Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tkadlec
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
Will serving real HTML content make a website faster?
(blog.webpagetest.org)
186 points
by
tkadlec
4y ago
|
106 comments
2.
▲
by
tkadlec
5y ago
I built the site and I agree. :) Two things: 1. The data is in the process of being updated. Prices change quickly and from the trend of past changes I fully expect these prices to drop as soon as I make the change. 2. While the ITU (and ot
3.
▲
by
tkadlec
5y ago
You probably already noticed, but you can also access site cost data from the WebPageTest itself. (Note the cost column in the metric summary for your linked test, for example: https://www.webpagetest.org/result/210707_
4.
▲
by
tkadlec
6y ago
Bytes over the wire (I can clarify in the post too). So _most_ of that weight is gonna have gzip or brotli applied. (Last I looked, around 17% of JS requests recorded by HTTP Archive are uncompressed.)
5.
▲
by
tkadlec
6y ago
I suspect you're absolutely right! :) Using jQuery is definitely a different style of development than using something like Angular/Vue/React. I tried to clarify in the post (under "The Big Picture") that the data s
6.
▲
by
tkadlec
7y ago
Hopefully that's not the way it comes off! The entire last section of the article is my attempt to make it clear that this _doesn't_ happen because we're bad people. > So clearly, folks who have built a heavy site are bad,
7.
▲
Serverless Security: What's Left to Protect?
(infoq.com)
38 points
by
tkadlec
9y ago
|
18 comments
8.
▲
by
tkadlec
9y ago
> What I'm getting at is maybe AMP is Google's way to make the problem easy. Sometimes when a general problem is difficult, you're better adding restrictions to make the problem tractable. It absolutely is! (Sorry if I mad
9.
▲
by
tkadlec
9y ago
First off, you're right: any metric can be gamed. Even so, Google is already using performance to factor into its algorithm, so some level of reasonable accuracy must have already been agreed upon. Ensuring a certain level of performan
10.
▲
Building an Investor/Founder Community with Boldstart’s Ed Sim
(heavybit.com)
2 points
by
tkadlec
9y ago
|
0 comments
11.
▲
We'll know DevSecOps has won once it's dead
(snyk.io)
1 points
by
tkadlec
9y ago
|
0 comments
12.
▲
by
tkadlec
9y ago
Not by itself, but it does provide a portion of what is needed. Specifically: > The developer may want to use the policy to assert a promise to a client or an embedder about the use—or lack of thereof—of certain features and APIs. For ex
13.
▲
by
tkadlec
9y ago
FWIW, they did let performance factor, slightly, into ranking, but there was never a "fast" icon (one was rumored, but never shipped). An icon like that would've easily motivated folks, no need for AMP to be involved. That be
14.
▲
by
tkadlec
9y ago
Automated tooling is a must, yes. The riskiest part about relying on ONLY GH's solution (IMO) is the NVD/CVE limitation. I agree, CVE would be _awesome_ in theory. In reality, very few file for CVE's and so the coverage is if
15.
▲
The 2017 State of Open Source Security from Snyk
(snyk.io)
20 points
by
tkadlec
9y ago
|
0 comments
16.
▲
by
tkadlec
9y ago
Completely agree! The post actually alludes to that a bit towards the end. > Single Page Apps increase the amount of client side logic and user input processing. This makes them more likely to be vulnerable to DOM-based XSS, which, as pr
17.
▲
XSS Attacks: The Next Wave
(snyk.io)
88 points
by
tkadlec
9y ago
|
43 comments
18.
▲
Top 50 breaches data challenges the OWASP Top 10
(snyk.io)
17 points
by
tkadlec
9y ago
|
0 comments
19.
▲
Snyk introduces security monitoring for serverless applications
(snyk.io)
53 points
by
tkadlec
9y ago
|
0 comments
20.
▲
by
tkadlec
9y ago
Ha! I'll try to add some decimal points for sub $.01 sites.
21.
▲
by
tkadlec
9y ago
This is a very fair point, sir. I'll pull the phrase.
22.
▲
by
tkadlec
9y ago
Yeah, it's a rounding thing. I'm guessing your site is so lightweight that the cost ends up being negligible. You should be able to click through from the result page to a fully detailed report from webpagetest.org.
23.
▲
Serverless security implications from infra to OWASP
(snyk.io)
114 points
by
tkadlec
9y ago
|
14 comments
24.
▲
77% of sites use at least one vulnerable JavaScript library
(snyk.io)
13 points
by
tkadlec
10y ago
|
0 comments
25.
▲
Type Manipulation: Escaping Template Sandboxes
(snyk.io)
8 points
by
tkadlec
10y ago
|
0 comments
26.
▲
[Podcast] Making security more inclusive
(heavybit.com)
2 points
by
tkadlec
10y ago
|
0 comments
27.
▲
by
tkadlec
10y ago
> * The complete list of the 72 libraries that were tested? I could not find it. Me either. They list out the 30 most popular of those 72, but I can't see the full list. Yet another reason why the 37% they report may be underselling
28.
▲
by
tkadlec
10y ago
Really depends. How big is the once CSS file you're loading and how much of the CSS is common from page to page? If 20kb is for a specific component on one or two, less-visited pages, then it probably doesn't make sense to lump ev
29.
▲
The Frequency of Known Vulnerabilities in JavaScript
(snyk.io)
170 points
by
tkadlec
10y ago
|
57 comments
30.
▲
[video] Exploiting Real-World XXE Vulnerabilities in Nokogiri
(youtube.com)
6 points
by
tkadlec
10y ago
|
0 comments
More ›