Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mathias
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
mathias
10y ago
That’s true for client-side JavaScript (like I said in the presentation). It’s a whole different story if you’re using server-side JavaScript (e.g. Node.js), though.
32.
▲
by
mathias
10y ago
> It looks like this is possible because there is not an explicit 'access-control-allow-origin' header set on facebook CORS has nothing to do with it, actually. This is where the strength of the attack lies.
33.
▲
by
mathias
11y ago
“If you are logged in to a site that does this, it's a huge danger. Your private account information can be slurped down by ajax on any other sites.” This is false (unless `Access-Control-Allow-Credentials` is set). See CORS 101: http
34.
▲
ES6 `const` is not about immutability
(mathiasbynens.be)
1 points
by
mathias
11y ago
|
0 comments
35.
▲
Security certification services may harm your website
(vagosec.org)
4 points
by
mathias
12y ago
|
0 comments
36.
▲
by
mathias
12y ago
More details on the Unicode regex problems in JavaScript (slide 62) and how ES6 will solve most of these issues: https://mathiasbynens.be/notes/es6-unicode-regex
37.
▲
Hacking with DNS
(docs.google.com)
62 points
by
mathias
12y ago
|
9 comments
38.
▲
by
mathias
12y ago
Luckily shaaaaaaaaaaaaa.com itself is fine: https://shaaaaaaaaaaaaa.com/check/shaaaaaaaaaaaaa.com
39.
▲
Why Google is Hurrying the Web to Kill SHA-1
(konklone.com)
423 points
by
mathias
12y ago
|
131 comments
40.
▲
by
mathias
12y ago
I spotted this earlier this week when ordering a t-shirt through TeeSpring using PayPal. I authorized a payment of 22.95 USD. Here’s a screenshot from the payment confirmation email I received: http://i.imgur.com/BGjKcsW.png
41.
▲
by
mathias
12y ago
Please use http://meiert.com/en/indices/html-elements/ instead, as it’s based on the WHATWG HTML Living Standard rather than W3C’s versioned fork.
42.
▲
by
mathias
12y ago
The point of typing a message in a webmail UI and sending it is to deliver the exact message you entered to the recipient. Adding hard line breaks, effectively altering the original message, is not useful. Making text fit on a 80-character
43.
▲
by
mathias
12y ago
> > The RFC does not reflect reality either (which, ironically, is what you seem to be complaining about). > Well, or reality does not match the RFC? Doesn’t matter – if there’s a discrepancy between what a document says and what i
44.
▲
by
mathias
12y ago
But then you might end up shortening things like `about:blank` by accident.
45.
▲
by
mathias
12y ago
You do realize that RFC 3986 doesn’t actually match reality, right? http://url.spec.whatwg.org/#goals
46.
▲
by
mathias
12y ago
My exact use case was the following: the user clicks a bookmarklet that passes the current URL in the browser as a query string parameter to a URL shortener script. The validation is then performed before the URL is shortened. In that scena
47.
▲
by
mathias
12y ago
Yes, to reject non-URLs and also some URLs that are technically valid but that I want to explicitly disallow anyway.
48.
▲
by
mathias
12y ago
That was not an option in this case, as the goal is to validate URLs entered as user input and blacklist certain URL constructs even though they’re technically valid.
49.
▲
by
mathias
12y ago
> Deviating from the formal spec because everyone practically agrees how to do things, albeit differently than in the formal spec, is something quite different from making shit up, and actually tends to be even harder than building thing
50.
▲
by
mathias
12y ago
The goal was to come up with a good regular expression to validate URLs in user input, and not to match any URL that browsers can handle (as per the URL Standard). I am fully aware that this is not the same as what any spec says. > By th
51.
▲
by
mathias
12y ago
You forgot the most relevant spec, the URL Standard: http://url.spec.whatwg.org/
52.
▲
by
mathias
12y ago
As for why the trailing dot is disallowed, see < http://saynt2day.blogspot.com/2013/03/danger-of-trailing-dot... . The goal was to come up with a good regular expression to validate URLs as user input, and not to
53.
▲
by
mathias
12y ago
Exactly. The goal was to come up with a good regular expression to validate URLs as user input. There’s no way I’d want to allow alternate IP address notations.
54.
▲
by
mathias
12y ago
If you looked at the page before commenting you’d know that PHP’s built-in URL parser is one of the implementations that is being tested. You’d also see that one of the requirements was to not match scheme-relative URLs (e.g. `//f
55.
▲
Regular expression that matches only itself
(codegolf.stackexchange.com)
2 points
by
mathias
12y ago
|
1 comments
56.
▲
Hacking with Unicode (examples similar to the TweetDeck XSS)
(speakerdeck.com)
13 points
by
mathias
12y ago
|
0 comments
57.
▲
Firefox 30 adds support for CSS `line-height` on s
(twitter.com)
3 points
by
mathias
12y ago
|
0 comments
58.
▲
by
mathias
12y ago
The post links to it as well.
59.
▲
Hacking with Unicode
(speakerdeck.com)
4 points
by
mathias
12y ago
|
0 comments
60.
▲
The correct abbreviation for Firefox is ‘Fx’, not ‘FF’
(website-archive.mozilla.org)
39 points
by
mathias
12y ago
|
55 comments
More ›