Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pilif
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
91.
▲
by
pilif
3y ago
> That's also a good reason for others to drop support until licensing of these patents is clarified. If that were true, then browsers should drop support for VP8, VP9 and indeed AV1 because the MPEG-LA is claiming ownership of pa
92.
▲
by
pilif
3y ago
I assume that's the key used by the app. So if they kill that key, they also kill all existing applications. That's the thing with this kind of "protection". If your proprietary app needs to access the server, anybody wh
93.
▲
by
pilif
3y ago
maybe for you, but not for me. 800x600 was still very cramped and the first time I felt I could comfortably do development was on a 21" Sony CRT at 1600x1200, though that was pushing the monitor resolution-wise and it lost a bit of sha
94.
▲
by
pilif
3y ago
The package manager has been open source, cross platform and available since pretty much from the start. The standard library is becoming cross-platform as we discuss it here.
95.
▲
by
pilif
3y ago
Because that potentially allows all distro-supplied files to live under one (eventually read-only) directory.
96.
▲
by
pilif
3y ago
you're supposed to use the control endpoint to negotiate which data endpoints to set up in what way for communication and then communicate over those. In the case of this barcode scanner all communication was done over the control endp
97.
▲
by
pilif
3y ago
Reminds me when I had to read barcodes from a USB-connected barcode scanner on a Mac. The manufacturer supplied a closed-source library which only supported PPC code and they told me that they lost the source code, so I couldn't easily
98.
▲
by
pilif
4y ago
or to the point, how is this different from just using `style=` attributes? One of the big reason to not do that in the past was in order to disconnect the presentation from the page structure, but if you have individual classes for each in
99.
▲
by
pilif
4y ago
Drag to your rightmost home screen and then drag one more time
100.
▲
by
pilif
4y ago
Oh. TIL. Thank you
101.
▲
by
pilif
4y ago
Some of the repos we work on date back to 2004 (going from CSV to Subversion, to git. Developers moving from mostly Windows to mostly Linux, to mostly macOS). If everybody was free to check in debris of whatever IDE and/or OS they were
102.
▲
by
pilif
4y ago
yes. it's in-fact there. But that's one more level of indirection from the "problem" at hand (because the global excludes file needs a config setting for it to even be considered, whereas .git/info/exclude is p
103.
▲
by
pilif
4y ago
> what prevents a intern to not have a correct exclusion there, and happily push a .ds file ? Our CI. And code review is what prevents .DS_Store to be added to .gitignore. And, again, I'm saying this as a purist with a developer te
104.
▲
by
pilif
4y ago
nitpick: As it’s a platform and machine specific thing, technically it shouldn’t be in .gitignore but in .git/info/exclude People working on Linux or Windows do not need to know about garbage your dev env leaves on your machine. I
105.
▲
by
pilif
4y ago
Traffic is probably the higher cost
106.
▲
by
pilif
4y ago
you scan the QR code with your android phone. That will cause your existing phone to be unregistered. What eSIM does is turn the physical smart card into a QR code which can be shown on a screen in addition to being printed on a piece of ph
107.
▲
by
pilif
4y ago
> it is more cumbersome to replace phones, as you have to move identities from phone to phone and get approvals by carriers and device makers instead of just replacing the physical SIM That really depends on the carrier. In my case, se
108.
▲
by
pilif
4y ago
> It does not burden a system to have it. any file format you support poses a significant attack surface, especially an old and creaky one whose parser you've written in the 90ies and ever touched.
109.
▲
by
pilif
4y ago
The user-specific parts of the registry are powered by files in the user‘s profile and ACLs do not normally allow other users to have access, so the same issue applies there too
110.
▲
by
pilif
4y ago
Especially ~/AppData (and ~/Library) is problematic because the person uninstalling the app might not be the person who was previously using the app. Reaching into another account‘s home directory to remove stuff feels very intrus
111.
▲
by
pilif
4y ago
I use a catch all alias that maps all local parts to one account (unless a specific account or alias already exists) Requires zero user action to make up an address
112.
▲
by
pilif
4y ago
Let me add a counter anecdote: from kindergarten through primary school and high school my life was hell thanks to bullying (being slightly neurodivergent in the 80ies and 90ies is a recipe for disaster) to the point of me nearly killing my
113.
▲
by
pilif
4y ago
and even then there should be no way to offer a completely insecure iteration count to a user because one of their devices is slow because the attacker's devices won't be. Even on slow devices, password managers can employ techniq
114.
▲
by
pilif
4y ago
so it would log other devices out, but not the device you're currently looking at. I think that's still an acceptable behavior compared to have people stuck with iterations counts of 500 or even 1 as we had seen in LastPass
115.
▲
by
pilif
4y ago
I have 524 passwords in my vault. That's a list large enough to require a big sheet of paper that's very inconvenient to carry around. I'm also changing passwords often enough such that keeping track of which password I chang
116.
▲
by
pilif
4y ago
> One issue I could see with that is that because it’s the encryption key it’s going to lock out all your “live” devices, so an explicit step is an easy opportunity to warn them. how so? The iteration count must be part of the non-encr
117.
▲
by
pilif
4y ago
Tangentially related: why would a password manager provide a configurable iteration count? This is a number whose purpose is fairly hard to understand for many people and yet it’s an important corner stone for password security, especially
118.
▲
by
pilif
4y ago
DNS can be MitMd. crt.sh would be in a position to get all your browsing history. The local thing would work, but of course only for local hosts. It would not be worse than using plain http and my personal opinion is that visiting a plain h
119.
▲
by
pilif
4y ago
> there should be a way to use TLS with a self-signed cert to say hey, I'm not making any strong claims of identity or privacy here, I just want some modicum of obfuscation of the traffic. How would a browser know whether a site p
120.
▲
by
pilif
4y ago
I said "can be made to persist" and I meant, yes, that the malware could be compromising the firmware. And by "can" I implied that not all of it does, but the possibility of it doing it does exist. Secure boot is indeed
More ›