Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mieko
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
31.
▲
by
mieko
10y ago
There's still a decent size contingent of non-technical people that look at exampleapp.com the way I'd look at wellsfargo-online-banking.com. I don't blame them: subdomains imply authority. While I'm sure there's m
32.
▲
by
mieko
10y ago
I think a plumbing-level security implementation detail should be a little less intrusive than having to move either the corporate domain or millions of user's addresses. I can't imagine Tumblr rolling out HPKP now with this work
33.
▲
by
mieko
10y ago
Here's an issue not mentioned in the article, which gives me the half-baked feeling about HPKP: Thought experiment: (just using companies I think HN will be familiar with, I'm not involved with these.) 1. You're Tumblr or Bas
34.
▲
by
mieko
10y ago
This is awesome. A few days ago I posted this question at the Qualys SSLLabs forum: "Is there a reason for still having TLSv1.1 enabled?" https://community.qualys.com/thread/16565 Considering SSLv3 has been
35.
▲
by
mieko
10y ago
> Are you saying you're OK with co.uk getting a cert for foo.co.uk, even though they're under different administrative control? This argument hasn't been made, or hinted at, by anyone, anywhere in this thread. And $50 isn
36.
▲
by
mieko
10y ago
That's not how domain-validated wildcard certificates from any CA have ever worked, and it's not how any proposed wildcard-supporting future LetsEncrypt would work. I can, today, get a valid certificate for myname.github.io (getti
37.
▲
by
mieko
10y ago
This is the real issue with not allowing wildcard certs. If the rate limits were something that just cut in at abuse-levels, there'd be no need for them. Sites with per-user subdomains (to get security features like cookie isolation,
38.
▲
by
mieko
10y ago
If I operated banking.io, I could get a bankofamerica.banking.io cert from LetsEncrypt today. Unless something has changed, I could also get bankofamerica.com.banking.io, from LE or many other CAs. The wildcard issue has no effect on this
39.
▲
by
mieko
10y ago
LE uses the Public Suffix List to decide what's a "domain". Their really-low rate limits have caused a flood of applications which are overwhelming the PSL's maintainers. https://community.letsencrypt.org
40.
▲
by
mieko
10y ago
ActionCable generators can now generate either JS or Coffeescript. This is relatively recent, but the direction is clearly toward decoupling. https://github.com/rails/rails/commit/63ac6255ba3553b529f4b2...
41.
▲
by
mieko
10y ago
> If you add a .bold class to an element, why would you want it to sometimes not be bold? The problem is having a class called .bold, and then baking it into your HTML. I feel like many people arguing this have never undertaken a full-s
42.
▲
by
mieko
10y ago
They're suggesting that Bootstrap-like classes that name and reference a specific visual rendering (e.g., col-md-hidden) are no better than the old ROWSPAN/COLSPAN mess. They've just moved from HTML attributes to being packe
43.
▲
by
mieko
11y ago
Legally, there is a huge gradient between length(work), sha(work), train(transcription(work)), transcription(work), thumbnail(work), etc. Your personal definition of "derived" sounds a lot like the mathematical definition, which
44.
▲
by
mieko
11y ago
I hadn't heard of the LG/webOS story, but it's a good read: https://gigaom.com/2014/08/28/a-failed-experiment-how-lg-scr...
45.
▲
by
mieko
11y ago
"Intentional" was perhaps the wrong word for glibc, but BSD libc (at least on FreeBSD and OS X) actually document it as intentional: NOTES The fclose() function does not handle NULL arguments; they will result in
46.
▲
by
mieko
11y ago
I'd personally err on the side of clearer clean-up code, but this a good point (and a view shared with glibc and BSD-derived libcs that intentionally segfault in this case).
47.
▲
by
mieko
11y ago
This is The Way To Do It. I take minor issue to calling free(NULL) abuse, though (I know you get it, but allow me to soapbox). I've known programmers who get squeamish relying on this, as if it's a hack, even though it's be
48.
▲
by
mieko
11y ago
I think, day-to-day, the Ruby object model can be as simple or as complex as you'd like it to be. Most dynamic or static OO languages have just as much complexity under the hood (vtables, doesNotUnderstand, metaclasses, etc). It has
49.
▲
by
mieko
11y ago
FIPS is bureaucratic government red tape, and nothing else. It gives the "US Department of Whatever" and their contractors someone to blame when there's a fuck up. No one respected in cryptography that I've met, or read
50.
▲
by
mieko
12y ago
A few years ago, the Wolfire team (AKA, the Humble Bundle originators), put together a great set of articles on linear algebra as it applies to game development. I think it's one of the most plainly-written and practical guides out th
51.
▲
by
mieko
12y ago
I've seen Microsoft employees across the web have to point this out a dozen times. "The New Microsoft" seems to be making better decisions overall, but it apparently didn't learn anything from the early-2000s ".net
52.
▲
by
mieko
12y ago
Most C++ platform ABIs are pretty trivial to recognize. A tool like this could distinguish a C++ binary by looking at its initialization/housekeeping sections, static constructors, __cxa_atexit, exception handling tables, linked libra
53.
▲
by
mieko
12y ago
This is all true. The first thing I built was an awesome hammer, and I had a large amount of nails to deal with. In retrospect, I'm sure there was a good deal of more focused, surgical solutions that'd save some overhead.
54.
▲
by
mieko
12y ago
Author here. Here's the corresponding proggit thread: http://www.reddit.com/r/programming/comments/2hisfk/breaking...
55.
▲
by
mieko
12y ago
Yeah, for this scheme to work, a locked phone would need to be a brick, short of desoldering the flash. Unauthenticated recovery modes destroy this. I can see a scheme where each device has a specific unlock/recovery keypair in its ke
56.
▲
by
mieko
12y ago
As ineffective as biometric unlocks (TouchID, etc) are in targeted data retrieval scenarios, I'd wager their wider adoption would effectively kill casual smartphone theft. Every 5S owner I know actually uses TouchID. I'd guess ar
57.
▲
by
mieko
13y ago
I've implemented a handful of simple dynamic languages years ago, and something I was interested in trying, but never did, was taking advantage of the MMU to replace guard clauses. For example, mapping a few pages for vtables/meth
58.
▲
by
mieko
13y ago
jquery-turbolinks as a drop-in fix worked great for my application. The only tweaks my own code required at that point were resources I assumed would die and be recreated on the next page load, like doubling up setInterval handles in domre