Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
steakejjs
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
steakejjs
12y ago
You'll notice a lot of people just have X-CSRF.* header (Stripe for example if you want to check one out). In my opinion you might as well just go the full 9 and actually implement an anti-CSRF solution instead of a quick hack. x-Reque
62.
▲
by
steakejjs
12y ago
That's the one. Starts around 28 minutes. Goes on for a couple minutes Listening to Tom and Ray you get a sense that they are two of your oldest friends. I've never heard two more likable guys talk.
63.
▲
by
steakejjs
12y ago
Aww man. I love Click and Clack. I know nothing about cars, I don't even have an interest in them, but I loved listening to these two talk about cars. My favorite episode was the one where he talked in depth about his time in the Army
64.
▲
by
steakejjs
12y ago
If you want more information on the specifics behind how FB did this, here is a really really informative mailing list conversation about it. Instead of coming up with facebookcorewwwi and then searching for it, they found a bunch of "
65.
▲
by
steakejjs
12y ago
I don't see a point to arguing this. Both are harmful. You can end up like CurrentC at the top of hacker news, or you can be 1 day behind. Both are bad. You can maybe prevent yourself from having to make this decision by being security
66.
▲
by
steakejjs
12y ago
Considering AppSec harmful is ridiculous. I know a particular startup that received millions of dollars in VC to start a payment processor. I RCE'd them in under 5 minutes and they remained vulnerable for more than a month after I repo
67.
▲
by
steakejjs
12y ago
I think OWASP does a good job explaining this stuff if you know how to build a web-app, you should be able to understand the vulns (they give PoC code and examples). OWASP could be doing a lot more but their PoC and descriptions are pretty
68.
▲
by
steakejjs
12y ago
I don't see it as any different than "it's own thing". CurrentC is a new product built from scratch essentially. Building things from scratch means you end up having to worry about how your code is organized to make good
69.
▲
by
steakejjs
12y ago
This is a big problem I've noticed with startups. Stupid web vulns are EVERYWHERE. I've reported so many serious web vulnerabilities to startups it isn't even funny (4-5 S14 YC batch alone). Account hijacks, XSS, SQLi. Everyw
70.
▲
by
steakejjs
12y ago
It's a shame more people haven't really spent time on Tack. I spent a weekend playing with it and it was really great. Trevor stopped paying for the TACK test server so Im guessing the push has died. Trust agility and certificate
71.
▲
by
steakejjs
12y ago
I really think C is much easier to get good at than other languages. There is no mystery with what's going on in the computer when you learn C, the builtin functions, how big something is, how things work, etc. When you learn higher le
72.
▲
by
steakejjs
12y ago
wow that's awesome! We really appreciate that.
73.
▲
LastPass command-line interface tool
(github.com)
173 points
by
steakejjs
12y ago
|
69 comments
74.
▲
by
steakejjs
12y ago
It's actually twitter.com/steakejjs. I just changed it last night actually independent of reading this. Cheers
75.
▲
by
steakejjs
12y ago
I've got a lot of practice breaking things. CSRF can be identified really fast by checking for unique tokens. Some unguessable token should be submitted with each state changing request. If not, attackers can steal authenticated accou
76.
▲
by
steakejjs
12y ago
Unfortunately that is too simple. These are secrets. People forget to update credit cards in sites all the time and you're going to immediately shoot an email off on a failed CC transaction or when you cancel a credit card hastily? An
77.
▲
by
steakejjs
12y ago
You've got to be kidding me. Despite the policy difficulties of running a site like this (when is someone dead?, how long until release of secrets?, how to deal with lack of access to emails? etc), This site is completely insecure. ht
78.
▲
by
steakejjs
12y ago
If you ever listen to people who really love locks talk about locks they all seem to say one thing. "All locks are pickable [or attackable]". This just means that this particular lock is abnormal and most lock-people don't ha
79.
▲
by
steakejjs
12y ago
Password managers are a better solution to prevent people from memorizing a lot of passowrds....Copied straight from the article "there is no risk of users reusing passwords"......That is what they have to do with this conversatio
80.
▲
by
steakejjs
12y ago
FD I work for a password manager...but I would still think password managers are better even if I didn't. 1) Password managers have security qualities built into them, example forced logoff after X amount of time. Someone who leaves th
81.
▲
by
steakejjs
12y ago
You can do this for any app.... not just snapchat. He sets his computer as a proxy between snapchat-app and snappchat-server. When I did this, Snapchat was certificate pinned to their server (it's been over a year though..so correct me
82.
▲
by
steakejjs
12y ago
One of the reasons preventing XSS is important is preventing data exfiltration. One of the things I see a lot of people doing is whitelisting in their CSP rules 3rd party APIs like Google Analytics. Well...these can be used to exfiltrate da
83.
▲
by
steakejjs
12y ago
I suppose it is possible. I just checked sheetz gift cards and the value you enter online is 19digits and incremented. However in the past I examined sheetz cards and the value on track2 of the mag strip was different than the incremented 1
84.
▲
by
steakejjs
12y ago
This was almost certainly a social engineering hack (if it is true at all which I don't believe it is). There is no trick to how a gift card works... A token value is stored on the card which maps to a number in the backend, where they
85.
▲
by
steakejjs
12y ago
This seems like a really valuable recruiting tool for YC. Start early at Stanford, groom freshman to have a great mindset and understanding of the fundamentals, fund them and make money. YC is still a for-profit company, after all.
86.
▲
by
steakejjs
12y ago
I live next to a wholefoods and a wegmans so this is a good comparison. The things I buy bring my average meal cost to about $5. If I eat out (chipotle or something) it is $10. I eat simply. One thing I love is wholefoods preseasoned chicke
87.
▲
by
steakejjs
12y ago
1. To save cash and recreationally. I would like to buy a house and cooking cuts my meal costs in half. It is also something I do with my SO 2. No. I live next door to two different upscale grocery stores (talk about luck). I just go nextdo
88.
▲
by
steakejjs
12y ago
Obesity is a great example of an ounce of prevention being worth a pound of cure. Having been overweight and borderline obese I have a certain mindset that my level of fitness is achievable by anyone who puts in the effort. I firmly believe
89.
▲
by
steakejjs
12y ago
This is absolutely not the expected response, which is really odd. I am running android 4.4.4 on a nexus 5 on Chrome 37.0.2062.117 (it just so happens) and I don't see an alert box. Expected is no alert box
90.
▲
by
steakejjs
12y ago
The question I am asking is, do they really have the demand to make $1.5million a customer pay (or look like one day it could pay) for their expenses? My guess is your estimates are really conservative.
More ›