Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
msmith
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
31.
▲
by
msmith
8y ago
I was a lead on Blitz. You’re right that there are ways to get around this domain ownership check, but in practice it was enough of a hurdle to avoid bad actors. Also, I’m pretty sure that these stressors were way more cost effective if you
32.
▲
by
msmith
8y ago
Since Pi-Hole is a DNS server running on a separate machine, it just doesn’t have the same level of access as browser extension would. Even if it was rogue, the worst it could do is share the list of domains that you visit, and possibly hij
33.
▲
by
msmith
9y ago
IBM is also behind the very nice Carbon design system and its React component library. http://carbondesignsystem.com/ https://github.com/carbon-design-system/carbon-components-re...
34.
▲
by
msmith
9y ago
WP Engine | Austin, TX and Limerick, Ireland | ONSITE Full-time WP Engine is building a high-scale managed cloud platform for WordPress. We have solid and growing revenue with 70,000+ customers and 500,000+ sites. Our current tech stack is
35.
▲
by
msmith
9y ago
Most of the content has a shelf life much longer than one year, so I'm sure that factors into the equation.
36.
▲
DigiCert to Acquire Symantec’s Website Security and Related PKI Solutions
(symantec.com)
1 points
by
msmith
9y ago
|
0 comments
37.
▲
by
msmith
10y ago
How about creating hundreds of millions of certificates, developing a new standard protocol to interoperate with CAs, managing millions of registered users, managing certificate revocation, logging to certificate transparency logs, running
38.
▲
by
msmith
10y ago
I've built a small project using v2 and it really helped me get up to speed and learn some of the best practices for React front-end development. I'm looking forward to trying v3, because it addresses a several things that I felt
39.
▲
by
msmith
11y ago
It doesn't even have to be an undisclosed vulnerability. iOS 9.3 was released today and included several fixes to vulnerabilities which allowed arbitrary code execution, including one with "kernel privileges" [1] Now that the
40.
▲
by
msmith
12y ago
I'd just like to point out that the majority of those are sector funds, so it really doesn't make sense to compare it to a broadly-diversified index like the S&P 500. On top of that, many of the high-fliers in that list are le
41.
▲
by
msmith
12y ago
The first code I ever shipped was an ANSI viewer that was included in several artpacks. It's so great that I can still find it after almost 20 years. I really wish that I'd kept a copy of the source.
42.
▲
by
msmith
12y ago
I don't know if you can draw a conclusion from those numbers alone, but it's typical for a SaaS business to measure Customer Acquisition Cost (CAC) and Lifetime Value (LTV) of the typical customer. Sales and marketing seem to be t
43.
▲
by
msmith
12y ago
Ruby's dependency management (rubygems) also came from the community and is now part of the standard library. That seems like a good model to follow. Dependency management for Go is definitely on people's radar. https://
44.
▲
by
msmith
13y ago
Realize that Sal recorded this video in March of 2008, at the peak of the housing bubble. Many of the assumptions made in the video are certainly not going to be the same in today's market. When you're modeling the rent vs buy sc
45.
▲
by
msmith
13y ago
Used in this context, "reasonable royalty" is a legal term that describes the money that is to be paid due to the infringement. I don't believe the author was making a judgement call on the fairness of the award.
46.
▲
by
msmith
13y ago
> “He doesn’t have all these fancy degrees,” said Fenster. I find it funny that Fenster, after praising Jones in this way, would attack Diffie's credibility by pointing out that he lacks a master's or PhD. [1] http://
47.
▲
by
msmith
13y ago
Ironically, I think it's actually slightly easier for an eavesdropper to detect that your keystrokes are part of a password if the password is not being echoed. They could potentially use this information to know the length of a password, w
48.
▲
by
msmith
13y ago
One interesting thing about this is how it can lead to timing attacks which leak information about your keystrokes. There's a great paper [1] which gives some examples. One more reason to use pubkey authentication for SSH. [1] http://use
49.
▲
by
msmith
13y ago
Wow, that certainly is surprising. I've looked at the EC2 pricing page many times and never noticed that. I think you pasted the wrong link, though. Here's the page which contains that quote: http://aws.amazon.com/ec2/pricing/#reserved
50.
▲
by
msmith
13y ago
I put something like this together a while ago. I think it still works. Just two scripts, ffmpeg, and a cronjob. https://github.com/msmith/caps .
51.
▲
by
msmith
13y ago
He was probably talking about VTSAX. A different class of shares within the same fund, which has a $10,000 investment minimum.
52.
▲
by
msmith
13y ago
I occasionally read about people's 401K options on the Bogleheads forum [1]. You're right, many of them are shockingly bad. Startups and small companies are especially likely to have poor options. The solution is for employees to become b
53.
▲
by
msmith
13y ago
I've watched the Frontline piece that this article is based on. It's not quite as hysterical, but it does make the case that the high-cost actively managed funds offered by most 401k plans underperform low-cost index funds, which are not a
54.
▲
by
msmith
14y ago
OP has a good point about deployment. DevOps tools have made huge strides in the last few years and it's feasible to build something that approaches the convenience of Heroku's fully-managed deployment pipeline, but that's not the only valu
55.
▲
by
msmith
14y ago
bundle install has several other useful options too. My favorites: --local will prevent rubygems.org from being contacted, and will only use previously cached gems --standalone will package all dependencies into ./bundle, so that you can co
56.
▲
by
msmith
14y ago
It is possible for the publisher to sign the gems [1], but it's not common. If rubygems.org is keeping fingerprints of each gem, then it still isn't sufficient, since those could have been compromised as well. If there's no other trustwort
57.
▲
by
msmith
14y ago
More than half of the states in the Union have some sort of Castle Doctrine or Stand Your Ground law [1]. It's not just Texas. [1] http://en.wikipedia.org/wiki/Stand-your-ground_law#United_St...
58.
▲
by
msmith
14y ago
I agree that it's a bad idea to have a null check on req & req.getHeaders(). One might think that this kind of thing makes your code more resilient, but instead it just makes it harder to track down the inevitable bugs like forgetting t
59.
▲
by
msmith
14y ago
I'm not sure about Perth, but from AWS Sydney I'm seeing pings of around 400ms to AWS Singapore.
60.
▲
by
msmith
14y ago
One nice thing about git is that you can easily amend your commit history. If you've done several related refactor commits in a row, then sometimes it makes sense to squash them into one, using `git rebase -i` [1]. [1] http://gitready.com
More ›