Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sonnym
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
sonnym
13y ago
Over time, I have come to feel this git workflow is more of an attempt to coerce git into a workflow that is familiar to users coming from subversion, rather than learning and understanding git's strengths. A corollary problems is tha
32.
▲
by
sonnym
13y ago
I am only about a quarter of the way through the book, but thus far I would have to say the chapters on BerkeleyDB and Eclipse were the most interesting, both containing a lot of history and insight into how the projects changed over time.
33.
▲
by
sonnym
13y ago
I have been reading through this book, as each chapter is separate to all the others. It is, overall, a quality work, but some chapters definitely stand above others. On the downside, there is little cohesion between the chapters and, whi
34.
▲
by
sonnym
13y ago
Always remember this useful rule of thumb: "Any headline which ends in a question mark can be answered by the word no." https://en.wikipedia.org/wiki/Betteridge%27s_law_of_headline...
35.
▲
by
sonnym
13y ago
This is interestingly reminiscent of swearjure[1], clojure without alphanumerics. The IRC log in that post is very enlightening to see how the idea evolved into something absolutely frightening. I would like to see the history of JSFuck.
36.
▲
by
sonnym
14y ago
You are correct on both counts regarding the vim and grep example - I guess I just assumed I would have to have all the files on a single line before handing them off to vim. Thanks for the suggestion about -exec +; I will have to remember
37.
▲
by
sonnym
14y ago
I use xargs a lot for refactoring work when I cannot simply use sed, e.g. vim $(grep -lr foo | xargs) and doing what I need to do on a file by file basis. Otherwise, for renaming functions and the like, I do a lot of: find . -name foo_fn e
38.
▲
by
sonnym
14y ago
This is a clear example of a sampling bias. The voices of those angry with an experience of poor service will raise a cacophony compared to those who have a pleasant experience and simply carry on with their lives.
39.
▲
by
sonnym
14y ago
On the correlation between bearded language designers and language popularity: http://www.alenz.org/mirror/khason/why-microsoft-can-blow-of...
40.
▲
Exodus from Silicon Valley
(nytimes.com)
1 points
by
sonnym
14y ago
|
0 comments
41.
▲
by
sonnym
14y ago
If you are using an e-mail client, you will be connecting to the gmail server using STARTTLS, so your e-mails will not be transferred over the public internet in plain text. If you use the web client, everything is over HTTPS, and, like the
42.
▲
by
sonnym
15y ago
I almost hate to be that guy, but mount /mnt/book && cd /mnt/book && wget ... work just fine for me with the Sony PRS-300. I imagine things might be a bit different with a more closed system, but this has been doing the tri
43.
▲
by
sonnym
15y ago
Barry Cooper, a former narcotics officer, explains in pretty great detail how they train with alert dogs: http://youtu.be/F9pGylTSDj0 A lot of the video isn't particularly relevant, but he does discuss how the officers are trained to inci
44.
▲
by
sonnym
15y ago
This is the video from the technical demonstration and explanation: http://www.youtube.com/watch?v=R2Cq3CLI6H8
45.
▲
by
sonnym
15y ago
It should be noted that dustjs is not yet updated for node v0.6.x. I submitted a rather trivial pull request toward the end of October fixing the problem and another user has submitted one since then, but the author has not responded to ei
46.
▲
by
sonnym
15y ago
I was merely pointing out how easy it is to fake, although you are correct a third party site could not do this. Atwood's point is that checking the "referer" will both be unreliable and, more importantly, lead to false positives; there are
47.
▲
by
sonnym
15y ago
You cannot assume a request is coming from a browser. curl --referer http://www.example.come http://www.example.com
48.
▲
by
sonnym
15y ago
In double cookie submission, you are not issuing two requests to the server, but rather using javascript to append the session id to either the post body or the URI. Since the browser automatically submits the cookie via HTTP Headers, singl
49.
▲
by
sonnym
15y ago
From http://www.codinghorror.com/blog/2008/09/cross-site-request-... The HTTP referrer, or HTTP "referer" as it is now permanently misspelled, should always come from your own domain. You could reject any form posts from alien referrers.
50.
▲
by
sonnym
15y ago
My bad, I thought the timestamp was being inserted into a form ala Rails' authenticity_token method in a way that would allow it to go stale if a new request was submitted in a new tab. Although this makes sense, I feel it is not as safe as
51.
▲
by
sonnym
15y ago
How do you mitigate problems with a user opening multiple tabs over a span of time, and attempting to submit the first one opened? I believe the best practice is to provide the user's session id in their cookie and provide that with the req
52.
▲
by
sonnym
15y ago
Because you cannot issue cross-domain AJAX calls, the attacker does not have access to the response body as a string that can be manipulated. https://secure.wikimedia.org/wikipedia/en/wiki/Same_origin_p...
53.
▲
by
sonnym
15y ago
While I generally agree with your sentiment, I was merely writing a brief proof of concept test in the firebug console. From: http://www.json.org/js.html "The use of eval is indicated when the source is trusted and competent. It is much s
54.
▲
by
sonnym
15y ago
I imagine they simply remove the first 8 characters from the response string. eval("(for(;;);{})"); doesn't work, but eval("(" + "for(;;);{}".substring(8, 10) + ")"); works fine where 10 is the length of the response string. EDIT: This is
55.
▲
by
sonnym
15y ago
Statistics on when posts are submitted can be found here: http://blog.itlater.com/whats-the-best-time-to-post-to-hacke... From that, take what you will.
56.
▲
by
sonnym
15y ago
This reminded me of a very interesting interview with Russell Brand I saw recently, in which he discusses the error in seeking celebrity for the sake of celebrity as this ends without any real fulfillment. Instead, he advocates working in
57.
▲
by
sonnym
16y ago
The CommonJS module specification uses the require() function to include modules. Because this function can take paths, it becomes difficult to share code between the server and the client without some workarounds. What this module does (a
58.
▲
Kinect 3D Reconstruction Software Release Announcement
(youtube.com)
2 points
by
sonnym
16y ago
|
0 comments
59.
▲
by
sonnym
16y ago
Single page: http://nymag.com/print/?/health/features/46213/index1.html
60.
▲
by
sonnym
16y ago
I've been using an HP dv6113us for ~4 years now, with every version of openSUSE through that time span working without any deal breaking problems. When the laptop was brand new, I had some problems with the sound drivers, but contacted some
More ›