Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mdp
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
mdp
12y ago
Think about this for a second. You can literally go "crawling all over the Brooklyn Bridge consequence free" anytime you like. It's a bridge you can walk on. You can even drive your car on it. In both cases you're far mo
62.
▲
by
mdp
13y ago
I think it's the same strategy as Georgia/Abkhazia. You go in to "defend" the ethnic Russians. You don't take it over, you simply "Keep the peace" and make them a separate country. Congrats, now you have a
63.
▲
by
mdp
13y ago
This is simply not true. 'In some of the documents, prosecutors allege that HSBC intentionally flouted the law. The bank created an operation that was a "systemically flawed sham paper-product designed solely to make it appear tha
64.
▲
by
mdp
13y ago
I can actually answer this decisively. Don't take legal advice from anyone but a lawyer that you are paying. Seriously, this depends on a variety of factors and is especially dependent on your local laws, the specifics of the contract
65.
▲
JsPoker - PokerBot Tournament written in Javascript
(markpercival.tumblr.com)
2 points
by
mdp
13y ago
|
1 comments
66.
▲
by
mdp
13y ago
It looks a bit obfuscated, but there might be some useful finds. I'm going through it and looking for hardcoded strings that might not be in the resource files. I posted the APKTool output on Github for anyone that wants a quick look -
67.
▲
by
mdp
13y ago
Yep, yet another Gogo "exploit" disclosure. This one is actually quite pathetic. Here's my security disclosure for the day: You can walk out of most stores without paying for their merchandise if you hide it in your pocket. W
68.
▲
by
mdp
13y ago
It's definitely a questionable javascript library, I wrote it back in 2008 after reading the wikipedia article :) It was designed to interop with OpenSSL's default command line AES crypto, which has some weak points, mostly around
69.
▲
Hacking HTTPS to HTTP referrers
(markpercival.us)
2 points
by
mdp
13y ago
|
0 comments
70.
▲
Curl directly to gist
(github.com)
1 points
by
mdp
14y ago
|
0 comments
71.
▲
by
mdp
14y ago
Yeah, I've only had this happen a couple times, and it does make you trust your spam system less. That being said, it's seems to be getting better as more companies embrace SPF.
72.
▲
by
mdp
14y ago
Look at the IndieGoGo header image he's using. It's a screencap of Gmail's spam folder with 5,048 messages. Hasn't this clearly been solved? I get MAYBE 2 spam emails a month that gets through the filter, and my address is pretty easy to ha
73.
▲
by
mdp
14y ago
Yeah, this is an entirely valid criticism. It was more of a nitpicky point that they weren't flipping to HTTPS automatically, but from a practical standpoint it's no more secure if they did since they lack HSTS. Struck it from the post.
74.
▲
by
mdp
14y ago
They've never really been focused on security in the past. Honestly, I love the service, but their lack of concern about keeping it secure has never sat well with me. I wrote up a post with some of my security concerns. http://news.ycombin
75.
▲
Evernote doesn't really care about security
(markpercival.us)
115 points
by
mdp
14y ago
|
61 comments
76.
▲
by
mdp
14y ago
I always just assumed you split your time between writing and running a Volkswagen dealership in Southampton. http://www.petercoopergroup.co.uk/
77.
▲
by
mdp
15y ago
This looks very cool. I've been working on a similar project built on top of Node.Js and Connect ( https://github.com/mdp/middlefiddle ) It lets you use Connect compatible middleware to alter the request or response - ( https://github.com/m
78.
▲
by
mdp
15y ago
"* OP double-protects the SSH key. It means you need the key's passphrase and another factor (Google authenticator) to decrypt the ssh key. Then the ssh key is used to auth with the server. => the authentication with the server is still
79.
▲
by
mdp
15y ago
Actually, I made the switch from Slicehost to Rackspace because it was cheaper. It's pay for what you eat pricing, so you don't get a free allotment of bandwidth, but it's around ~$11 for a 256 meg instance. My biggest concern is that the R
80.
▲
by
mdp
15y ago
Yes, but I'm extremely lazy :) The less time I spend learning a new editor is more time I can spend learning a new technology.
81.
▲
by
mdp
15y ago
Yes, but what happens when development on this closed source editor dries up? It looks like a great app, but I'm still leery of basing something as important as my editor on a closed code base again. There are also some great alternatives o
82.
▲
by
mdp
15y ago
I'm more impressed by those UK click through rates on bieberfever.com
83.
▲
by
mdp
16y ago
Yeah it's easy, just convince everyone you're too big to fail and have the American taxpayer pay it off.
84.
▲
by
mdp
16y ago
I'm typing this from my iPhone in a bar in Siem Reap, Cambodia, so forgive my brevity and spelling. Wifi might be prevalent in most places but quality and reliability will always be am issue. I've found it to be ubiquitous is SE Asia, howev