Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nsgi
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
18 ms
·
121.
▲
The college cleaner no-one knew was a slave
(bbc.co.uk)
2 points
by
nsgi
7y ago
|
0 comments
122.
▲
Premature Vaccine Launch Has Deadly Repercussions
(npr.org)
11 points
by
nsgi
7y ago
|
4 comments
123.
▲
by
nsgi
8y ago
#1 and #4 read as trying to catch the employer out. If an employer asked me interview questions like that I would view it as a red flag. It's one thing to be challenging, it's another to sound like you're on a power trip.
124.
▲
A new study shows sex doesn’t sell
(qz.com)
1 points
by
nsgi
8y ago
|
0 comments
125.
▲
by
nsgi
8y ago
Something like Netlify would do the trick. Zero cost or maintenance once you set it up with AdSense code, and better than using some parking service that would probably want to keep some of the revenue. https://www.netlify.com&#x
126.
▲
by
nsgi
8y ago
It's only one more hoop compared to doing it with a static IP. Pretty trivial to anyone capable of setting up a server.
127.
▲
by
nsgi
8y ago
I think the GP was suggesting automated sign in links for random web services. Using them for a bank account would be silly.
128.
▲
by
nsgi
8y ago
I can see a few problems with that approach: - It's already fairly straightforward to predict how easy a password will be to crack e.g. if you're going to bruteforce dictionary passwords or those with predictable combinations of c
129.
▲
by
nsgi
8y ago
Just because it's trivial doesn't mean all websites are doing it.
130.
▲
by
nsgi
8y ago
Why would age discrimination be easier to quantify if it was legal?
131.
▲
by
nsgi
8y ago
I rarely check my personal email because of the volume of spam and other noise I receive, so if a friend tried to contact me that way I probably wouldn't get it. I don't set up email notifications on my phone for that reason.
132.
▲
by
nsgi
8y ago
Yes. If they sell them in three months they're using insider information for financial gain. If they live there they could have just been making an early start on finding somewhere convenient to live. Whatever the rules are there'
133.
▲
by
nsgi
8y ago
Canada also has two entries
134.
▲
by
nsgi
8y ago
HTTPS protects against all of these: > any site that is loaded via http can have content mutated -- forcing users to http (and then acting as MITM), injecting javascript, other payloads. Which is why everyone is moving to HTTPS. > If
135.
▲
by
nsgi
8y ago
HSTS and Certificate Transparency, yes. Certificate Pinning is too easy to shoot yourself in the foot with, so it should only be considered for the most sensitive sites.
136.
▲
by
nsgi
8y ago
Now that we have Certificate Transparency you have much less need to trust them. Starting from scratch with a new system at this point would be a massive undertaking, all to attempt to solve a problem which has been largely fixed by CT.
137.
▲
by
nsgi
8y ago
Seems like this has some good security features, but with the move towards universal Https connecting to an unsecured WiFi network no longer carries the same level of risk it once did (other than exposing LAN shared resources). As good as p
138.
▲
by
nsgi
8y ago
On the other hand, that means bad managers are being paid more to do the opposite.
139.
▲
by
nsgi
8y ago
It's not really temporary in that example, though, if mp5 existed for some period of time there will always be mp5 files that some people will want to play and adding support ensures those files are never lost.
140.
▲
by
nsgi
8y ago
What stops you either using a browser extension or analysing encrypted data sent between IPs?
141.
▲
by
nsgi
8y ago
How would you phrase it instead, that would communicate the nuances of the issue and allow the lay user to assess the risk?
142.
▲
by
nsgi
8y ago
It's more likely that Google's support for HTTPS everywhere caused them to do both. It introduced HTTPS as a ranking signal in 2014, well before Let's Encrypt.
143.
▲
by
nsgi
8y ago
It would be necessary to use a different private key on each device for it to be secure, so something like 192-168-1-1.internaldevices1489420.hp.net
144.
▲
by
nsgi
8y ago
Ultimately Cloudflare is just another provider you have to trust if you decide to rely on them, just like your web host and anything else you use. For any non-trivial site you should do a risk assessment of the service providers, external j
145.
▲
Inside Scotland's 'village of dreams'
(bbc.co.uk)
1 points
by
nsgi
8y ago
|
0 comments
146.
▲
by
nsgi
8y ago
For something like a password manager, the most compelling updates are security fixes, but there are several problems with charging for these: - It's unreasonable to expect people to pay the full price for minor security fixes that sti
147.
▲
by
nsgi
8y ago
No idea if this is Apple's policy, but I would expect apps to follow UNIX philosophy. "Locate your device" should really be a separate app rather than a fringe feature of a fart app.
148.
▲
by
nsgi
8y ago
The potential savings from shutting down welfare programmes would be fairly easy to calculate, though.
149.
▲
by
nsgi
9y ago
Serving user-submitted files from your main hostname is generally a bad idea because of the risk of XSS vulnerabilities. On Amazon cloud the content is served from the subdomain. Though it does raise a good point as a content domain/su
150.
▲
by
nsgi
9y ago
The Death Note method. Reminds me of https://www.gwern.net/Death-Note-Anonymity
More ›