Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tprynn
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
tprynn
7y ago
How can I opt out a virtual card number through Apple Pay? It doesn't seem that you can get the full "Device Account Number".
32.
▲
by
tprynn
7y ago
iOS won't consider itself connected to a WiFi network until it can hit that domain and get the response it expects, but some networks want you to be connected even though they don't actually give you full internet access. For exam
33.
▲
by
tprynn
7y ago
Yes and yes, the $5 droplet is perfect for wireguard.
34.
▲
by
tprynn
7y ago
The animation effect seems to be adapted from the Yellowtail project which they cite as inspiration. Original: http://flong.com/projects/yellowtail/ JS Port: https://github.com/n1ckfg/yellow
35.
▲
A Hacker Guide to Deep-Learning Based AES Side Channel Attacks
(elie.net)
4 points
by
tprynn
7y ago
|
0 comments
36.
▲
Deconstructing the Phishing Campaigns That Target Gmail Users
(elie.net)
1 points
by
tprynn
7y ago
|
0 comments
37.
▲
by
tprynn
7y ago
The reason not to implement this in inline assembly is that you would have to implement unique assembly for each architecture supported, which would mean probably dozens of different implementations, especially considering that even on a gi
38.
▲
by
tprynn
8y ago
That's only true with Do Not Disturb, which also silences all other notifications as well, a major drawback (for me, at least).
39.
▲
by
tprynn
8y ago
It doesn't matter what algorithm you use to hash passwords when users login if you also store them md5-ed somewhere else!
40.
▲
by
tprynn
8y ago
I flagged this comment because it seems to be an obvious violation of the HN guidelines: * Eschew flamebait. Don't introduce flamewar topics unless you have something genuinely new to say. Avoid unrelated controversies and generic tang
41.
▲
by
tprynn
8y ago
I flagged this comment because I believe it is far outside of appropriate discussion to dehumanize someone in the way your comment does. For other commenters, the original comment before editing said: "And now this thing works for the
42.
▲
by
tprynn
8y ago
Slightly directed at a sibling comment, but yes indie games (can) make a significant amount of revenue through non-release sales, even at heavy discounts. For example, Dustforce more than doubled its cumulative revenue through a 50% steam s
43.
▲
by
tprynn
9y ago
Then your comment is off-topic, because the realm of discussion was explicitly "self-driving cars equipped with LIDAR". Uber's self-driving vehicles are all equipped with LIDAR, as are basically all other prototype fully-auto
44.
▲
by
tprynn
9y ago
I found the easter egg! Hilarious way to handle the quora-like "subscribe for more", and actually got me to subscribe. I won't spoil it for others.
45.
▲
Boeing 757 Testing Shows Airplanes Vulnerable to Hacking, DHS Says
(aviationtoday.com)
2 points
by
tprynn
9y ago
|
0 comments
46.
▲
by
tprynn
9y ago
I don't think you'll find many people in the security industry who think ProtonMail is anything but a joke. I'll leave you with this (written by 'tptacek): https://www.nccgroup.trust/us/about-us/
47.
▲
by
tprynn
9y ago
Looking back at my notes, I think my earlier comment was misleading. The offline brute force was due to an insecure random number generator, which allowed an attack against B to recover b (and from there crack the 8 digit code). So, uh, ...
48.
▲
by
tprynn
9y ago
1Password uses TLS, and SRP inside TLS. If TLS is broken as in Cloudbleed, SRP hopefully still protects the channel - at least against non-active attacks such as Cloudbleed. The security still ultimately relies on TLS. Having not read the d
49.
▲
by
tprynn
9y ago
I haven't read enough about the other PAKEs to know what offline attacks look like there, but the fact that they are endemic to PAKEs is a total footgun. For example, one implementation of SRP I looked at used 8-digit codes (e.g. 12345
50.
▲
by
tprynn
9y ago
While this is interesting historical reading, SRP is badly outdated and should not be used for any newly built systems. It has a lot of non-obvious failure modes around parameter handling and offline password cracking that have broken the a
51.
▲
by
tprynn
10y ago
You are wrong. Many states have laws against this type of deceptive pricing, and it's against the FCC's guidelines as well: http://www.ecfr.gov/cgi-bin/text-idx?SID=0fe5a1d5614a06c2f27...
52.
▲
by
tprynn
10y ago
Other comments have mentioned the obvious issue that you can't use this feature across multiple browsers. So you still need CSRF tokens, and the title is just wrong. He also mentions checking the origin/referrer header. I would st
53.
▲
by
tprynn
10y ago
You are wrong. The 'origin' of a script is the domain which loads it, not the domain where it is hosted. (Those can be the same, though.)
54.
▲
by
tprynn
10y ago
The average user does not know anything about encryption! But they have heard about hacking, so they know that if a popular paper is reporting something as insecure, they shouldn't use it. What will they use instead? Whatever is availa
55.
▲
by
tprynn
10y ago
Not to be too pointed, but would you consider adding this disclaimer to your blog post and github repo? Hopefully that will inform potential users before using a system that could leave them less secure.
56.
▲
Testing Random, Valid SQL in CockroachDB
(cockroachlabs.com)
34 points
by
tprynn
10y ago
|
2 comments
57.
▲
Reviewing bug bounties – a hacker's perspective
(skeletonscribe.net)
2 points
by
tprynn
10y ago
|
0 comments
58.
▲
by
tprynn
10y ago
Thanks for your clear argument. I was definitely arguing 'past' the parent, and this helped me to see that. Won't hide my shame at completely missing the point.
59.
▲
by
tprynn
10y ago
The discussion of cigarette sales/taxes is clearly a strawman. If you believe that we shouldn't have laws unless we are willing to kill to enforce them, you should be able to defend this argument against a law which the vast major
60.
▲
by
tprynn
10y ago
The fact that Signal exists, and I can use it every day with friends and coworkers, is evidence that we are not locked in. No one is making money from Signal, and anyone who uses Signal can switch to any of ten different (less secure) apps
More ›