Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
moonboots
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
16 ms
·
91.
▲
by
moonboots
14y ago
Sorry, I misinterpreted your attack, and it's more worrying than I initially thought. I would add some information about the fix, namely adding the header "X-Frame-Options: SAMEORIGIN" [1]. [1] https://developer.mozilla.org/en-US/docs/HTTP
92.
▲
by
moonboots
14y ago
Usually these guarantees mean credits toward future billing. Cloudflare's enterprise plan offers 2500% uptime guarantee, which means if they are down 10% of the time, customers are credited 2.5 months. It sounds a lot nicer than it is, much
93.
▲
by
moonboots
14y ago
The kdf should be as slow as possible for an attacker but fast enough for you. If you're using python and the attacker is using C, you can increase security with no usability loss by switching to C and raising the iteration count.
94.
▲
by
moonboots
14y ago
Usually encryption schemes use a key derivation function like PBKDF2 to "stretch" a user's password to generate 128/256 bits for the symmetric cipher. In this case, the attacker cannot bruteforce aes directly because the generated key is "r
95.
▲
by
moonboots
14y ago
SSL doesn't protect against this timing attack. The vulnerability allows an attacker to generate a malicious cookie that the rack server believes is authentic. The attacker sends repeated http/https requests to your server with the maliciou
96.
▲
by
moonboots
14y ago
That package is it. It's in the universe repo, which is disabled by default (I think), so I didn't want to claim scrypt was as convenient as openssl.
97.
▲
by
moonboots
14y ago
The scrypt command line utility uses the scrypt kdf to generate a 256 bit key for aes. Both kdf and cipher are used during single file encryption with openssl and the scrypt command line utility. Openssl implicitly uses a md5 as a kdf durin
98.
▲
by
moonboots
14y ago
I recommend the scrypt command line utility [1] instead of openssl. Openssl use md5 as a key derivation function [2], and cost of recovering a reasonable length, randomly generated password is surprisingly low [3]. The costs in the presenta
99.
▲
by
moonboots
14y ago
Besides the difficulties of patching openssl and nss, what are other technical and political challenges preventing the adoption of djb's crypto primivatives in tls?
100.
▲
by
moonboots
14y ago
> Look at the data passed to the event. The callstack starts at the function attached as a listener to the event. > Is the event data incorrect? Then the problem is in the code that triggers the event. > Is the event data correc
101.
▲
by
moonboots
14y ago
The new ssl pinning proposals work very similarly to ssh. When the user visits an https site with pinning enabled, the browser will remember the server's public key similar to ssh's known_hosts. You're correct that this won't protect agains
102.
▲
China, GitHub and the man-in-the-middle
(en.greatfire.org)
36 points
by
moonboots
14y ago
|
35 comments
103.
▲
Seamless Git interop with Hg and Bzr
(felipec.wordpress.com)
2 points
by
moonboots
14y ago
|
0 comments
104.
▲
by
moonboots
14y ago
agl's blog is a good source: http://www.imperialviolet.org/
105.
▲
by
moonboots
14y ago
Fortunately, it looks like Chrome prevents users from clicking past the ssl errors. This Chinese chrome screenshot[1] shows that there's only a back button (for English versions of this page, see [2]). Unfortunately, it appears that IE allo
106.
▲
by
moonboots
14y ago
The problem with running crypto code in Javascript is that practically any function that the crypto depends on could be overridden silently by any piece of content used to build the hosting page. Ecmascript 5, the latest version of the Ja
107.
▲
Japan’s Business Culture Hovers Over Boeing’s Battery Choice
(nytimes.com)
2 points
by
moonboots
14y ago
|
0 comments
108.
▲
by
moonboots
14y ago
The overhead of newer ephemeral elliptic curve diffie hellman is as low as 15% compared to rsa[1]. [1] http://vincent.bernat.im/en/blog/2011-ssl-perfect-forward-se...
109.
▲
by
moonboots
14y ago
Redo lacks features baked into Drake, especially the Hadoop integration, but I believe it would be easier to incorporate custom functionality into redo versus hacking Make or writing a custom build system. I haven't used Drake, so I would b
110.
▲
by
moonboots
14y ago
Djb redo[1], a make alternative, feels like a good fit for these type of data manipulation and dependency representations. Below is a port of the first example. The build script is just shell, so you can do stuff like embed python with a he
111.
▲
by
moonboots
14y ago
In chrome, I'm not seeing the flash warning message. I'm only seeing an endless "Loading your fonts..." I have click-to-play flash enabled. Webfontloader[1] uses javascript to detect whether a specific font is available. They use a hack whe
112.
▲
by
moonboots
14y ago
A good intro is a talk given by Ryan Tomayko called the Shell Hater's Handbook[1]. His POSIX Shell and Utilities is also a great reference[2]. For a more comprehensive guide, I recommend the dash man pages[3]. Dash is shell, the good parts.
113.
▲
Releasing bitmapist.cohort - or how we saved over $2000/month
(amix.dk)
3 points
by
moonboots
14y ago
|
0 comments
114.
▲
by
moonboots
14y ago
I created http://typing.io primarily to help programmers practice typing, but it also allows users to explore open source code like jQuery and Rails by typing through instead of just reading.
115.
▲
Linux 3.7 released
(kernelnewbies.org)
254 points
by
moonboots
14y ago
|
114 comments
116.
▲
by
moonboots
14y ago
I'm using nginx+lua as the backend to http://typing.io , and I've found the combination to be a fast and robust alternative to more full featured web stacks like Rails.
117.
▲
by
moonboots
14y ago
As a side note, I love the slideshow UI. The keyboard navigation (j/k or left/right) brings each picture flush against the top of the screen. I hate when I need to manually scroll down to bring the picture into full view and hide the naviga
118.
▲
by
moonboots
14y ago
I can only imagine how much hairier these diagrams become if generated from code instead of English/html. Even for the best case scenario of "The Robot" combined with an "ergonomic" layout like dvorak or colemak, the right pinky area would
119.
▲
by
moonboots
14y ago
I'm a fan of cloudflare, but I'm disappointed they didn't thank or mention nginx in this blog post. Cloudflare uses nginx, which recently released OCSP support thanks to sponsorship from Comodo, DigiCert, and GlobalSign [1]. [1] http://ngi
120.
▲
by
moonboots
14y ago
Thanks for the feedback. Occasionally I also find myself typing opening brace, closing brace, left arrow, inner text, and right arrow. However, it's very inefficient to jump to the arrow keys, so I want to discourage this typing pattern. To
More ›