Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sehrope
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
25 ms
·
181.
▲
by
sehrope
13y ago
YAML 1.2 is a super set of JSON. Check out the spec itself: http://www.yaml.org/spec/1.2/spec.html#id2759572
182.
▲
by
sehrope
13y ago
> L'Oreal, the Body Shop and Johnson & Johnson all committed to phasing out plastic microbeads by 2015, and Proctor & Gamble said it would do so by 2017. Unfortunately there's no mention if "phasing out" means
183.
▲
by
sehrope
13y ago
Or just use YAML[1]. It's a super set of JSON, includes comments, nicely formatted lists, and is (IMHO) much easier on the eyes. [1]: http://en.wikipedia.org/wiki/Yaml
184.
▲
by
sehrope
13y ago
It's kludge plain and simple. It's ugly but it works (well kind of). That's the exact definition of a kludge. Further interesting things with wp-cron is that since other plugins make use of it, if you do have a "real&quo
185.
▲
by
sehrope
13y ago
Yes that's exactly why it came about. I still find it very interesting (and humorous) solution though. I've seen the same inner platform effect in legacy systems at large corporations.
186.
▲
by
sehrope
13y ago
I've never used WP but I've read about it quite a bit. Usually it'd be after site X on HN goes down for not enabling caching and not being able to handle the load. There's always links to "best practices for caching
187.
▲
by
sehrope
13y ago
You'd think so but when the use case involves dynamically retrieving fresh data it becomes one of the last things to work on. Lots of people have CSV data and it makes sense to support it but since it's generally a manual process
188.
▲
by
sehrope
13y ago
Substringed JSON arrays work great for this as well. Basically you just convert each row to an array, convert the array to JSON, and the strip the leading and trailing brackets ("[" and "]"). Newlines will be properly re
189.
▲
by
sehrope
13y ago
> I've lately been coming around to the belief that anyone who uses the term "sanitize" in this domain, as in, "sanitize user input" really doesn't know what they are talking about (at least on average). I&#
190.
▲
by
sehrope
13y ago
In our app we neither validate nor escape user strings for any free form text (eg. "names" and descriptions)[1]. We only validate the max length. If text is truly free form then you don't need to validate or white list anythi
191.
▲
by
sehrope
13y ago
If it's the same one I remember the plate was "NO TAGS"[1]. [1]: http://www.huffingtonpost.com/2012/02/16/no-tags-meet-sauced...
192.
▲
by
sehrope
13y ago
> ... Google seems to have abondoned their Authenticator app What exactly would you like improved in Google Authenticator? It's not like it does anything special, it just scans TOTP QR codes and generates TOTP codes, and it does bot
193.
▲
by
sehrope
13y ago
> Column names not parameterizeable in prepared statements. You should still use prepared statements for these types of queries as more than likely they will have parameters as well. You might end up with a couple more SQL statements in
194.
▲
by
sehrope
13y ago
If your product is profitable then being able to scale the server side by buy bigger/more servers (aka throwing money at the problem) can be a great approach. It means no new code write, and more importantly, no new code to test. There
195.
▲
by
sehrope
13y ago
Both raw SQL and using an ORM have their place. The latter is definitely less prone to unintended SQL injections but it's still possible. The reverse is true too. Raw SQL can be quite secure if you're not an idiot about it (golden
196.
▲
Appeals Court Upholds Ruling That Halted NYC's Large-Soda Ban
(nytimes.com)
1 points
by
sehrope
13y ago
|
0 comments
197.
▲
by
sehrope
13y ago
I do that as well. It's a belt and suspenders approach. Also, by leaving cash there's never any math involved either as the pre-tip total is the final total.
198.
▲
by
sehrope
13y ago
I do the opposite and always leave tips in cash but not just to give a bonus to the server (if they don't declare/share it). It also makes it so that my receipts, credit charge email alerts, and monthly bill all reconcile. Otherwi
199.
▲
by
sehrope
13y ago
To clarify by "finished" I meant shipping a working version of a product, not being finished with all work on the product.
200.
▲
by
sehrope
13y ago
I see nothing wrong with using stored procs or non-ANSI features. You just need to know what you're getting into. The same goes for any database. Being database agnostic is great but so is actually finishing what you're working on
201.
▲
by
sehrope
13y ago
The problem with the software one is you need a way to modify it when you can't access the instance. With AWS you do it from the admin console or APIs. If it's on the machine itself you'd have to know the IP to open up in adv
202.
▲
by
sehrope
13y ago
Generating fresh keys aside, one thing I do with our AWS setup is whitelist the IPs that can connect to our SSH bastion host. This completely eliminates scripted port scans of the SSH server and makes the auth logs much more manageable. If
203.
▲
by
sehrope
13y ago
> This sounds reallly interesting, but it feels very painful for reporting. Trying to run reports on this type of data for a dashboard seems out of the question. Yes we've saved it mainly to look at it later. It's the lowest le
204.
▲
by
sehrope
13y ago
Very nice logo by the way. Took a second glance to see the speech bubble at the top but once you do it's beautiful.
205.
▲
by
sehrope
13y ago
How you store your logs depends on your server configuration. Analytic services like Google Analytics or Mixpanel will work for any type of config as they're initiated by the client. They both also have a nice UI so can see live user&#
206.
▲
by
sehrope
13y ago
> Any request that is denied by OpenDNS is then allowed by our DNS server, and any request allowed by OpenDNS is blocked by us. The most interesting part of this to me is using multiple DNS providers to determine which category the site
207.
▲
by
sehrope
13y ago
For stateless load balancing without a central server. By having the data in a client cookie so that any web server can access it. Without it you need sticky sessions on your load balancer or a central data store requiring additional round
208.
▲
by
sehrope
13y ago
This is in almost the same category as checking in your SSH private keys. I say almost because at least this one is somewhat understandable. From the perspective of of an app developer having everything in one place that you can deploy
209.
▲
by
sehrope
13y ago
Miscom on my part. By driver I meant the nginx module that's calling out to libpq (which would more accurately be referred to as the DB driver). I meant that libpq supports bind variables and the nginx module should be using them rathe
210.
▲
by
sehrope
13y ago
Unfortunately when defaults are inherently insecure, they lead to people building insecure systems. If every single parameterized SQL command needs to include (possibly multiple) escapes then it'll be missed in some places. It's u
More ›