Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
wsargent
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
61.
▲
by
wsargent
11y ago
There's two problems with the lookahead approach: 1) It only applies to the code you write. Libraries can still use insecure object serialization under the hood i.e. you can't apply this to an built in app server running JMX. 2)
62.
▲
Closing the Open Door of Java Object Serialization
(tersesystems.com)
1 points
by
wsargent
11y ago
|
0 comments
63.
▲
by
wsargent
11y ago
Jasypt is unfortunately prone to inventing its own crypto. This in itself leads me not to trust it. http://security.stackexchange.com/a/65240/6714
64.
▲
by
wsargent
11y ago
Thank you fsargent. You are a scholar and a gentleman.
65.
▲
Effective Cryptography in the JVM
(tersesystems.com)
5 points
by
wsargent
11y ago
|
2 comments
66.
▲
by
wsargent
11y ago
So much great code being checked in.
67.
▲
Monkeypatching Java Classes
(tersesystems.com)
2 points
by
wsargent
13y ago
|
0 comments
68.
▲
by
wsargent
13y ago
Try the Mechanic's Library, off Market St near the Crocker Galleria.
69.
▲
by
wsargent
14y ago
It's MD5 with a salt. "Since the hashed password is never exposed outside of our data center, we don’t think that the differences between MD5 and SHA-1 are relevant. I.e. the risks for MD5 are about producing two inputs that match the same