Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sytringy05
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
sytringy05
1y ago
Java applets were terrible in all possible ways that something can be terrible and it took no less than Steve Jobs to kill off Flash. This stuff was foundational to the modern web and it's clear the maintainers, who probably are not St
2.
▲
by
sytringy05
2y ago
I worked for an aircraft parts manufacturer, they closed an entire factory / production site rather than try and upgrade the manufacturing system or move the part production onto the new one they had implemented. 500 people out of work
3.
▲
by
sytringy05
2y ago
The issue with myki wasn't the card technology, it was the fact they wanted to have standardised ticketing across the entire state. eg Tap on a bus, tram and train in Melbourne, get off in Wangaratta and tap on to a bus there. There wa
4.
▲
by
sytringy05
3y ago
<7000 lines of cut / paste YAML later> “it’s that easy!”
5.
▲
by
sytringy05
3y ago
It’s from the original borne / korn shell in Unix. Ctrl H was backspace, but the pc keyboards would send a different control character. you often had to map the backspace on the pc keyboard to make it work properly. Set -o or somethin
6.
▲
by
sytringy05
3y ago
Pretty interesting way to run what's in effect a XSS attack.
7.
▲
New localstorage JWT exfil just dropped
(twitter.com)
2 points
by
sytringy05
3y ago
|
1 comments
8.
▲
by
sytringy05
3y ago
It's interesting to hear that because IHMO one of the reasons OAuth and JWT took over the world is that you can base64 decode the tokens and see whats inside them, compared to Kerb or NTLM which you eventually learn to spot based on th
9.
▲
by
sytringy05
3y ago
Well hopefully someone has taken the time to, or there will be nasty surprises I certainly don't want people building security sensitive parts of an app to be slinging the features out.
10.
▲
by
sytringy05
3y ago
The whole point of access tokens is to not do expensive checks on every request. Signature checks out and isn't expired - you are free to go. This is a core design thing of OAuth, once access tokens are out the door they are very hard
11.
▲
by
sytringy05
3y ago
Yes, single log out is an ongoing nightmare. <Stares at Ping> As many here have said the size and range of use cases that OAuth and OIDC support is off its head. And that's with the big boys who have millions of users, throw in $
12.
▲
by
sytringy05
3y ago
lol, here's my visual flow which consists of "start" -> "script node" -> "end" Still, people buy Dell Boomi and Mulesoft, so it's not like there's no market for this rubbish
13.
▲
Atlassian lay off 500 staff
(theguardian.com)
11 points
by
sytringy05
4y ago
|
1 comments
14.
▲
by
sytringy05
4y ago
It wasn't a draft, it was reviewed, approved agreed upon etc, but the initial reason to do it was supporting a review of how things were integrated. Basically because it was useful and there wasn't anything else like it, they turn
15.
▲
by
sytringy05
4y ago
because that's just how it was there... wasn't the best place in the world to work.
16.
▲
by
sytringy05
4y ago
I once made the mistake of doing a set of rather detailed integration diagrams for an airline I was consulting at. This diagram, which was intended to be a rough snapshot of how the systems interacted, instead became the single point of ref
17.
▲
by
sytringy05
4y ago
the main ones are OIDC plugin, the serverless plugin, advanced req and resp transformer plugins. auth connectors are useful, but most orgs I work with are using OIDC or SAML
18.
▲
by
sytringy05
4y ago
does anyone know the history of the project? I hadn't really heard of this until earlier this year.
19.
▲
by
sytringy05
4y ago
the same benefit you get from most reverse proxies. If you dont need it, then nothing. If you do need it, it's critical. If you: - have more than 1 upstream service to hide behind your api.bigcorp.com name? - want to enforce standard
20.
▲
by
sytringy05
4y ago
I think they were logging them in clear text, so server side, prolly ended up in splunk or elasticsearch.
21.
▲
by
sytringy05
4y ago
This article answers its own question: "The situation is hopeless, but not serious." REST vs HATEOS vs HTTP API vs Web Service It's not serious and it doesn't matter that much. If I'm writing an API, I probably want
22.
▲
by
sytringy05
4y ago
I wholeheartedly agree, which is why hardly anyone ever builds "REST" APIs. It doesn't really add that much to a data API
23.
▲
by
sytringy05
5y ago
According to this web page - https://vicsig.net/infrastructure/signalbox/Metrol - it seems yes, it has been replaced. > Train Describer replaced with TCMS in 2014-2016.
24.
▲
by
sytringy05
5y ago
IIRC high speed signalling is coming with the Melbourne Metro trains (and the existing lines those trains will run through). Replacing train management systems like this with new ones seems to be all but impossible, my brother in law worked
25.
▲
by
sytringy05
5y ago
No doubt, but there's always a way to smoke the whole thing, even with all the fail safe and redundancy in the world.
26.
▲
by
sytringy05
6y ago
How about a shipping choke point and a city at the same time: https://xkcd.com/748/
27.
▲
by
sytringy05
6y ago
Wow, I wonder if this will create some space for a new competitor? I mean apart from these 2, who else are a serious option for rock solid SaaS IdP?
28.
▲
Facebook bans news sharing in Australia
(theage.com.au)
11 points
by
sytringy05
6y ago
|
10 comments
29.
▲
by
sytringy05
6y ago
Is remote from Melb possible?
30.
▲
by
sytringy05
6y ago
The problem with TCP jokes is that people keep retelling them slower until you get them
More ›