Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
wepple
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
121.
▲
by
wepple
2y ago
We love it. Can move on to the other two hundred problems to work on. Including where CNE will go next; logic and web bugs.
122.
▲
by
wepple
2y ago
Or an alternative approach: only compile the subset of features you explicitly need. Obviously there’s a ton of variance in how practical this is any place, but it’s less common than it should be.
123.
▲
by
wepple
2y ago
Nit: have orgies
124.
▲
by
wepple
2y ago
> I wouldn’t serve 30 days in jail for a billion dollars. You’d rather spend 50 years _totally free_ in your cubicle?
125.
▲
by
wepple
2y ago
There does seem to be an exception for public outlets. I clicked a link to NYPDs twitter and didn’t have to AuthN. Makes sense too; every org who wanted their content to be fully available to anyone would leave if twitter mandated login (Al
126.
▲
by
wepple
2y ago
The former, yes, but they’re far more expensive. The latter, kind-of. You have to have regular check-ins, dependent on the type of medication
127.
▲
by
wepple
2y ago
Very aware of that. That to me seemed like a targeted attack by a tracked APT group. What I’m referring to above is that the more vanilla attacks (ex: popular online mattress store gets popped) actually have national security implications,
128.
▲
by
wepple
2y ago
I forgot where I saw this, but the US govt recently announced that they see mass PII theft as a legitimate national security issue. It’s not just that you or I will be inconvenienced with a bit more fraud or email spam, but rather that larg
129.
▲
by
wepple
2y ago
So, what do you do once you’re on the map and so are other people?
130.
▲
by
wepple
2y ago
I have a strong standing dislike for Microsoft, but I’ve gotta agree here. It sounds like they’re having a summit with partners and… those are typically never open to the public, so um? Are we going to start renaming meetings to “conference
131.
▲
by
wepple
2y ago
Sorry, when I said OTP I mean the recovery code OTP. They’re often 16 hex, so 16^16
132.
▲
by
wepple
2y ago
> It is unclear why generating a one-time password for the user is bad but if we call the password a "recovery code" it is suddenly sufficient. The OTP is usually very long, highly randomized (you don’t get to choose Summer2024
133.
▲
by
wepple
2y ago
This looks like any other public key crypto authentication (U2F) but more complex and less universally adopted? How is this better than OIDC?
134.
▲
by
wepple
2y ago
TOTP is trivially phishable. Code security is orthogonal to end-user authentication methods. So, wrong on every count.
135.
▲
by
wepple
2y ago
Not a hot take at all, for anyone who has worked with securing code. SWEs simply aren’t trained to deeply examine code and the side effects of it being pressured by skilled attackers. 2+ LGTMs reduces the change of a security issue making i
136.
▲
by
wepple
2y ago
I’m curious too. Perhaps they mean getting others to do all the scouting to near guarantee a successful hunt? I spend a ton of time in the woods reading sign and just generally being aware & learning. Ton of hours and boot leather burne
137.
▲
by
wepple
2y ago
Whilst hunting might involve the killing & taking of an animal, it 100% relies on there being a healthy population to begin with. Not to mention, hunting is actually very difficult (contrary to a lot of belief). You end up spending a ph
138.
▲
by
wepple
2y ago
I recall reading about this in “The Scavengers Guide to Haute Cuisine”. In it. Steven Rinella creates a feast from Escoffier’s classic book. Excellent read.
139.
▲
by
wepple
2y ago
I believe both cases come down to how much effort the leaders put into identifying and purging the bad activities on their platforms. One would hope that there is clear evidence to support a claim that they’re well aware what they’re profit
140.
▲
by
wepple
2y ago
I think that’s what we’re doing today, and it’s a phenomenal mess. The typical HTML page these days is horrifically bloated, and whilst it’s machine parsable, it’s often complicated to actually understand what’s what. It’s random nested div
141.
▲
by
wepple
2y ago
Yeah, very very important point
142.
▲
by
wepple
2y ago
I bet that too is a ton of what drives interest, the platform angle was just the primary thing that came to mind now that that’s more the world I think about The piracy discussion is also hugely fascinating; I’m sure a good portion of HN re
143.
▲
by
wepple
2y ago
Perhaps the meta-message here is that you absolutely have to design for cryptographic agility. You may not need to jump to the next best thing every 3 years, but as certain constructs are proven weak, you’ll need to start migrating systems
144.
▲
by
wepple
2y ago
There’s a substantial ongoing debate about how much responsibility a platform as for what users do on that platform. Nearly everyone in tech is affected by that. The theatrics and drama of it is a silly distraction, but the fundamental ques
145.
▲
by
wepple
2y ago
I do not categorize him as “small folk like us”
146.
▲
by
wepple
2y ago
“Carefully” is very load bearing. A similar but different class of issues common to web stacks is when you have proxies and multiple layers of HTTP “things”, especially when they parse data differently (eg: nginx fronting Apache)
147.
▲
by
wepple
2y ago
No surprises, they’re late stage enshittification.
148.
▲
by
wepple
2y ago
Oh yeah, I’d absolutely not want to have a raw unfiltered inbound bug bounty and be first line of triage, so paying H1 or Bugcrowd is the way to go. But you’re also paying them to make sure the serious bugs absolutely do get to you, and if
149.
▲
by
wepple
2y ago
Bugcrowd is no different. The folks doing Triage often don’t comprehend even simple security issues. I’m convinced it’s largely designed to keep people from going full disclosure rather than actually getting bugs fixed.
150.
▲
by
wepple
2y ago
What’s that understanding based on?
More ›