Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
zemnmez
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
1.
▲
by
zemnmez
2mo ago
>Safer against injection: since the server renders and escapes the HTML before sending it over the channel, an attempt to sneak in a <script> travels as inert text and reaches your neighbor's screen as plain letters, not as co
2.
▲
by
zemnmez
2y ago
a few of my writeups discuss ways of doing this: appleid https://zemnmez.medium.com/how-to-hack-apple-id-f3cc9b483a41 steam https://hackerone.com/reports/409850
3.
▲
by
zemnmez
2y ago
i think what's being conflated here is that there are reasonably buyers for this kind of vulnerability but there's no market in the truest sense. I think a correctly connected individual could well sell this vuln to a state ac
4.
▲
by
zemnmez
2y ago
I apologise for my "but, actually...": Analogue clocks like the face of big ben are not like digital displays, and whether they "show seconds" in the context of the meaning of this article is not, like digital displays,
5.
▲
by
zemnmez
3y ago
OIDC+OAuth is what most people actually want when they think of OAuth imo. The main issue here is that OAuth was not designed as an authentication protocol.
6.
▲
by
zemnmez
3y ago
No, Google actually runs a remote web IDE called Cider. The latest version is derived from VSCode.
7.
▲
by
zemnmez
3y ago
check the zerodium pricelist for a general guide: https://zerodium.com/program.html
8.
▲
by
zemnmez
3y ago
This is absolutely because NK doesn't want to pay market rate for 0days.
9.
▲
by
zemnmez
3y ago
in the uk, most pay tax by an even simpler method, Pay as You Earn (PAYE). the taxes are all filed by the employer, and the online website allows taxpayers to add anything else
10.
▲
by
zemnmez
3y ago
Before the layoffs I worked on a security checks team (“ISE Hardening”) at Google. Google requires for almost all projects that code is physically imported into the SCS; when this code touches anything at all, extremely stringent security c
11.
▲
by
zemnmez
3y ago
I think this is what WhiteSource does. (it's also apparently called Mend now)
12.
▲
by
zemnmez
3y ago
I want to second this. The top StackOverflow comment for protecting against XSS in PHP still recommends htmlspecialchars() https://stackoverflow.com/questions/1996122/how-to-prevent-x... which is a terrible and an
13.
▲
by
zemnmez
4y ago
I think this kind of gets to the point of what protobuf is, and what a lot of tech is like at Google in general. I spent a lot of my career believing elegance and expressiveness was so important to strive for, even if we as engineers often
14.
▲
by
zemnmez
4y ago
wanted to correct this one: I confused Barbados with Jamaica here. Barbados is a republic. I am sure its laws still use the term "the crown", but it looks like it uses the term "Public Prosecutor" instead of "Crown
15.
▲
by
zemnmez
4y ago
“the crown” is an idea stemming from english constitutional law representing “the state”, i.e. the legal entity constituting the country. It doesn’t have a lot to do with the physical monarch except in metaphor. It looks like, based on some
16.
▲
by
zemnmez
4y ago
Surely this is a question of supply and demand and if a 4 day workweek is the legally cheap and good path supported by governments in the same way the 5 day workweek is, the competition for salaries will be nearly identical
17.
▲
by
zemnmez
4y ago
The logic here is somewhat sound. VSCode does sanitize by default, but Jupyter notebooks effectively need to run Python code on your machine to work. At that point (this is the meaning of trusted mode), it's not really worth protecti
18.
▲
by
zemnmez
4y ago
First-party (i.e. Google). Tricked in the sense I was asked to do a security assessment and didn't check what differential changes had been made edit: correct!
19.
▲
by
zemnmez
4y ago
I have been looking for something like this for so long!
20.
▲
by
zemnmez
4y ago
I can personally attest to the fact that yes, british citizens can assess vulnerabilities in UK government systems. This was something I worked with the UKNCSC on: https://www.ncsc.gov.uk/information/vulnerability-repor
21.
▲
by
zemnmez
4y ago
david is one of the smartest people I've ever worked with at Google. It's good to see him here :)
22.
▲
by
zemnmez
4y ago
Vary has no effect on the cors preflight cache: https://stackoverflow.com/questions/42848208/cors-preflight-...
23.
▲
by
zemnmez
4y ago
if you can query the DB directly from the frontend, what’s the security model? what prevents me from pulling sensitive data, passwords etc?
24.
▲
by
zemnmez
4y ago
Access-Control-Max-Age has, unfortunately a big security caveat which is that it is cached on a per-endpoint basis. Because Access-Control-Allow-Origin only allows one origin specification, if you previously used the Origin header to determ
25.
▲
by
zemnmez
4y ago
> Make something that works with with HTML and CSS alone, and enhance it with JS. Hydration is... an automated system to do this? Am I missing something
26.
▲
by
zemnmez
4y ago
i’m not really sure what you mean. most of these products are indeed reverse-proxies, but reverse proxies do not sit in front of the whole internet, just corporate services
27.
▲
by
zemnmez
4y ago
"With TLS verification captured by the extension it’s easy to confirm that any scraped data is authentic" hahaha yeah let me know what API you can use for that
28.
▲
by
zemnmez
5y ago
I mean, it is factually true that the Emperor in the east sent an envoy in 1095 to ask Pope Urban II for aid. I am not sure if the crusades would have happened without that.
29.
▲
by
zemnmez
5y ago
A lot of it was moved to Byzantium / Constantinople / İstanbul by Constantine, who tried to pay all the Roman elite he could, especially senators to move to his 'New Rome'. The ERE would continue to be wealthier until th
30.
▲
by
zemnmez
5y ago
This is the kind of thing I mean when I say "Americans give me weird anecdotes". 'Americans can't use washer-dryers because they're more fat than everyone else in the world' has got to be the strangest case of
More ›