Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pmylund
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
pmylund
13y ago
Disclosure: I work for Evidon. Evidon provides reports to different types of companies that give them information about what trackers appear where, how prevalent they are and/or whether they're in compliance with privacy laws. Hig
2.
▲
by
pmylund
14y ago
And here's why: http://stackoverflow.com/a/5411601/620239 . Forgot to change that first occurrence after pasting it in. "Oh, it works. I'm done."
3.
▲
by
pmylund
14y ago
And Go lets you do that. You just return the error. Try writing a few things in Go. I very much doubt you'll respond like this afterwards.
4.
▲
by
pmylund
14y ago
Nice save.
5.
▲
by
pmylund
14y ago
Famous last words :)
6.
▲
by
pmylund
14y ago
Thanks for this example. I wasn't trying to be condescending when I asked how it was significant. I really didn't understand what you meant. I've added a note to the article.
7.
▲
by
pmylund
14y ago
Nm. Got it.
8.
▲
by
pmylund
14y ago
It's not that the size doesn't matter; it's just that it's not as significant. It becomes very, very hard to compute rainbow tables after just a few random bytes. No matter how long the salt is, it doesn't do anything to prevent somebody fr
9.
▲
by
pmylund
14y ago
How does this matter given a proper avalanche effect?
10.
▲
by
pmylund
14y ago
I agree, but "outsourcing" includes using libraries written by people who know what they're doing. (And not using libraries written by people who know what they're doing, but which are the wrong tools for the job.)
11.
▲
by
pmylund
14y ago
Sure, but I try to not make any assumptions without being boring. I think the goto-link at the beginning works fairly well.
12.
▲
by
pmylund
14y ago
OpenID and OAuth really did a lot, but there's just nothing called "don't use passwords." Fingerprint readers suck. Anything biometric that doesn't suck costs too much, and 99% of people don't have them. A good KDF is not bad in comparison
13.
▲
by
pmylund
14y ago
So something like a HMAC digest generated using a pepper stored in the source code/binary or on disk before passing it to bcrypt/scrypt? :) This only really protects against SQL injection attacks, though/when there is actually a separation
14.
▲
by
pmylund
14y ago
You're right. That was an unfortunate choice of words.
15.
▲
by
pmylund
14y ago
I'm not sure I agree that it would matter, but, either way, using a constant-time equality function might have given readers the impression that my code was safe to use. It isn't. That was never the intention. One of my main points was that
16.
▲
by
pmylund
14y ago
So much for white-boarding it. Fixed, thanks.
17.
▲
by
pmylund
14y ago
FWIW I included scrypt :) I personally agree that "Use bcrypt." should become "Use scrypt." soon. My main gripe is that there is far less library support for it, at least for now.
18.
▲
by
pmylund
14y ago
Although it's not that much if you're using a long hash, iterating a hash function causes you to lose entropy. The implementation in the article is basically PBKDF (1). PBKDF2/HMAC avoids this by making an "outer" and "inner" layer.
19.
▲
by
pmylund
14y ago
I agree there are a ton of articles saying "Use bcrypt." After Coda's post ( http://codahale.com/how-to-safely-store-a-password/ ) it's almost become a meme. I don't, however, think that the people who say "Use bcrypt!" tend to explain why
20.
▲
go-cache: fast, in-memory key:value store with expiration times for Go
(github.com)
3 points
by
pmylund
15y ago
|
0 comments
21.
▲
You Are Here
(youtube.com)
1 points
by
pmylund
15y ago
|
0 comments
22.
▲
Big Bad Congressmen Afraid of the Dark
(patrickmylund.com)
8 points
by
pmylund
15y ago
|
3 comments
23.
▲
Senka - Portable SSH server for connection tunneling and firewall traversal
(patrickmylund.com)
7 points
by
pmylund
15y ago
|
0 comments
24.
▲
by
pmylund
15y ago
Indeed. Keep in mind it's the top, so these are the people you really expect to keep something like that hidden. I promise you the stats are much worse further down the list, or if you do the same, but for a specific country's TLD.
25.
▲
by
pmylund
15y ago
I think there are far more nameservers allowing AXFR than you think. Write a little app that attempts a zone transfer for the top 1000 of the Alexa list ( http://s3.amazonaws.com/alexa-static/top-1m.csv.zip ) and see for yourself. (Note to
26.
▲
by
pmylund
15y ago
So you agree that disabling AXFR, if AXFR is enabled, is a good idea? Could you explain why you think wide-open-dev-machine.customer.com is NOT safer without AXFR (assuming it blocks robots, and the web server only serves the site for "wide
27.
▲
by
pmylund
15y ago
If a company with a large and complex web property, e.g. Microsoft.com or Google.com, asked you if it mattered whether they allow DNS AXFR, what would your answer be?
28.
▲
by
pmylund
15y ago
Right. The analogy isn't bulletproof, but in conclusion it's pretty dumb to share information that could conceivably be used to extract some information or otherwise get an advantage when there's no reason to.
29.
▲
by
pmylund
15y ago
Good point. Let's say, for the sake of argument, that each of them have their own salt :)
30.
▲
by
pmylund
15y ago
It was a kind of tongue-in-cheek comment to demonstrate the irony of "exposing it doesn't matter". I should probably have been more clear that I wasn't actually serious.
More ›