Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
xrstf
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
30 ms
·
91.
▲
by
xrstf
11y ago
That's not an adjective, that's a reference to Taylor Swift on Security. SCNR.
92.
▲
by
xrstf
11y ago
Do not confuse Germany's prior superiority with made goods with their IT skills. As a German, I can tell you: We're becoming a 3rd world IT country real quick. Plus the USA is our best friend, including the NSA.
93.
▲
by
xrstf
11y ago
> The server immediately started having problems, and every flaw in the message handling code suddenly became glaringly obvious. We quickly added another server and that seemed to hold off the worst of the problems (for the curious, we a
94.
▲
by
xrstf
11y ago
See also http://www.ietf.org/blog/2015/02/http2-approved/
95.
▲
by
xrstf
11y ago
One point of doing REST instead of RPC is because you shouldn't re-invent the wheel. HTTP already has verbs and identifiers, so why create another set of verbs (the RPC methods)? REST is embracing HTTP to its fullest, RPC[overHTTP] is
96.
▲
by
xrstf
11y ago
I did the exact same thing in a project of mine. We're shifting away from that and put our data in cookies, so we can cache some of the things our API send out.
97.
▲
by
xrstf
11y ago
At the company I work for, we don't have a paid Slack account for our team, but I remember at least one of my coworkers using his regular IRC bouncer to connect to Slack. Maybe they changed the rules since the last time you checked?
98.
▲
by
xrstf
11y ago
A few mockups or screenshots would have helped me immensely to understand this "next gen text-based-programming killer", that is ironically described exclusively in plaintext. In my head, ideas range from visual programming langua
99.
▲
by
xrstf
11y ago
It is. I want to finally understand why and how I can secure a login form against CSRF (i.e. when I don't yet have a session for the visitor).
100.
▲
by
xrstf
11y ago
The CSRF token is generated on login and then stored in the user's session. We accept the risk of not having a per-form token for pure developer/user convenience reasons.
101.
▲
by
xrstf
11y ago
What's the advantage of still having the cookie with some value in it when we use a random token as a hidden form value plus this token being stored on the server? Your suggestion seems overly complex to me, so maybe I'm missing a
102.
▲
by
xrstf
11y ago
My takeaway from this: `Set-Cookie` and `User-Agent` headers are great places to hide stuff and sneak it by IDS.
103.
▲
by
xrstf
11y ago
Current workaround: Restart the estimated 28 U.S. planes at least every 120 days[1]. Wonder how long it could take for the update to be actually available (after testing, approving, ...). Are we talking weeks, months, years? [1] https:
104.
▲
by
xrstf
11y ago
Thanks. So the 1.7 mainline version on the downloads page should be "1.9 mainline" soon?
105.
▲
by
xrstf
11y ago
I'm always confused by nginx's version scheme. What does "mainline" mean? Is mainline better or worse than stable?
106.
▲
by
xrstf
11y ago
Oh how I love it to fetch a package via NPM, thinking it's gonna be JS-only and then being greeted by compiler errors because I don't have a C compiler setup on my Windows machine. Without falling on my face or reading the very en
107.
▲
by
xrstf
11y ago
You are looking for setImmediate[1]. EDIT: Oh, never knew that this method was a Node-ism only. [1] https://developer.mozilla.org/en-US/docs/Web/API/Window/setI...
108.
▲
by
xrstf
11y ago
The same holds true for Silex[1], the Symfony Components-based micro framework. Silex and Lumen look very similar (not only because Laraval/Lumen use Sf Components as well), not only because both use (just as Laravel) Sf Components. Sl
109.
▲
Ext4 encryption patches for Android
(thread.gmane.org)
39 points
by
xrstf
12y ago
|
9 comments
110.
▲
by
xrstf
12y ago
A few things I noticed while reading through the readme: * For me to consider using a PHP library in 2015, it must support Composer. * Currently, a lot of the API is static. This makes it hard to inject the template engine as a helper int
111.
▲
by
xrstf
12y ago
Is hoogle a special search engine for Haskell code or was that an unintentional typo?
112.
▲
by
xrstf
12y ago
I remember reading somewhere that PGP is not suited for realtime web chats. Can't explain precisely why or cite sources, though.
113.
▲
by
xrstf
12y ago
Nice idea. For anyone wondering how it looks in Chrome on Windows 7: http://imgur.com/Weu6dpG -- so I hope that it doesn't catch on [until my OS can handle it]-
114.
▲
by
xrstf
12y ago
You are right, my times are apparently somewhat dated. HHVM 3.6 actually gives me 1.88 seconds with costs of 15. Good thing you made me re-measure :) That makes 13 my new bcrypt default.
115.
▲
by
xrstf
12y ago
If I set bcrypt cost to 11, hashing takes 0.1 seconds . At 12, it takes 1 second roughly. Setting it to anything higher leaves my service open to Denial-of-Service attacks, so I'm very hesitant to increase the cost factor. To you have
116.
▲
by
xrstf
12y ago
> 1. Scheduled to come out in Q4 2015 ... and available on general cheap webhosting sometime around 2020. If we're lucky. Thank god our company slowly moved away from building small PHP websites that have to run on the most fucked u
117.
▲
by
xrstf
12y ago
Blue links on bright orange background. Nicely done.
118.
▲
by
xrstf
12y ago
Slashes are not possible, that makes it hard to load code from somewhere.
119.
▲
by
xrstf
12y ago
Thanks for this explanation! :)
120.
▲
by
xrstf
12y ago
> "If it doesn't load through curl, it's broken." --someone So, so true. Thanks, curl.
More ›