Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
problems
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
50 ms
·
481.
▲
by
problems
9y ago
Wouldn't that value mostly be based off popularity? Chrome is vastly more popular than Firefox - therefore it's less valuable to exploit a smaller number of users.
482.
▲
by
problems
9y ago
It works just fine if you require an OCSP response and hardfail. Soft-failing is for usability and it's the cause of the problem. Yes, must-staple is the optimal solution, but OCSP required is the best available today. Look at some of
483.
▲
by
problems
9y ago
> Without widespread adoption of a must-staple extension, OCSP is cosmetic. The decision to disable it didn't come from simplicity fascists; it came from people like Adam Langley. AGL isn't right about everything, but if you ta
484.
▲
by
problems
9y ago
Firefox - they're years ahead on this sort of stuff. Their about:config gives you immense power to configure your browser to behave exactly how you want it to. Unlike any other browser around really. The flexibility this brings you in
485.
▲
by
problems
9y ago
The CA tells you what response to give on that new account you signed up.
486.
▲
by
problems
9y ago
I think he's actually right about the attacker being near you most of the time - compromising a data center is much harder than compromising a LAN most of the time. However, he completely ignores the fact that some users may be sophist
487.
▲
by
problems
9y ago
There's a big difference in attitudes between browsers here. Take OCSP for example - Chrome disabled OCSP because in optional mode it wasn't a perfect solution and they didn't want to enable it in required mode because that c
488.
▲
by
problems
9y ago
I'm reminded of a Torvalds quote from about a decade ago: > This 'users are idiots, and are confused by functionality' mentality of Gnome is a disease. If you think your users are idiots, only idiots will use it.
489.
▲
by
problems
9y ago
> (snoozing, send later, reminders, open tracking, etc.) None of that has any appeal to me, I'd much rather a mail system which doesn't require using someone else's server. Maybe this isn't a priority for other people
490.
▲
by
problems
9y ago
I feel the same way personally. I feel like I see tons of people complaining about it, but it's just what I want out of a mail client. The UI is a great, the GPG integration is great with enigmail, it's a very polished product. No
491.
▲
by
problems
9y ago
One of my biggest asks from todo apps like this is that my todos be kept private. I need encrypted sync so that the authors can't just go and read them... so I'm basically left with todotxt and emacs org-mode as options and then u
492.
▲
by
problems
9y ago
Interesting, what I'd heard from a colleague is that asan wasn't worth using since it couldn't catch uninitialized memory and stuff. Thanks, I'll have to look into it more.
493.
▲
by
problems
9y ago
How does asan compare with Valgrind? Valgrind is a serious savior for me sometimes, it's able to catch leaks, access violations, use of uninitialized memory, use-after-frees (and it can tell you where it was free'd), data races, e
494.
▲
by
problems
9y ago
> But I do wonder whether some languages have debugging problems that require "keeping more state" to solve them than others, such that the developers doing debugging in those languages would rather forge ahead and finish, than
495.
▲
by
problems
9y ago
Correct me if I'm wrong, but all the build and deployment steps are being managed via Amazon-specific tools directly, which want you only to use Amazon-specific services, no? That sounds like lock-in to me. It's pretty trivial to
496.
▲
by
problems
9y ago
Yeah, the key is to start out writing shit code, but to skim over and get a feel for when you might use the more advanced concepts so that when the time comes that you think you might be able to apply something you know what to look for qui
497.
▲
by
problems
9y ago
This is why I prefer the Rust and modern C++ approach more personally. Put everything on the stack by default for fast, easy access, it automatically gets destroyed when you leave the scope. Then use reference counted shared pointers or oth
498.
▲
by
problems
9y ago
I for one just don't give a shit and will completely admit I just eat whatever's cheap and tasty. I doubt many people will admit this, but I bet there are many in the same boat. If we can get lab-grown meat below the cost and/
499.
▲
by
problems
9y ago
It's not - they just stopped developing the desktop one because now they're all about web-only. It sucks too because we use the desktop one all the time at work - though we're slowly replacing it with custom Cesium-based stuf
500.
▲
by
problems
9y ago
That's an excellent question - especially given that you can essentially use it as a "functionally enhanced java" as it's not a hard-FP language like Haskell. I'd love to know - maybe it's a question of staffin
501.
▲
by
problems
9y ago
Not really the kind of thing I'm talking about - I mean users-vs-publishers. Chrome and Google tend to favor publishers - being an ad agency and all.
502.
▲
by
problems
9y ago
For hostkeys on DO you can probably get a script to run that'll request a signed certificate from a server you own. The signed cert can be validated fully by clients. Or go with a convergence style system and probe it from multiple loc
503.
▲
by
problems
9y ago
Did they actually remove this? Probably the only pro-user thing I've heard of chrome doing in its entire lifetime.
504.
▲
by
problems
9y ago
> Nintendo has every right to do limited runs on some Amiibos. They have every right to do limited runs, I have every right to do everything in my power to bypass that. I own the console, it's processor and memory after all. This is
505.
▲
by
problems
9y ago
By worm level I mean it's a remote code execution attack which can be propagated over the internet. Someone can write a little piece of code that scans for random hosts, runs the attack and installs itself on the target system which th
506.
▲
by
problems
9y ago
This would make heartbleed and similar look like childsplay - this is a worm level attack if it's as bad as the title sounds. But given that redhat has so far labelled themselves not vulnerable, I'm guessing there's more to i
507.
▲
by
problems
9y ago
Honestly, I'm glad they did it - it proves the risk these types of devices pose. Better people stop using it over shit like this than worse...
508.
▲
by
problems
9y ago
I think the point is that if something else took over as the king search engine, they'd likely be able to get traffic there too.
509.
▲
by
problems
9y ago
Hmm, maybe I'm used to different games, but typically there are some nickel-and-dime type purchases with premium money that you can pretty much extract the full value from one way or another. Clash of Clans has a speed boost, World of
510.
▲
by
problems
9y ago
I did not suggest this justifies anything - in fact I said this was severely mishandled. I merely tried to explain the slight against overbooking some people seem to have - which is mostly unrelated entirely, but that's why I didn'
More ›