Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
scient
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
scient
7y ago
Even then the external services will still require first and second factors of authentication. If your workstation is compromised on an ongoing basis, then nothing matters. If its an one-time even, 2FA will protect the external services sti
32.
▲
by
scient
7y ago
My anecdotal opinion - pure tech people don't usually make good founders because they are too realistic and grounded. A company needs a visionary, someone who is at times even blinded by their optimism and vision. You pair that visiona
33.
▲
by
scient
7y ago
Uber is literally having the same business model of subsidizing rides, which loses them a lot of money. This is not even tied to simply being competitive with Lyft - its also to incentivize users to choose them over taxis. You really thing
34.
▲
by
scient
7y ago
Quite the feat to build a site this slow...
35.
▲
by
scient
7y ago
Its absolutely ridiculous. Its now to a point where 15-18% is expected even for bad service, and 25% and up for good services. There is no way I'm paying an extra quarter of my bill in tips because the restaurant owner is too cheap and
36.
▲
by
scient
7y ago
Not a good look questioning people who know what they are doing by promoting a service apparently built by someone who does NOT know what they are doing.
37.
▲
by
scient
7y ago
Data breaches are never a question of "if", but "when".
38.
▲
by
scient
7y ago
Preach. Them changing the rules and overriding the usage of this attribute is ridiculously stupid in the first place. HTML attributes are there for a reason, developers are supposed to be able to use them and they are supposed to work as ex
39.
▲
by
scient
7y ago
I think the statement you make about "something you know" always being more secure is not nearly as clear cut as you present it. A combination of "something you know" and "something you have" is always going to
40.
▲
by
scient
7y ago
How is it not? Consent to releasing information should be supported on a granular on-demand level. If I initially only need name, I'll ask the user to consent for that. If I later on need an email (lets say for some additional function
41.
▲
by
scient
7y ago
Its only "popular" because for a long time it was the only choice in Europe pretty much. In several countries it still is. It also was total garbage developer friendliness wise ~5 years ago.
42.
▲
by
scient
7y ago
So you are blaming them for your own fault?
43.
▲
by
scient
7y ago
And finding that place also means you will never be anything more than that. Thats what always strikes me about these complaints about having to do a little extra, or stuff thats not directly in your job description etc. And then complain a
44.
▲
by
scient
7y ago
CTO sets the technical and architectural vision, also security and toolchain being used etc. You can think of it as CTO is leading the technical vision, while a VP of E is helping out managing the team on a daily basis, organizing the produ
45.
▲
by
scient
7y ago
You should look into Estonian ID card program. Its exactly what should be done.
46.
▲
by
scient
7y ago
I think you are the one lacking perspective here. The same way you are trying to make a point, I can make a counter point. The person making $20 is considered comparatively rich by someone making less than a dollar a day in some underdevelo
47.
▲
by
scient
7y ago
And what would the lawsuit be based on? Stealing documentation for how OAuth 2.0 works?
48.
▲
by
scient
7y ago
Its not even their proprietary API, its OAuth endpoints.
49.
▲
by
scient
7y ago
Its OAuth documentation - its a very well described standard protocol. Most of the OAuth documentation looks and reads exactly like this. The only "smoking gun" is the "random" value used for the state parameter, which s
50.
▲
by
scient
8y ago
But muh decentralization! /s In reality most of the exchanges and sites dealing with crypto were (and probably still are) built by absolute amateurs with no checks and balances on their apps from a security perspective. Its scary as he
51.
▲
by
scient
8y ago
One can only hope this would make it to the US as well. The problem largely seems to be banks being ancient behemoths in terms of technology, and introducing APIs like this poses a significant risk from security and policy perspective. Plus
52.
▲
by
scient
8y ago
I hope not, because its such a shitshow. You literally give your bank credentials to a third party who then logs in to your account and scrapes info off of it - info that you have no control over. Capital One was smart enough to block them
53.
▲
by
scient
8y ago
How much does it hurt?
54.
▲
by
scient
8y ago
Yeah, KYC/AML is totally bad because of trying to actually prevent money being funnelled into crime organization etc. This is why I cant stand ignorant crypto-fans.
55.
▲
by
scient
8y ago
OAuth access tokens? The difference being that JWTs contain information directly, as well as an access token to hit any APIs, while an access token contains no information on its own - thus solving the revocation issue. Now I don't thi
56.
▲
by
scient
8y ago
Except cookies are quite literally perfect for that - set the expiration to 30 minutes from issuance and it will automatically be expired with inactivity. Or bumped on activity.
57.
▲
by
scient
8y ago
And why would someone put $50m into a highly volatile, unchecked tech, where mediators are mostly known because of their security problems and breaches?
58.
▲
by
scient
8y ago
So you're saying cant read existing code in order to understand it, or you just wont? Not arguing that self-documenting code is a good excuse for not documenting anything, but if you have to write an essay to go with your code, maybe t
59.
▲
by
scient
8y ago
I've done major upgrades from 3.2 to 4.1/4.2, and from there to 5.1 followed by 5.2 - the only time we had to put in a little work was when moving from 3 to 4. When moving from 4 to 5, we relied on simple smoke tests and unit test
60.
▲
by
scient
8y ago
BLE solutions are going to work much better for mobile devices than NFC I think. Google already supports it for their apps via SmartLock and Advanced Protection on both major mobile platforms. Its the browsers, and namely Safari, thats bein
More ›