Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
steakejjs
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
steakejjs
12y ago
Hey this is my blog post and that's not all it says. At the time, keybase used a font allowed me to perfectly copy (and make it look like twitter/github was verified) people's profiles. Totally a lame vulnerability? Yes. Pret
32.
▲
by
steakejjs
12y ago
EVERYONE does a horrible job recruiting. I think a very low number of companies are doing this correctly. The thing about the process is one bad moment spoils the entire process for the candidate. Shallow/No responses, or horrible ques
33.
▲
by
steakejjs
12y ago
Yes the school code was the same for everyone at the University. It differs from college to college, since this is a "solution" that the university purchases from a company.
34.
▲
by
steakejjs
12y ago
I went to a University in Virginia and ours, and other surrounding VA universities were equally insecure. We each had a 9 digit code that looked like 10XXXXXXX. These numbers were incremented from one student or faculty to the next. The onl
35.
▲
by
steakejjs
12y ago
IT security is ridiculously easy to break into, and I'm not kidding. If you are able to demonstrate all that talent (github, outside projects, anything else) and you are able to hold a conversation with people, there are literally thou
36.
▲
by
steakejjs
12y ago
I wish the email stack was simpler. While working on a project to learn go, I was using postfix to pipe email directly to a Go program, that then sent them as an SMS. I couldn't help but thinking how old and clunky the software I was u
37.
▲
by
steakejjs
12y ago
Cool idea but will this actually be good in practice. When I go on Instagram a huge number of the popular images are NSFW with partial nudity or other things I wouldn't like to see every time I open a new tab
38.
▲
by
steakejjs
12y ago
pretty small world. I'm from Stafford and went to school in Harrisonburg too. Not a lot of VA folks on HN
39.
▲
by
steakejjs
12y ago
I agree. Go was really nice to write code in since I do a huge variety of system level and Web things. It's my goto for practically everything now. It will get better but for now I think writing a full web-app in Go, (presentation etc)
40.
▲
by
steakejjs
12y ago
I wrote a Go Web Application with authentication and an API to learn Golang. I must say, writing an API and some other services (SMTP pipe listener) was much nicer in Go than Authentication. There is gorilla/sessions for sessions, but
41.
▲
by
steakejjs
12y ago
I don't know of any security conferences that preview slides. original research is presented regularly which means your hard work might leak by conference organizers who can't keep their mouths shut. Alsp, many speakers are workin
42.
▲
by
steakejjs
12y ago
This looks like a giant list of trivia that has almost no bearing on the day-to-day effectiveness of the candidate. For example, I don't have the slightest clue what the answer is to probably half of these and a lot of my job is to wri
43.
▲
by
steakejjs
12y ago
In my opinion the best way to start a profitable side projects is to limit the scope of the project. I fall into the category of starting too many things that I don't finish. I've recently realized that the size of the things I wa
44.
▲
by
steakejjs
12y ago
There are a lot of things here that stand out to me, as a recent grad of just a regular state school. Things like "Using an API Key", and "Using git" cause students to HAVE to go above and beyond the assignment Because t
45.
▲
by
steakejjs
12y ago
The API with a single call "createWithdrawl" is very good. Having code like this to begin with changes how all your future code works. It also is easier to debug, simpler to explain, etc. You think twice about adding new API calls
46.
▲
by
steakejjs
12y ago
The answer to "Can you sue?" is always yes, yes, yes. You always can.
47.
▲
by
steakejjs
12y ago
I honestly don't think it is unfair. "Both technically violated the CFAA" is an important sentence. The legal system is very complicated and sometimes small details make very big differences in cases. I'm not convinced o
48.
▲
by
steakejjs
12y ago
If this were the USA it would certainly be bad enough to warrant prosecution of the researcher. I am not familiar with laws in the UK, however. Keep in mind the similarities between this research and weev's research. This type of blata
49.
▲
by
steakejjs
12y ago
This might be a good time to post the link to Facebook's XHP https://www.facebook.com/notes/facebook-engineering/xhp-a-ne... I've been using XHP at work and love the improvements it has made to the new c
50.
▲
by
steakejjs
12y ago
It's surprisingly not difficult. I got the woff files, base64'd them, and then threw the output into several CSS files. Words of warning, If you use Content Security policy, you must allow Unsafe Inline for the style-src directive
51.
▲
by
steakejjs
12y ago
I got tired of using font CDNs, didn't like extra round trips for the woff files, and I also really liked open-sans, so I made an OpenSans.css which inlines all the OpenSans fonts. It makes my life a little more convenient. https:
52.
▲
by
steakejjs
12y ago
I think "Never unchecked the checked-by-default whois checkbox when purchasing the domain" is more accurate than actually saying it is a decision. While a company should definitely have a whois page, most startups make it abundant
53.
▲
by
steakejjs
12y ago
So I wrote a golang application and it runs behind nginx. My server "restart" when I want to push new code is, Re run my program on a different port, point nginx at the new port, reload nginx, kill the old. Curious what is so bad
54.
▲
by
steakejjs
12y ago
"Goto is bad" is something that professors tell first year computer science students because as computer scientists, the students will find novel ways of abusing them. Using goto for error cleanup is pretty standard, easily readab
55.
▲
by
steakejjs
12y ago
This research lcamtuf has been doing with AFL is really important. One thing that it is proving (exactly as a lot of people expected) is, we don't have any idea where security bugs (think the next heartbleed or shellshock) are going to
56.
▲
by
steakejjs
12y ago
Cool stuff. Really like the app.
57.
▲
by
steakejjs
12y ago
So this looked really great and I'm sure it will be. I realize that there are a lot of barcodes, but I happened to see this thread while at Costco. I downloaded the app while here and it only recognized 2 beers from the entire beer isl
58.
▲
by
steakejjs
12y ago
Seems like this might impose on Clinkle quite a bit? Who is going to download clinkle when they can do the same thing from snapchat? Seems neat to me, and pretty unexpected. One scary thing is just how bad a lot of passwords are for mobile
59.
▲
by
steakejjs
12y ago
One thing I've noticed that will become increasingly important in the future is for JavaScript APIs it would be really nice if you had a per user path, for example: api.com/steakejjs/v1/ This way, user's of your API
60.
▲
by
steakejjs
12y ago
I think your comment shows part of the problem, which isn't mean as a dig. carbs, sugar, low dairy, small portions? What does this leave you to eat? The average person will go crazy following these rules. The problem is people aren
More ›