Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ppierald
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
ppierald
13y ago
I hope this is a troll and if it is not, you should read through your contract, look for a breach clause, and exercise that clause. Otherwise, you should eat the cost of getting a new security auditor. A good relationship with a qualified a
62.
▲
by
ppierald
13y ago
Always happy to see new input sanitization libraries, but most don't deal with the especially difficult problem of safe subsets of HTML. i.e. How to accept html from an untrusted source, apply whitelisted tag/attribute combination
63.
▲
by
ppierald
13y ago
It's not Hedy. It's Hedley!
64.
▲
by
ppierald
13y ago
gperf - https://www.gnu.org/software/gperf/ This is a "perfect" application of a "perfect hash" generator.
65.
▲
by
ppierald
13y ago
UTF-8 wins for the internet because most of the payload of an HTTP request/response is 7-bit ascii characters, so it is the most efficient even in languages where UTF-16 may be more efficient because of the complexity of their characte
66.
▲
by
ppierald
13y ago
I nominate you for HN Comment of the Year!
67.
▲
by
ppierald
13y ago
You are really protecting against local, non-root access to your box, especially when that user is the nginx child process. This can manifest itself in a number of ways, but most roads lead back to improper input sanitization and/or us
68.
▲
by
ppierald
13y ago
The threats to passwords are generally two-fold: 1) SQLi leaking the contents of your database to the public. 2) Malicious insiders with access. Blocking SQLi should be every web developer's first priority, not debating the efficacy of
69.
▲
Secure ID Reclaimation: Require-Recipient-Valid-Since
(developer.yahoo.com)
4 points
by
ppierald
13y ago
|
0 comments
70.
▲
by
ppierald
13y ago
Yes. https://www.duosecurity.com/sla
71.
▲
by
ppierald
13y ago
Nope. Sorry if it came across that way. I am just a happy customer that loves their product. Others have mentioned Duo on this thread (and other HN threads too...) Great product, great support, reasonable price.
72.
▲
by
ppierald
13y ago
I would highly recommend using DuoSecurity for all your 2-Factor Authentication needs. Their solution is very slick, easy to use, and intuitive. Duo has options for every conceivable situation a user might get themselves into including Push
73.
▲
by
ppierald
13y ago
The GPGTools team had a paid version (beta) out for months. I felt the functionality was worth the minor investment and also ensured that there was some path forward for future revs.
74.
▲
by
ppierald
14y ago
The concept of putting <script src=> on my login page skeevs me out more than a little bit. This is a major security hole that won't be patched until there is native support in the browser.
75.
▲
by
ppierald
14y ago
Knowing that all user-data is required to have a user-credential, use this fact when issuing the urls to the browser that instantiate this request, make these urls specific to the user and cryptographically bound to their authenticated stat
76.
▲
Two Factor Authentication for Twitter
(blog.duosecurity.com)
2 points
by
ppierald
14y ago
|
0 comments
77.
▲
by
ppierald
14y ago
I would recommend against using sudo su -, esp if you have <user> ALL=(ALL) NOPASSWD: ALL or such constructs in your /etc/sudoers file that exempt password requirements from executing sudo commands. 1. su gives you a root shell. Pri
78.
▲
by
ppierald
14y ago
A little heads up to the Yahoo Security team probably would have been appreciated!
79.
▲
by
ppierald
14y ago
I have to note that the length and strength of your AES key is no different than the complexity of your password. Once either is compromised, then you are totally exposed. So your attacker will take the path of least resistance. He can eith
80.
▲
by
ppierald
14y ago
No Terms of Service or Privacy Policy. I can imagine having a list of email addresses with people interested in getting coding interviews could be interesting to the right people with enough money.
81.
▲
by
ppierald
14y ago
"corporate standards" are at least partially good. They should be reasonable though and adaptive to the times. Having a set of acceptable programming languages, frameworks, etc. ensures that the company understands the risks of those choice