Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
odammit
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
91.
▲
by
odammit
9y ago
That made me laugh out a boogie.
92.
▲
by
odammit
9y ago
Of course. But that driver could have a disability - their allergy if it’s severe. Maybe it shouldn’t be a toggle, maybe it’s a part of both the driver and users profile so a driver can’t descriminate and instead it’s more of a matching alg
93.
▲
by
odammit
9y ago
When booking a ride, Uber needs three toggles: - Do you a service dog - Do you want AC - Do you want to talk to the driver Edit: I can’t format.
94.
▲
by
odammit
9y ago
Wow. If deaths are broken out by pedestrian vs passenger, I wonder how people will respond if safety skews heavily towards one of those groups with self driving cars.
95.
▲
by
odammit
9y ago
Curious how the numbers work out of number of miles [1] to number of deaths of autonomous vs standard vehicles. I know the scale is different but since this is the first death I’m curious if the percents fall in line. [1] is distance the ri
96.
▲
by
odammit
9y ago
That’s impressive: > Libraries written in C doe not have a huge run-time dependency. In its minimum configuration, SQLite requires only the following routines from the standard C library: memcmp() memcpy() memmove() memset()
97.
▲
by
odammit
9y ago
Chill, even his lawyer wants to punch him in the face. http://time.com/5193461/martin-shkreli-lawyer-punch-face/
98.
▲
by
odammit
9y ago
Corrected.
99.
▲
by
odammit
9y ago
Ha. I didn’t realize I did that. She’s cool ;)
100.
▲
by
odammit
9y ago
After the leak last year I’ve spent a few hundred bucks freezing my wife and my credit. While the cost is annoying, the process is even more annoying. The entire idea/industry needs to be changed. It’s absurd all Americans are opted in
101.
▲
by
odammit
9y ago
Paywall?! I assume they are doing it through toilet cams. Is this a rehash of the Reply All episode? https://www.gimletmedia.com/reply-all/109-facebook-spying
102.
▲
by
odammit
9y ago
Do you know what all of that piping and industrial looking stuff is east of Playa on Culver?
103.
▲
by
odammit
9y ago
I lived in Playa del Rey for years just a few blocks from the house on the hill in the 4th pic. A few of the local coffee shops and restaurants have some of these old photos and I always found it amazing that you could still see the resembl
104.
▲
by
odammit
9y ago
$5,388. Not worth the humor of owning it.
105.
▲
by
odammit
9y ago
I wonder how much winblows.com is going for. Edit: I’ll update in 24 hours when a BuyDomains expert responds to my spam email address.
106.
▲
by
odammit
9y ago
I assumed they meant largest economy?
107.
▲
by
odammit
9y ago
I think it’s for the convenience of people that are already using spanner and don’t want an additional data store.
108.
▲
by
odammit
9y ago
Kinda agree about it being annoying. I think MFA is important and have it enabled for every service that offers it, but we have MFA set up for our CLI access to AWS and I used to let out a volume of curses frequently when my token expired.
109.
▲
by
odammit
9y ago
Wow you’re aggressive. Using something like Hashi Vault, Gluu, or Shiro does not overly complicate things. They’re stable, trusted solutions. It can also greatly simplify things. In the common scenario of having a web app for customers and
110.
▲
by
odammit
9y ago
Absolutely, Im not stating otherwise. Im saying you shouldnt have your authentication inside your business logic. It should be a separate service. Limited access, and transparent to the application that is calling on it. If you want that to
111.
▲
by
odammit
9y ago
They aren’t “hacking on production.” They’re occassionlly under pressure to release features. If they don’t get someone that catches a SQL injection or something else silly in a PR it’s nice to know we cant possibly bleed our password has
112.
▲
by
odammit
9y ago
The point is not putting them in a system that can leak them right alongside the login identifier. If someone wants to go exercise 9384828388 GPUs on your list. Fantastic, at least the other piece of their auth username/etc isn’t sitt
113.
▲
by
odammit
9y ago
^ above is pretty damn simple. I also never said “write your own hashing algorithm” I said abstract it so it’s not sitting around in your ecommerce app code. That is a simple security system. It’s just not baked into your flagship ecommerce
114.
▲
by
odammit
9y ago
You don’t have to “roll your own security.” You can easily put any open source security system behind a secondary system. Hell - it would already be a secondary system. Not putting your passwords right next to the identifiers is a simple wa
115.
▲
by
odammit
9y ago
A day of engineering effort to make exposing passwords much more difficult. Yes. If you’re a company that stores someone’s password. You know they probably use it elsewhere so it’s your responsibility to help keep it safe. Also I left the l
116.
▲
by
odammit
9y ago
You need both. https://www.trustedsec.com/2016/06/introduction-gpu-password...
117.
▲
by
odammit
9y ago
Split brain your password storage. Another table, another database or another storage system in general. If an attacker SQL injections your database don’t go spilling every hashed or unhashed password you’ve got. I tend to store passwords i
118.
▲
by
odammit
9y ago
Sure and 10k will do fine otherwise “! I thh Cher;457?:25?//(5 we” is going to suck for you user login story. Maybe salt your passwords, use some stretches, and a decent algorithm instead of MD5, SHA1, etc. Also stay up on algorit
119.
▲
by
odammit
9y ago
WAF, IP blacklists, naive bot detection[0] and why would a decent thresholding system allow for a single IP to fail multiple accounts in a short time period. If you hit two valid accounts [1] with bad passwords in a few ACCEPTABLE_UNIT_OF_T
120.
▲
by
odammit
9y ago
Although it does happen that’s amature and unacceptable. Either you have some EXTREME legacy or lazy engineers. Doing it right doesn’t take long.
More ›