Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sehrope
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
17 ms
·
151.
▲
by
sehrope
13y ago
If you can be legally compelled to provide what's in your mind (password) and what's in your pocket (2FA device) then what's to stop them from compelling you to instruct your legal counsel (or whoever else is providing your &
152.
▲
by
sehrope
13y ago
Spoofing it in a client's browser is not possible but it's trivial to spoof referrer headers (or anything else) from a stand alone program. Beyond checking for referrer headers the server should give the client a signed token (ret
153.
▲
by
sehrope
13y ago
There was a post a couple weeks ago about an nginx module atop PosgreSQL providing a REST interface[1]. This is a similar idea but for Datomic and using a REST server that comes bundled with it. Compared to the PG ngnix module, this one has
154.
▲
by
sehrope
13y ago
It doesn't have to be voluntary. If I have a list of all the MAC addresses/timestamps and can cross reference that against a different known list of people times (ex: credit card transactions, rewards card, even face recognition)
155.
▲
by
sehrope
13y ago
The verbosity of the XML pom is the problem. Alternative syntax using the same coordinate system are great and much easier on the eyes. The real value in maven (I think) is having that clean dependency chain and it works great. XML is what
156.
▲
by
sehrope
13y ago
If the only purpose is for IP blacklists (bans, dos, etc), then doing 12 rounds of bcrypt would be counter productive. It'd be a lot of CPU usage on your end. Especially if its done for every request. A better approach would be somet
157.
▲
by
sehrope
13y ago
I use Linux exclusively on my desktop and have had a bunch of laptops over the years with Linux installed (mainly Debian based). It's never been quite pleasant though. I work primarily off my desktop so I wouldn't mind it that muc
158.
▲
How to import CSV files with JackDB
(blog.jackdb.com)
3 points
by
sehrope
13y ago
|
0 comments
159.
▲
by
sehrope
13y ago
> I understand that you can have a Vagrant provider for VMWare and VirtualBox, but what does it mean for you to have a DigitalOcean provider for Vagrant? Instead of spinning up a VM on your local machine it spins up a new droplet in your
160.
▲
by
sehrope
13y ago
I used to think that TOTP was the way to go too but it can be improved. I really like having a public/private key pair vs a static shared secret. It's just objectively better. With this setup a rogue agent working at company X c
161.
▲
by
sehrope
13y ago
> That is one of the nice things about SMS 2-factor auth, the backup authentication method (lost phone) is on the wireless company instead of you. This is one of the terrible things about SMS 2-factor auth! In exchange for having them
162.
▲
by
sehrope
13y ago
Looks cool but I'd like something like TOTP where anyone can implement the client side of it. Since everything is done with public/private key pairs it's possible to have a setup with a central party acting as an opaque forwa
163.
▲
by
sehrope
13y ago
If you have live server access yes (you can do whatever you want at that point). But if you just have a data breach then no. A data breach of the public keys wouldn't require them to reset two-factor auth for the impacted users. An att
164.
▲
by
sehrope
13y ago
With this new setup the carrier channel is irrelevant. It could even be done in plain text (eg. no SSL). Since the request is being signed using a pre shared public/private key pair it can't be man in the middled or spoofed. At be
165.
▲
by
sehrope
13y ago
> The new two-factor system works like this. A user enrolls using the mobile app, which generates a 2048-bit RSA keypair. The private key lives on the phone itself, and the public key is uploaded to Twitter’s server. > When Twitter re
166.
▲
by
sehrope
13y ago
I don't think so. Here's the snippet from the linked PDF[1]: > DEFLATE [2] (the basis for gzip) takes advantage of repeated strings to shrink the compressed payload, an attacker can use the the reflected URL parameter to guess
167.
▲
by
sehrope
13y ago
A server that only serves static files. It doesn't enable the use of dynamic content like CGI[1]. Compare this to something like Apache or nginx. Both can serve static files but also support a number of ways of either directly running
168.
▲
by
sehrope
13y ago
... and especially not if you're suggesting run it as root. You should never run anything as root unless you know what it is. Having it over HTTP vs HTTPS makes things really bad though.
169.
▲
by
sehrope
13y ago
Not necessarily. The token can be used to simply verify that the request came from a legit page and not cross site request. The encrypted CSRF need only be verified by the server to see if it's not expired. The server can store the exp
170.
▲
by
sehrope
13y ago
How about having the CSRF token change with each request? If it's encrypted/signed by the server for each request with a random IV then it would be different in each request. It would be a bit more processing on the server (decryp
171.
▲
by
sehrope
13y ago
You should check us out[1]. We're haven't quite got to the full ETL stage as we've focused on individual databases first. If you've got a decent imagination though then you can figure out what we're trying to get to
172.
▲
by
sehrope
13y ago
Yes but a non trivial amount of the app would need to be obfuscated. You wouldn't be able to just obfuscate the license validation code as the caller could then be modified to skip over that function call. If this really is as slow as
173.
▲
by
sehrope
13y ago
There was some slight formatting issues but overall it worked well. It's nice to have the additional context/detail with the slides kind of like what you'd get if someone presented it live. The node.js side project is a RESTf
174.
▲
by
sehrope
13y ago
Netcat is indeed very versatile and useful but most of the time it's used improperly when used as a server (-l mode). Unless you're doing basic network diagnostics (ex: testing if firewall ports are open) you're better off us
175.
▲
by
sehrope
13y ago
He's talking about underscore.js which coincidentally was created by the same guy, Jeremy Ashkenas, that created CoffeeScript (and Backbone.js). Underscore actually is still useful with CS. You just don't need it as often as a lot
176.
▲
by
sehrope
13y ago
This is a fantastic slide deck. The per slide comments below are great too. Particularly on an iPhone as you read them simultaneously. We've been using CoffeeScript for a bit over a year now and never looked back. All of our front end
177.
▲
by
sehrope
13y ago
> Your page will poll /transactions/<id> until the transaction ends in either success or failure. If you do something like this you need to make sure to verify that the user actually created the transaction. Blindly loadi
178.
▲
by
sehrope
13y ago
This is nice. I particularly like the addition of the Vagrant config. These days any app example that requires external resources should include them. It makes things so much easier for someone to go from read, to download, to run. One thin
179.
▲
by
sehrope
13y ago
They should switch to a better cipher suite to enable PFS[1] (ex: ECDHE-RSA-AES128-GCM-SHA256). Right now they're using RC4-SHA: $ echo | openssl s_client -debug -connect en.wikipedia.org:443 | grep "Cipher is" -A 4
180.
▲
by
sehrope
13y ago
They themselves might not have years worth but it could take a while to flow through the supply chain, get off store shelves, and be out of consumer's hands.
More ›