Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nextgens
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
nextgens
8y ago
Many things... here are the ones I care about: - you can have different keys for all your "partitions" without having to pre-allocate them - you can send encrypted incremental snapshots to a host that doesn't have the key (fo
32.
▲
by
nextgens
8y ago
The most effective trick it uses requires the ability to send custom HTTP headers... that wouldn't work as a bookmarklet.
33.
▲
by
nextgens
8y ago
They make it clear that it's not the listing of the addon on AMO that makes it subject to their policies (and local laws)... it's the signing itself. So yeah... I can provide an unsigned copy of my add-ons to users... but unsigned
34.
▲
by
nextgens
8y ago
I am the author of that add-on ... what would you do in my shoes ? - provide an XPI (that will only benefit the few since the side-loading process is made awkwarder at every point release) ? - fight it ? If so, on what grounds and how
35.
▲
by
nextgens
8y ago
Let me introduce you to https://safepass.me ; My current pet project
36.
▲
by
nextgens
9y ago
Google's take good care of it... and they explain precisely what they do on the topic... https://developers.google.com/speed/public-dns/docs/ecs https://developers.google.com/speed/p
37.
▲
by
nextgens
9y ago
Are you aware that your public resolvers are actively breaking DNS-based GeoIP (striping EDNS0-ECN and not using source IPs geo-localized as the requester would be)? and if so, what is the rationale for it?
38.
▲
by
nextgens
9y ago
> Why would you not recommend code that checks the hashed password against a local DB? I would. In fact that's why I have created a product to do exactly that in an efficient way... Doing the checks online has too many drawbacks:
39.
▲
by
nextgens
9y ago
You're not comparing the same thing. One is a commercially supported product... that ships HIBPv2 in a ~400MB bundle, the other one a PoC... that suggests that doing a binary search over a 30GB+ dataset each time there is a password ch
40.
▲
by
nextgens
9y ago
If you are looking for an "offline" way of checking your (windows) passwords against the HIBPv2 dataset, I encourage you to check my current pet project out: https://safepass.me It's an active-directory password f
41.
▲
by
nextgens
9y ago
> If you want to stop password spraying, protect your hashes. Again, it's not about your hashes, it's about the attacker having access to your users' credentials. Users re-use credentials accross services and you have no c
42.
▲
by
nextgens
9y ago
> I'm going to have to disagree with the premise that sites should stop users from choosing a password which happens to have been cracked offline at some point in the past Well, NIST, NCSC and Microsoft all seem to be on the same pa
43.
▲
by
nextgens
9y ago
You might want to give https://github.com/nextgens/anti-paywall a shot.