Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
technion
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
22 ms
·
271.
▲
by
technion
3y ago
Most companies making this jump are already using azure and vulnerable to any azure compromise. And for a long time, adding in okta was some kind of trendy thing to do "for security" but all its adds at this point is another point
272.
▲
by
technion
3y ago
I just watched the Anthony Bourdain special where he talked to people in Israel about previous wars, and they talked about Twitter saving their lives, calling in NATO strikes by Tweeting about enemy activities.
273.
▲
by
technion
3y ago
If I need to sign a legal contract asserting that every desktop has bitlocker or the mac equivalent, there needs to be a level of remote management, and I'll be the first one telling people they can't force people to intune enroll
274.
▲
by
technion
3y ago
What you are saying is absolutely true, but I've worked with some particularly inept executives and they are often identifiable with requests like "I want every email that new staff send bcced to me", which always becomes fun
275.
▲
by
technion
3y ago
I think this should be assumed for any "x company uses y uncommon language heavily" argument that you read online.
276.
▲
by
technion
3y ago
You'd be surprised how many candidates would prefer to just take another job. If for no other reason than resume building with the word react.
277.
▲
by
technion
3y ago
Mastodon runs as a rails api with a react frontend. Last time I discussed this people mentioned it was the worst of both worlds and I get the argument. But doing things that way means nearly every fronted dev can work with their favourite p
278.
▲
by
technion
3y ago
For the most part it's not common to be able to make a server call curl with an arbitrary server which is usually required to exploit this sort of thing. There will be some vulnerable apps, but the vast majority of servers with this vu
279.
▲
by
technion
3y ago
I feel that examples argues the opposite. It's not entirely known how every step of that attack went down, but "breaking low quality crypto" hasn't factored into any incident write up I've ever seen. However, nearly
280.
▲
by
technion
3y ago
I feel like it's been one of the great identifiers of blog spam - articles on "worst c mistakes" where someone writes about all the problems trigraphs cause, I guess because they are banned in some standards like misra. No I&
281.
▲
by
technion
3y ago
It's the correct answer today, in the same way that clicking "use a local account" was the answer yesterday. Ms will have this plugged at some point and our account managers are advertising this like it's a good thing.
282.
▲
by
technion
3y ago
I had an 800GB database and developers were putting up queries that took over ten seconds to run. I can be critical of Google at times but I'll never actually properly come to terms with how Google's search index is still so fast.
283.
▲
by
technion
3y ago
It would surprise me if it wasn't given my massive increases in rent paid, and absurd increase in advertised selling prices on basically everything.
284.
▲
by
technion
3y ago
I am talking about Tinder. The platform is at this point majority scam accounts, I'd probably put the number at 80% (speaking as a man looking at women at least) as fake. They'll send you a like, and they'll quickly talk abou
285.
▲
by
technion
3y ago
It would sure make you a good mark for the crypto scammers that have completely overrun the platform.
286.
▲
by
technion
3y ago
I cannot believe how absurd and out of hand this has gotten. Why did we not all standardise on some _well_known. subdomain or similar for these dozens of records? The part that gives me an eye twitch is so many domains have multiple verific
287.
▲
by
technion
3y ago
I think the ship has sailed with regarding making captchas harder to automate, tech is too good. However, my experience has been that if you can protect a comment form against a curl command, or a login form against wfuzz, it's done t
288.
▲
by
technion
3y ago
Although it's unclear, every time someone provides a one liner there are staunch not satire arguments about "covering edge cases you didn't think of" and I disagree. Look at the actual code: https://github.com
289.
▲
by
technion
3y ago
One of the big issues with the fp javascript trend was that coding patterns which work well in languages like closure or Haskell had a kind of "let's shoehorn this into js". There was a tonne of blogspot on "how to write
290.
▲
by
technion
3y ago
Malware delivered as an email with a link to a zip file containing a .js file is one of the most common methods of delivery, right behind word macros. The "map the .js extension to notepad.exe" is a common security trick with a me
291.
▲
by
technion
3y ago
That's horridly confusing given MS has a Rust crate "Windows" has a "UI" Module that I guess is something different to WinUI. https://microsoft.github.io/windows-docs-rs/doc/windows/UI
292.
▲
by
technion
3y ago
Last year I got asked to add some functionality to a commercial app. The app.... was Implemented as cgi scripts written in awk. There's a backed c app often called, if you call with the wrong input it just segfaults. "Hardest"
293.
▲
by
technion
3y ago
Using an Abortcontroller with fetch for example is only recently supported. I like to use it where I can, but I don't want to crash on a slightly older browser. Feature detection is absolutely practically useful.
294.
▲
by
technion
3y ago
I've always advocated for feature detection. If you test for typeof Object.assign !== 'function' you can be sure you have a reasonably recent browser. If you want fetch, test for window.fetch. This sort of thing always feels
295.
▲
by
technion
3y ago
Don't forget "functions that do totally normal things now need to be rewritten as a hook".
296.
▲
by
technion
3y ago
Speaking for the Australian market.... I had two Toyota Celia's and they were fantastically reliable cars. I would love to own another. But I look through the Toyota yard and everything there is a truck, or at least an SUV. So I have
297.
▲
by
technion
3y ago
I'm pretty annoyed by BIMI. We only just had Lets Encrypt shutdown the EV nonsense from the CA industry, and BIMI, which is only currently able to be signed by two super expensive providers, is their comeback. Aside from the fact it&#x
298.
▲
by
technion
3y ago
It's always worded as though you have some trivially exploited RCE, unless you pay them, someone will exploit it. To be fair I'm not suggesting they imply that they will exploit it, but it's always overblown in a way that imp
299.
▲
by
technion
3y ago
File sharing sites where you would download 13 .rar files and get yourself a .zip through to .z12 from the set.
300.
▲
by
technion
3y ago
One of the biggest difficulties I have with security is clients with the view "none would want to attack us". The problem is many ransomware gangs are opportunistic and will "target you" because you opened a word documen
More ›