Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
subudeepak
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
subudeepak
12y ago
Thanks for the insights. I wonder if a feature by feature in-app purchase on the app would have fared better.
32.
▲
by
subudeepak
12y ago
I do not think so. I am not sure if you are aware of Hawala http://en.wikipedia.org/wiki/Hawala or so many other malicious instruments that can be used in a manner similar to crowdfunding. This also includes other fact
33.
▲
The functionality exists but only usable by native implementation of browsers
(gist.github.com)
4 points
by
subudeepak
12y ago
|
1 comments
34.
▲
Heartbleed is a vulnerability with a CVSS score of only 5.0/10.
(alienvault.com)
2 points
by
subudeepak
12y ago
|
0 comments
35.
▲
by
subudeepak
12y ago
Yes. The malicous scripts can already do that. It has taken years to train people and educate them on adding suitable Content-Security Policy headers to prevent such violations without breaking the internet. Every modern technology (especia
36.
▲
by
subudeepak
12y ago
The Origin header is used to protect the server. This is to prevent the WebSocket Hijacking attack ( http://www.christian-schneider.net/CrossSiteWebSocketHijacki... ) . i.e. it does not help a lot in the browser end especiall
37.
▲
by
subudeepak
12y ago
Note that this is not an implementation problem but a problem in the general specification of websockets. So there is not going to be a solution to this issue until the specification itself is updated.
38.
▲
by
subudeepak
12y ago
I doubt you are the first one ;) .. I was shocked when I discovered this myself.
39.
▲
The problems and some security implications of websockets
(gist.github.com)
42 points
by
subudeepak
12y ago
|
7 comments