Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
smagin
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
1.
▲
Open Letter to Steve Lemay
(ilyabirman.net)
7 points
by
smagin
4mo ago
|
0 comments
2.
▲
Falsehoods programmers believe about addresses (2013)
(mjt.me.uk)
1 points
by
smagin
7mo ago
|
1 comments
3.
▲
by
smagin
7mo ago
in light of zipcodefirst site
4.
▲
by
smagin
9mo ago
https://smagin.fyi/ That's my blog. I have opinions on software, make a couple of apps and patch other people programs when I like them enough. People here liked https://smagin.fyi/posts/cross-site
5.
▲
The Science of Word Recognition
(learn.microsoft.com)
1 points
by
smagin
9mo ago
|
0 comments
6.
▲
by
smagin
1y ago
This feels like April 1st joke made in October. Like the Enter dial in particular.
7.
▲
Keyboard with Turntable Dials
(designboom.com)
3 points
by
smagin
1y ago
|
1 comments
8.
▲
by
smagin
1y ago
Like the take that we need to authentificate more often nowadays. AWS makes it extreme — it resets login each 12 hours I reckon, and each time I need to click like 10 times, touch the fingerprint button 3 times (fill email, fill password, p
9.
▲
by
smagin
1y ago
Thanks for the information hierarchy / conceptual boundaries distinction, makes sense. I didn't know the latter term but tried to describe it in the last section of the post, nice to have a name now. There are apps and sites that
10.
▲
by
smagin
1y ago
yup, that's a good part of the page to stand out, when I've seen all the landing page can show and now it nudges me to try the app out
11.
▲
by
smagin
1y ago
hm, I sort of agree with the train of thoughts but not with the conclusion. Maybe it's "is my blue your blue" situation. I talked to people while working on this post and some said e.g. grid with cards is way easier to them t
12.
▲
by
smagin
1y ago
author here (not super educated either). That's part of the idea — when cards are removed it becomes obvious that tags become the most noticeable part while not being the most (or any) important one. When you look at the cards you see
13.
▲
Spacing Over Cards
(smagin.fyi)
43 points
by
smagin
1y ago
|
10 comments
14.
▲
by
smagin
1y ago
Unrelated but I have the easiest design improvement for your website: change <html> background color to #4285f4 (same as in topbar) so it looks like a sheet of paper on a blue base
15.
▲
Ordinary life improvements 2018-2025
(smagin.fyi)
7 points
by
smagin
1y ago
|
2 comments
16.
▲
by
smagin
1y ago
Gwern wrote a post about his everyday improvements in 2018, I thought I'd write a follow-up.
17.
▲
I Need Your Help to Improve Money Formatting on the Internet
(smagin.fyi)
2 points
by
smagin
1y ago
|
0 comments
18.
▲
by
smagin
2y ago
oh god you're right https://stackoverflow.com/a/57206146/1685746 yeah sure what can go wrong, let's listen to fetch and modify requests in a service worker.
19.
▲
by
smagin
2y ago
I asked that in the post but nobody answered still, let's try here. Why are CSRF tokens rotated? OWASP says it's somehow more secure but I don't really see why.
20.
▲
by
smagin
2y ago
not even you don't need to, you shouldn't. Sessions shouldn't be accessible to js at all
21.
▲
by
smagin
2y ago
mitm means you can control users network, doesn't it? Another question, does this work with https? And the third one, if this was the thing some dishonest governments or vpn providers would do this already. Would be cool to read on tha
22.
▲
by
smagin
2y ago
You shouldn't need your session token in JS, you can specify your fetch requests to include cookies, and you can setup CORS to allow that.
23.
▲
by
smagin
2y ago
> How does server know the cookie is valid if it doesn't store it depending on why you'are asking the question, * because it decrypts correctly * because it contains some user identifier People don't usually store sessions
24.
▲
by
smagin
2y ago
Why would you need that? Also, one thing I can speculate that phishing would become even easier if such things were allowed
25.
▲
by
smagin
2y ago
This is my blog. I haven't posted all the articles from there to hackernews. I think some of them are not worth discussing because too old or too poorly written, but some are just not posted because I didn't think of it at the tim
26.
▲
by
smagin
2y ago
it is true. But again, writes are allowed, reads are not, you won't be able to see the reply. Which author of the question eventually realised https://stackoverflow.com/a/44122076/1685746
27.
▲
by
smagin
2y ago
well it does make sense to assume that by default different origins belong to different people, and some of those people don't have to behave friendly to each other. There is little server can do with that, because of the request-based
28.
▲
by
smagin
2y ago
yup. You didn't imply it but just in case -- this token shouldn't be the same as session token. Session tokens should be `HttpOnly`, so that we don't even expose it to javascript
29.
▲
by
smagin
2y ago
oh hell yes. And oh yes iframes and postmessages, of course people would setup them incorrectly and even if they do some (probably not that important but still) data will leak if you're creative enough. Thanks for the link!
30.
▲
by
smagin
2y ago
"search this site in google" shouldn't even be a POST request, but yeah, when we'll have better defaults for cookies it should work nicer. And if you are a web developer, you should check your session cookie attributes a
More ›