Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nmgsd
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
nmgsd
8y ago
You can't forge a JWT without stealing the private key of the valid JWT signer. You can steal a JWT token the same way you can steal a session token.
2.
▲
by
nmgsd
8y ago
The issue becomes very difficult when you need to preserve message history reliably and allow account usage across devices. Because key management becomes tricky and clunky and there's no easy UX ways around it. For ephemeral messagin
3.
▲
by
nmgsd
9y ago
I agree strongly with you that the direction to be taken is independent messaging clients for existing messaging channels as long as those channels allow third party API use. What channel would you use to share the keys on FB? The Facebook
4.
▲
by
nmgsd
9y ago
This highlights a major issue with ALL messaging apps, namely that the provider owns the clients AND the backend. Distributed open-source clients that use end-2-end encryption over third party messaging channels is the future of secure mess
5.
▲
by
nmgsd
10y ago
VPN people, VPN
6.
▲
by
nmgsd
10y ago
It depends what the API is supposed to do of course.
7.
▲
by
nmgsd
10y ago
A cool way to circumvent the keyword filtering: www.seecret.io
8.
▲
by
nmgsd
10y ago
This is why you should never trust proprietary secure messaging solutions that offer you both the client and the channel. The future of trusted secure messaging will be open source, auditable, independent non-native clients that connect and
9.
▲
by
nmgsd
10y ago
of course he does.
10.
▲
by
nmgsd
10y ago
One option is to store the files in Amazon S3 and only serve them over cloudfront signed URLs. There's ways to lock down the S3 access so that only a few Very Important tech leadership folks can get to it.
11.
▲
by
nmgsd
10y ago
You can always assume this.
12.
▲
Show HN: End-to-end encryption for Twitter direct messages
29 points
by
nmgsd
10y ago
|
5 comments
13.
▲
Show HN: Hide your tweets in plain sight – Twitter steganography
2 points
by
nmgsd
10y ago
|
0 comments
14.
▲
by
nmgsd
10y ago
From the article:"But take a closer look at that list and you can quickly see that all of these various behaviors could be described by one simple, everyday phrase: You're in trouble if your employee starts phoning it in." Th
15.
▲
by
nmgsd
10y ago
Are you perhaps thinking of JQuery UI? The core JQuery lib is still used. And for basic front end dev it really does offer most of the utility you'll look for in other libs. 1. Get and manipulate dom elements. 2. Register simple eve
16.
▲
by
nmgsd
10y ago
The App Store run by a central authority with complete control over what can even be available and the ability to modify the delivery at their own whim is certainly a big issue in terms of trusting the integrity of the apps running on a dev
17.
▲
by
nmgsd
10y ago
Most interview processes are a real disservice to the interviewee AND the company. Typically, the team manager will just have his team members all interview the candidate. They will have no prep, no guidance, nothing. Just "intervie
18.
▲
by
nmgsd
10y ago
This is 100% false. Can confirm.
19.
▲
by
nmgsd
10y ago
I have never once attended an all-hands meeting that couldn't have been an email instead.
20.
▲
by
nmgsd
10y ago
A lot of these answers are pointing out the x-browser complexity which is true but that isn't what drives JS package mgmt. It's mostly Node stuff. The mature common JS libs for browser work are pretty robust when it comes to x-b
21.
▲
by
nmgsd
10y ago
Let's hope they at least hashed their passwords correctly.
22.
▲
by
nmgsd
10y ago
-- "Open source software and decentralization is nice and all but to become a mobile app it'll have to be compiled and run on a closed platform and will almost certainly use APIs of that platform." -- That's not necessa
23.
▲
by
nmgsd
10y ago
For high value targets yes, they can't really be safe but for avoiding mass surveillance it's good.
24.
▲
by
nmgsd
10y ago
can anyone confirm this is legit?
25.
▲
by
nmgsd
10y ago
Suprising to no one.
26.
▲
by
nmgsd
10y ago
You had me at "planners"
27.
▲
by
nmgsd
10y ago
To be fair this is a criticism of Javascript package and library tooling rather than Javascript itself.
28.
▲
by
nmgsd
10y ago
No-password access can be pretty good for enterprise but just not realistic for consumers (yet). This humorous take on it actually does a pretty good job of explaining the user-experience reasons.
29.
▲
Fix your legacy password storage. NOW
(medium.com)
1 points
by
nmgsd
10y ago
|
0 comments
30.
▲
by
nmgsd
10y ago
Accurate. Can confirm.
More ›