Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rdj
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
rdj
17y ago
The rapid growth in his follower numbers is certainly impressive, but I'm more curious about who he chooses to follow. Looking through the list, it was mostly foundations. What struck me as odd was that he followed Ashton Kutcher and Ashl
62.
▲
by
rdj
17y ago
I'm curious about the video monitoring on the machines that have been tampered with. What do these security cameras normally see? Do the perps block the camera so it can't see them installing their hardware? If so, couldn't some program be
63.
▲
by
rdj
17y ago
That seems like a reasonable expectation. I guess I need to look at this article and scanner a little closer before I comment on what this particular tool does (or doesn't).
64.
▲
by
rdj
17y ago
Scanners cannot look for every possible bug. They can however, look for known bugs. And that's what most attempt to accomplish. In a nutshell: The scanner looks for known files (thus you see a lot of 404's). If it finds these files, it ma
65.
▲
Top PNG Optimizers Don’t Use zlib
(zoompf.com)
3 points
by
rdj
17y ago
|
0 comments
66.
▲
by
rdj
17y ago
Would it be cheaper to buy noise-canceling headphones?
67.
▲
by
rdj
17y ago
Cool. Another part of my experiment complete with this publication: how to get press without really trying. (but I should probably save that for another post)
68.
▲
by
rdj
17y ago
and our paths cross again :). My effort is http://10balloons.com and http://twitter.com/10balloons . I'm curious though: as I've worked through this challenge, my focus has been drawn to post-contest plans, using this contest as a short
69.
▲
by
rdj
17y ago
I have no problem with your disagreement and I certainly appreciate that you took the time to say something. The issue you highlighted is interesting. We have someone who has been accused of a crime, but not convicted yet. Is it right or wr
70.
▲
by
rdj
17y ago
The auto-change is actually in the code, but the first beta-testers complained. Sounds like I may need to make it configurable, or redesign the was transitions happen. Your ideas about "just one more" and updated percentages sound interesti
71.
▲
My First Duck
1 points
by
rdj
17y ago
|
4 comments
72.
▲
by
rdj
17y ago
First, you need to define a few things: - very small (10's, hundreds, etc) - focused (girls who wear pink?) - successfully I've always assumed folks wrote facebook apps to grab the eyeballs of the 16 million users and ride the network effec
73.
▲
by
rdj
17y ago
If I recall correctly, and am seeing what I think I see in video #2, the purpose of the challenge was to lift off from one pad, move a certain distance and land safely on a different pad.
74.
▲
by
rdj
17y ago
http://www.kaymont.com/pages/sounding-balloons.cfm
75.
▲
by
rdj
17y ago
You could assume PG would be too busy to respond to a password reset, much like you could assume a password reset function is a basic necessity of a web site. However, I personally, have proven at-least one of these assumptions wrong.
76.
▲
by
rdj
17y ago
I'm not sure this is a metric a web developer should care about. I always assumed the website would deliver the same X bytes of data, at the same level of performance for each request, regardless of source location. If this, or any other te
77.
▲
by
rdj
17y ago
I don't understand why you would have a problem with this. The javascript that makes this happen, does run in the browser, on your desktop, or as you put it, the application level. Regardless of how your password is displayed when typed (ei
78.
▲
by
rdj
17y ago
The iphone does have a connection point, and if I remember correctly, they are opening it up to third parties. So, if the phone can take blood pressure and insulin readings, I'm guessing it will only be a matter of time before it also accep
79.
▲
by
rdj
17y ago
You are correct that the end user controls what is ultimately sent to MS (or whomever is probing). However, if they are doing something like plugin enumeration or using a java applet to go a little deeper, you then have to know what the req
80.
▲
by
rdj
17y ago
This is going to be a popular idea but I don't think it will work if MS has their act together. You can profile a browser based on things like plugins. Maybe there is a plugin that only works in IE8 and is used for nothing but real browser
81.
▲
by
rdj
17y ago
fwiw, he confirmed the deposit on twitter: http://twitter.com/XSSExploits/status/2186157907
82.
▲
by
rdj
17y ago
Believe it or not, I originally purchased the iPhone for the ease of making calls, placing people on hold to answer the other caller, merging multiple callers and using the speakerphone option. It does not get much easier than the one butto
83.
▲
by
rdj
17y ago
Nice looking, yes. Clue, not so much. It could be argued that they: - shouldn't be sitting with an open root shell - should use audited/logged sudo for root stuffs - use the full path to 'ls' but I probably shouldn't get bogged down discuss
84.
▲
by
rdj
17y ago
the only problem with this piece is, I have yet to find the mythical "real domain that you can own". I've leased/rented/licensed/used quite a few domains over the years, but they each come with some sort of expiration and a threat that some
85.
▲
by
rdj
17y ago
...that should read: "hardly seems practical"
86.
▲
ICSI released a tool to "Debug your Internet."
(netalyzr.icsi.berkeley.edu)
2 points
by
rdj
17y ago
|
0 comments
87.
▲
by
rdj
17y ago
Maybe the coffee hasn't kicked in for me yet, but this whole project seems to be missing something. First, I find it odd that a visiting lecturer in visual arts would have been a consultant for disaster recovery and development in one of th
88.
▲
by
rdj
17y ago
Looks like we may never know. Disclosure is not permitted per the official rules http://www.strongwebmail.com/secure/email/contests/hack/tc
89.
▲
by
rdj
17y ago
I hope the rules of the contest allow disclosure. Until then, I only have this tweet to reference from June 3rd: http://twitter.com/XSSExploits/status/2019746890 "alternatively- add a device to the auth list and wala ;)" [edit: I should n
90.
▲
by
rdj
17y ago
Since everyone is venturing a guess, here's mine: They used XSS (cross site scripting) to send a mail to the target. When the email is viewed a CSRF (cross site request forgery) is executed to add a new device (phone) to the authenticated d
More ›