Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
snowwolf
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
snowwolf
7y ago
There is an argument that you should absolutely be optimising for day 1. One of your biggest advantages as a startup is agility. Until you've hit upon product/market fit, you want to choose tools that enable you to iterate fast.
62.
▲
by
snowwolf
7y ago
Quite a few of the coffee shops I go to have started using these: https://www.vegware.com/biodegradable-hot-cups/cat_4.html The problem is that they require heat to activate the composting process, so need special bins
63.
▲
by
snowwolf
8y ago
The most frequent use cases for us in order of use-fullness: 1. Spotify 2. TV control (with Harmony) - great for the kids so they don't break the remotes 3. Home monitoring when we are away (drop in on the echo spot). But for me home s
64.
▲
by
snowwolf
8y ago
Is this Venezuelan coffee? https://www.bloomberg.com/features/2016-venezuela-cafe-con-l... But note I think you mean the $12 price but that’s only available from the 28th Feb. To buy today it is $11,500 (unless as othe
65.
▲
by
snowwolf
8y ago
That makes more sense. I had missed that there was a sunrise period for the .dev tld.
66.
▲
by
snowwolf
8y ago
Slack and Github were so worried about someone cybersquatting that they were willing to pay $11,500 each to get those domains today? I guess that's the point of the Dutch auction system, but still seems like a waste of money.
67.
▲
by
snowwolf
8y ago
>> a) the data wasn't breached through the credential stuffing attack, it was breached at an earlier time on another site. Remember GDPR is specifically concerned with "A personal data breach" The original breach that l
68.
▲
by
snowwolf
8y ago
>> According to your own interpretation of the law Look, I am not a laywer, and I am happy for someone to correct me here, but this is the wording of the law: "A personal data breach means a breach of security leading to the acci
69.
▲
by
snowwolf
8y ago
I'm not sure why this is being downvoted. All I am doing is pointing out what the current law is under GDPR. You may not agree with the law, but that doesn't change what it says.
70.
▲
by
snowwolf
8y ago
Remember part 2 of that section: "establish the likelihood and severity of the resulting risk to people’s rights and freedoms. If it’s likely that there will be a risk then you must notify the ICO;" So if it's a small irrelev
71.
▲
by
snowwolf
8y ago
Good look using that as your defence in a court of law :)
72.
▲
by
snowwolf
8y ago
I think unauthorised has a fairly clearly defined definition in the English language (without permission or authority). And I’m fairly sure that’s the definition already used in courts of law. So in the absence of any contradicting definiti
73.
▲
by
snowwolf
8y ago
You’re forgetting something. This isn’t my argument. This is what GDPR states. Unauthorised access to personal data constitutes a data breach. Does someone accessing your personal data who is not you using a stolen password count as unautho
74.
▲
by
snowwolf
8y ago
Yes, exactly that if the email provider hasn’t put in place sufficient defences. Why wouldn’t they be liable? They have a duty of care under GDPR to protect your personal data. If they are negligent in that duty then absolutely they should
75.
▲
by
snowwolf
8y ago
I actually think the article is correct about GDPR data breaches. See my other comment about this. https://news.ycombinator.com/item?id=18990122
76.
▲
by
snowwolf
8y ago
There are many things they could do. For starters they could verify (email, 2 factor, something) unusual sign ins - for example sign ins from a new IP, especially if that IP has a higher risk profile (data center, known vpn, tor exit nodes,
77.
▲
by
snowwolf
8y ago
In the UK, the ICO guidelines are "A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data." The key part being
78.
▲
by
snowwolf
8y ago
I found https://tomharrisonjr.com/uuid-or-guid-as-primary-keys-be-ca... has a good rundown of the pros and cons.
79.
▲
by
snowwolf
8y ago
On the server config I also had to add some iptables rules PostUp = iptables -A FORWARD -i wg0 -j ACCEPT; iptables -A FORWARD -o wg0 -j ACCEPT; iptables -t nat -A POSTROUTING -o enp2s0 -j MASQUERADE PostDown = iptables -D FORWARD -i w
80.
▲
by
snowwolf
8y ago
I forget where I saw it, but I thought this was a good test of whether it is legitimate interest. It went something like: "Would a 'reasonable' person be surprised if you told them about how you were using the data?"
81.
▲
by
snowwolf
8y ago
No. I’ve isolated the problem to the email account. You only need to set it up once with a provider who hopefully has the resources to do it properly (like gmail). Rather than having to do it for every website who all decide to do it differ
82.
▲
by
snowwolf
8y ago
This is all well and good for a tech savvy user. But for the user who "instead of properly setting up their authenticator app, they brilliantly used one of the ten backup codes to finish their 2FA setup (and didn’t even store the rest)
83.
▲
by
snowwolf
8y ago
I'm beginning to think the only user friendly secure way of user authentication is to go passwordless (except for the email account which becomes the key for everything). Setup an email account and lock it down - strong unique password
84.
▲
by
snowwolf
8y ago
I posted the same elsewhere in this thread, but if you are actually using a domain you control (@mydomain.com) then https://haveibeenpwned.com/domainsearch They don't support the gmail alias issue though ( https:/
85.
▲
by
snowwolf
8y ago
If you use your own domain, https://haveibeenpwned.com/domainsearch
86.
▲
by
snowwolf
8y ago
http://www.flatwhitesoho.co.uk/ “Flat White opened its doors in 2005 because it was nigh impossible to get a flat white; the strong, delicious creamy coffee of our namesake. London lacked a strong independent café/coff
87.
▲
by
snowwolf
8y ago
You can't have looked very hard. So called "Third Wave" artisanal coffee shops hit London around 13 years ago, mostly started by Australian immigrants bringing with them the "Flat White". The flat white become such
88.
▲
by
snowwolf
8y ago
20km/h top speed, driven by an "Official Bugatti Pilot" wearing a crash helmet on a closed circuit. I think they did their risk assessment.
89.
▲
by
snowwolf
8y ago
The dark patterns in play now to get explicit consent are pretty bad now though. Take Mashable for example. On first visiting the site you are presented with the option to "Consent" or view more Options (where you can Opt Out of a
90.
▲
by
snowwolf
8y ago
Add PayPal. And theirs is an EV cert "valid" till 2019. Bet they're happy having to go through the process all over again.
More ›