Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
samuellb
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
samuellb
11y ago
It seems to be an implementation of a subset of the Linux kernel ABI (binary interface to applications) on top of the NT kernel. It's most likely written from scratch, similar to WINE or FreeBSD's Linux ABI, and in that case there
32.
▲
by
samuellb
11y ago
I actually prefer undefined behavior to defined but not necessarily desirable behavior, such as values defaulting to zero/NULL or integer rollover. That's IMHO only hiding the symptoms (e.g. crashes) of the problems (e.g. logic bu
33.
▲
by
samuellb
11y ago
Mobile version that doesn't require Javascript: http://www.pranav-venkat.com/2016/03/command-injection-which...
34.
▲
by
samuellb
11y ago
I'd like to see some real standardized cross-browser interface between the browser and external devices (or applications on the same device). Previously there was NPAPI which did only the latter, and if you only need input to your de
35.
▲
by
samuellb
11y ago
Now that you're editing your comment while I'm writing this, it's a bit hard to comment. I agree with you to 100% that we should have anonymity online, and that the media supporting data breaches of personal data is a bad thi
36.
▲
by
samuellb
11y ago
That's true, but the format of signed tags will need to change in one way or another. What we could do is to have a "shadow" tree which is built using a stronger hash algorithm (e.g. SHA256), and which is used for signing his
37.
▲
by
samuellb
11y ago
There's no completely secure way, except for getting the public key directly from the developer over a trusted channel (or in person). And even that won't protect you in case the developer's keys gets compromised. But there a
38.
▲
by
samuellb
11y ago
It's not at the time of installation, but prior to updates the package management system will check signatures of the packages. (And it will only accept packages signed with your key, so the attack used against Transmission wouldn&#x
39.
▲
by
samuellb
11y ago
Yes, but it also stops sending you normal e-mail notifications, which is IMHO only annoying because I prefer to use my e-mail client to read messages, invites, etc.
40.
▲
by
samuellb
11y ago
Cookies (over SSL) can work if you only have one site, to store a session id or such. Since cookies could be replayed, they can't be used with multiple sites (that would be analogous to using the same password on multiple sites). Also,
41.
▲
by
samuellb
11y ago
We use a very similar system where I work, except that we have one "extra" person on-call in case the first one gets sick, has a hard disk failure or likewise, or just needs extra help for some reason. Both people are paid a fixed
42.
▲
by
samuellb
11y ago
No, it's for consumer subscriptions only, and commercial use is prohibited. On the same ISP, commercial users have to pay depending on IP address block size and justify how they will use the addresses etc.
43.
▲
by
samuellb
11y ago
Doing blacklisting of IPv6 addresses is actually quite hard, because you can't know how network owners lay out their addresses. Some networks (especially VPS providers) will use one /64 (or so) per datacenter, while other will giv
44.
▲
by
samuellb
11y ago
Yes the major Swedish ISPs also say the same thing, except for the "foresight" part. One of our ISPs is even giving out "unlimited" public IPv4 addresses on their consumer subscriptions (previously they had a limit on 5
45.
▲
by
samuellb
11y ago
I don't think Gmail would be able to block "own" email servers, because how would you tell them apart from company servers or web sites that send out confirmation e-mails or "forgot password" e-mails? They do howeve
46.
▲
by
samuellb
11y ago
I use PayPal for donations to an F/OSS project (which are subject to VAT in my country). This is how I "solved" the VATMOSS problem: 1. Generate different PayPal buttons for different countries (depending on IP). The country
47.
▲
by
samuellb
11y ago
"svn praise" seems to be simply an alias for "svn blame". Try "svn praise --help"
48.
▲
by
samuellb
11y ago
But you can still buy some types of appliances without circuit boards (and with minimal complexity in general). When my fridge/freezer broke down, I bought one with a mechanical thermostat and no circuit board. Slightly higher power co
49.
▲
by
samuellb
11y ago
Most people except for me and a colleague seemed to think he was honest, though.
50.
▲
by
samuellb
11y ago
Perhaps, and I had this in mind when I talked to him. But it was also non-technical stuff. For instance, one time he said he was on vacation for a month, but then I talked to his friend the day after who insisted that he was not on vacation
51.
▲
by
samuellb
11y ago
I haven't heard any of those abbreviations either. And what is Tesla doing in "NATU"? I thought it was in some states in the US where Tesla's business model is forbidden (i.e. selling directly to the customer). I don
52.
▲
by
samuellb
11y ago
Not sure if trying to "trap" the liar is always the right way to go. Once I had to work with a freelance web master and we were trying to cancel his contract and make him transfer the domain name to us (an association I was workin
53.
▲
by
samuellb
11y ago
This makes me think that there could be similar bugs in the browser, when it JIT-compiles or optimizes Javascript code. That could be used to take control of the whole browser/OS if used in an add-on/extension (given that it has s
54.
▲
by
samuellb
11y ago
In the meantime I can recommend the RequestPolicy[1] add-on for Firefox. It's not exactly what you're asking for; it blocks cross-domain requests entirely instead. Since it uses a whitelist you'll have to add exceptions for t
55.
▲
by
samuellb
11y ago
Mostly security, privacy and usability related stuff. Here's a quite long list: * Browser written in a way that prevents most exploits. * Built-in Javascript and cross-domain request blocking. * Single-process sandboxed browser where o
56.
▲
by
samuellb
11y ago
Some Unicode characters can also move the cursor in strange ways. I think most of them only work in GUI programs, though. (See the list of bad strings above)
57.
▲
by
samuellb
11y ago
I think the main reason we aren't moving away from C and C++ is interopability, and not performance. I can come up with a number of benefits of C in this regard: 1) Ability to use existing libraries directly (just #include and add to L
58.
▲
by
samuellb
11y ago
I think there can still be "emulation". For instance, when I was in elementary school I thought it was hard to remember the full multiplication table. Instead of remembering 7×9 I would think 7×10-7 = 63. That's IMHO a type o
59.
▲
by
samuellb
11y ago
more or less a dupe of https://news.ycombinator.com/item?id=9954686
60.
▲
by
samuellb
11y ago
>GNU/Linux distros are free open source software, and don't suffer from these sorts of update problems Agreed, but I would go further and say that the _PC platform_ doesn't suffer from such problems. You can buy a computer
More ›