the user to change their password from. Otherwise, your passwor
57.
▲
by
marcinw
16y ago
import bcrypt hashed = bcrypt.hashpw(password, bcrypt.gensalt(log_rounds=13)) Increasing log_rounds by one increases the work factor exponentially (2 * * log_rounds).
58.
▲
by
marcinw
16y ago
We're all wondering what he used to visualize his data set.
59.
▲
by
marcinw
16y ago
A bunch of "script kiddies" can make any website unavailable for some period of time. edit: The only difference is in how fast you manage to recover.
60.
▲
by
marcinw
16y ago
Nice job editing your comment without saying so (" -- although not impossible --" and your last paragraph). Anyway, your nginx/lighttpd server is more likely to be exploited and compromised via an actual vulnerability rather than your Apach
More ›