Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
werrett
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
werrett
2y ago
Out of interest -- Why put PHI in your SCM? If you're just wrangling code but not actual data SaaS should be kosher.
32.
▲
by
werrett
2y ago
Started off reasonable and interesting and the slid into: > For people looking for a conspiracy, the replacement language for C++, Rust, is compromised by a cabal of woke tards that are doing strange things. It's possible this could
33.
▲
by
werrett
2y ago
lol. no. besides which all of these hacks would have been prevented by simple, well established controls (eg. MFA everywhere, not hoarding every scrap of customer data and internal comms). so all of those basics are going to magically happe
34.
▲
by
werrett
2y ago
Doubly so given that Untitled Goose Game is from an Australian game studio. https://en.wikipedia.org/wiki/House_House
35.
▲
by
werrett
3y ago
I mean, it's arguably a security concern if you're not catching the mistakes you intended to catch.
36.
▲
by
werrett
3y ago
You know that is a direct result from competition from rideshare alternatives, right? Growing up in the late 90s and early 2000s, taxis always added an exciting extra frisson to any airport trip or evening date. Would they turn up at all? W
37.
▲
by
werrett
3y ago
Based solely on the above description -- wire-only is when you don't have wheels on deck, also slowing the craft down.
38.
▲
by
werrett
3y ago
Yes. A bunch. Service accounts that need to be shared between a limited group of people. TOTP + something like 1P moves this from happy-monday-an-infra-engineer-left-time-to-rotate-100-accounts to something you can just do periodically as
39.
▲
by
werrett
3y ago
You’re being purposefully reductionist. But even if that’s that’s the sole purpose any one would do seek an MBA the GPs point stands — reading this list doesn’t even tick the “MBA checkbox”
40.
▲
by
werrett
3y ago
It’s crazy that 3M is still selling “fabric protectors” today [1] that rely on PFAS. Not that you can tell based on the product listing or packaging, but they do publish a handy data sheet [2] that lists “< 3% fluorochemical urethane”. U
41.
▲
by
werrett
3y ago
Hashicorp Vault or (AWS|GCP) Secrets Manager would be the common answer. There is also the startup Doppler ( https://www.doppler.com/ ) that is directly taking on the Hashicorp Vault space. It’s probably easier to get up and
42.
▲
by
werrett
3y ago
“I’ll be there in 7 minutes” is my standard answer when I know it’s going to be more than 5, probably less than 10.
43.
▲
The secret experiment behind the Expensify Lounge
(use.expensify.com)
1 points
by
werrett
3y ago
|
1 comments
44.
▲
by
werrett
3y ago
> Going to the office is no longer a necessity. It's a choice. And we wanted to know what, if anything, would cause people to voluntarily choose to go back to the office when the entire rest of the world (including the comfort of
45.
▲
by
werrett
3y ago
This is a naive take. Okta solves both security and non-security problems. If they keep undermining the 'security' bits they will 100% get ditched. Assuming there is a credible alternative . But I'd argue there isn't a
46.
▲
by
werrett
3y ago
lots of people beg to differ. https://www.youtube.com/watch?v=b15-P12gIf0&t=80s&pp=2AFQkAI... [its bond/connery with the fry]
47.
▲
by
werrett
3y ago
Not to be much of a shill but iOS’ focuses are great for this. Create a ‘chillin’ mode that kills all notifications and still lets you use maps. I am sure Android has similar.
48.
▲
by
werrett
3y ago
We all got jobs in comp security when we turned 20 ;)
49.
▲
by
werrett
3y ago
Yes, it was. https://medium.com/@seanwilliams85/weworks-kindergarten-is-a...
50.
▲
by
werrett
3y ago
Using CloudFlare DNS by any chance? Archive.ph Getting Cloudflare Blocked? https://news.ycombinator.com/item?id=37082908
51.
▲
by
werrett
3y ago
It’s not not a myth. Not even really lost to time (or a simple Google search). E.g https://www.reddit.com/r/Bitcoin/comments/1zti1p/17956_hacke... https://www.wired.com/2015/07/
52.
▲
by
werrett
3y ago
Err, no. Compromising your email account will for sure be the worst outcome. Everything else, including your OpenAI account, are accessible via that email account + a password reset.
53.
▲
by
werrett
3y ago
It’s the latter. Lot’s of companies loosing their zero-interest rate valuation but funds have always needed to mark down swollen private valuations. Fidelity marks down stake in pre-IPO startups Cloudera, Dropbox March 30, 2016 https:&#x
54.
▲
by
werrett
4y ago
While getting rid of passwords is admirable and advisable, I don't think it is the answer here. What happens when `JSON.stringfy` posts your fancy magic link token somewhere undesirable? Applications will always need to generate, proce
55.
▲
by
werrett
9y ago
Hey Adam, you should probably avoid marked.js. It suffers from a number of security issues [1] and it's unmaintained (or at least the maintainer is AWOL and without him new releases can't be tagged). Markdown-it is probably a good
56.
▲
D'Oh My Zsh – How I unexpectedly built a monster of an open source project
(medium.com)
380 points
by
werrett
11y ago
|
97 comments
57.
▲
by
werrett
11y ago
Yup! Daily. FeedBin (service) and Unread (iOS) to follow infosec peeps, infosec company PR releases and a few security-focused subreddits. The subreddits don't work so well via RSS. Shrug.
58.
▲
by
werrett
12y ago
I love the way this reads: > The brain is surprisingly plastic... all the way into 40s and beyond I'll give you the benefit of the doubt and it is probably factual. But it reads like 40s is "advanced". What should we consi
59.
▲
Cyber-crime: Think of a number and double it
(economist.com)
2 points
by
werrett
12y ago
|
0 comments
60.
▲
The new age of crony capitalism
(economist.com)
2 points
by
werrett
13y ago
|
0 comments
More ›