Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ybx
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
ybx
11y ago
A better analogy is the one that's twisted to fit my narrative. (both you and the parent comment are kinda doing this)
32.
▲
by
ybx
11y ago
"does that license apply retroactively to a checkout of the first N-1 commits" No, unless you explicitly state it somewhere (and even then, I'm not certain). If they add a license to the older commits via rewriting history th
33.
▲
by
ybx
11y ago
It would probably have to be the entire IP address space, since they could transparently source NAT on the MITM server to make it look like it's coming from the user's IP.
34.
▲
by
ybx
11y ago
It's pretty clearly a joke, as he "makes the mistake" that he was just describing was something you needed not to do.
35.
▲
by
ybx
11y ago
> are so naive to waste electricity on collossal scales. I know right? The last time I had to use 20 watts for an extra 5 seconds nearly bankrupted me
36.
▲
by
ybx
11y ago
It's probably not at the point yet where you'd be interested in it (especially for tooling), but you might like Rust in the future.
37.
▲
by
ybx
11y ago
I presume a collection can have multiple of the same thing, whereas a set cannot?
38.
▲
by
ybx
11y ago
Well for one, LXC isn't necessarily a "thing" in itself - it's a combination of several Linux kernel systems (one of which is cgroups) that together provide machine-like containers.
39.
▲
by
ybx
11y ago
How does flexible mean do it well? "Do it well" is so vague of a saying that it really could mean any of those things, whether it be flexibility, or simplicity, or etc.
40.
▲
by
ybx
11y ago
Is SSH really a dependency you have to worry about though? Basically every server out there runs SSH.
41.
▲
by
ybx
11y ago
Yeah, there are plenty of authentication systems out there for this kind of thing, and preferably something like SRP would be used.
42.
▲
by
ybx
11y ago
From a usability perspective, it's probably because dealing with keys that can't just be memorized is hard for most people.
43.
▲
by
ybx
11y ago
The idea is that you're implicitly trusting the company (or website), as well as anyone who has (whether legit or not) access, to only keep that password in memory, and it's preferable to authenticate without requiring that trust.
44.
▲
by
ybx
11y ago
You're still passing the output to the server, which can be repeated. Certainly better than just a password, but not as good as public key crypto. In the end, I'd probably prefer something like SRP
45.
▲
by
ybx
11y ago
The difference here though, is that the private key is not being sent verbatim to the server.