Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
zer01
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
zer01
5y ago
What did the first cell phone cost? The first laptop? Every new piece of technology goes through a cycle where things are wildly inefficient and barely operable, but over time they're refined in a loop of iteration and improvement. Vac
32.
▲
by
zer01
5y ago
The eth classic fork was because of the first high profile hack of a smart contract leading to massive loss of funds (way way back in 2016 - https://en.wikipedia.org/wiki/The_DAO_(organization) ). The Ethereum community
33.
▲
by
zer01
5y ago
Right, so what's happening right now is much more akin to the early days of the internet than anything else IMO. In the same ways we couldn't have ever predicted Facebook, Google, iPhones, etc, in the 90s it's hard to say exa
34.
▲
by
zer01
5y ago
If you just want to store and host files like a website, there's a few projects in that vein that I know of - Arweave ( https://www.arweave.org/ ), IPFS ( https://ipfs.io/ ), and Filecoin ( https:/&#x
35.
▲
by
zer01
5y ago
I typically use DRF + Django for the backend and then have one “view” that renders an index.html with a context bridge (passed via a global JS variable) so I can bootstrap the front end with enough server side state to load quickly (and do
36.
▲
by
zer01
5y ago
I love Python, and I love Django, but I think async support would be a bad idea personally. I’ve written a lot of things using asyncio and steered into it hard when it was first stable, but I’ve found it cumbersome and (zooming out) pretty
37.
▲
by
zer01
5y ago
Malware detection uses it as a heuristic to peg specific “variants” to each other. Basically LSH is great for comparing corpuses of data that are slightly different. If you hash the data using something like SHA256 and even one byte is diff
38.
▲
by
zer01
6y ago
For me it’s actually more about isolation and security. I touch and build a lot of random code and docker gives me some good assurances that a transient dependency of a dependency somewhere in the pits of NPM install hell won’t do things li
39.
▲
by
zer01
6y ago
My hope is that those of us who feel like spinning wheels can show solidarity through a simple gesture of clicking a button, and those of us who may need it can find tangible proof that there are other Americans out there who care, share yo
40.
▲
Show HN: I built a living memorial to George Floyd and others
(stand-in-solidarity.com)
3 points
by
zer01
6y ago
|
1 comments
41.
▲
by
zer01
7y ago
I'm firmly in this camp as well. A strong code quality metric is how easily understood something is - we write code in all sorts of states of minds at all hours of the day. If others can read your code and understand it, it means you c
42.
▲
by
zer01
7y ago
> I also write Go code without missing generics, but that’s because I’m also fluent in other languages, and tend to use those when I want something ill-suited to Go, rather than trying to force Go into that shape. I think this should be
43.
▲
by
zer01
7y ago
This has absolutely been my experience as well. Golang is good at being fast, but to say that it helps write better code because of its missing batteries/features is just silly I think. "I want to interact with a REST API and pull
44.
▲
by
zer01
7y ago
This PNG parser in Elixir uses pattern matching in an elegant way. https://gist.github.com/zabirauf/29c89a084901cab8bc6b Parsing binary data can be...nontrivial. The beauty is in the code that doesn't exist.
45.
▲
by
zer01
7y ago
Yeah if you're going to sling shit like this, link to your sources. I've handled incidents involving both ecosystems over the past year and they're pretty comparable. NPM also bought a security company ( https://blo
46.
▲
Electrohunt Part 1: Hunting for the phishing campaigns on the Electrum network
(blog.coinbase.com)
3 points
by
zer01
8y ago
|
0 comments
47.
▲
by
zer01
8y ago
I'm just coming off a 7 month stint in an RV myself, and you speak the truth, and it's clear you've actually done full time living on the road. Dealing with sewage is a huge pain in the ass - especially if you're in the
48.
▲
by
zer01
9y ago
Having used Bulma for a few years now to build everything from product to open source stuff, I highly recommend it! It's currently in use both at https://phishfinder.io and https://certstream.calidog.io
49.
▲
by
zer01
9y ago
This...is actually 100% true. One of the biggest struggles I've personally had in security is to not be super jaded and cynical. Helps immensely to not be in an organization that tolerates (or even rewards) shoddy security practices
50.
▲
by
zer01
9y ago
It almost always pays to have your finger on the pulse of whatever industry you're looking to recruit from. If someone posts a neat article on something that's relevant to your problem space, don't be bashful and reach out to
51.
▲
by
zer01
9y ago
> is to act as a minimum level legitimizer for those willing to acknowledge a lack of experience True, but there are a lot of bullshit certifications out there that either 1.) vastly over project the actual knowledge people glean from
52.
▲
by
zer01
9y ago
> the excessive profanity is unprofessional and distracting I strongly disagree. Most security shops I've been in are made up of people who are blunt and speak exactly like that. You absolutely do need to be able to conduct yourse
53.
▲
by
zer01
9y ago
This is along the lines of the advice I also give people, it generally boils down to a few things: - Be hungry - I'm willing to spend hours with someone who's hungry and just lacks knowledge or a mentor - Be humble - Always unde
54.
▲
by
zer01
9y ago
SANS certifications are the only ones I think hold any actual water. People tout the CISSP like it teaches you anything but the very basics and use that to call themselves professionals, which is a huge red flag in hiring.
55.
▲
by
zer01
9y ago
> Your variable pricing is super interesting. Thanks! My goal is to make this extremely affordable protection. > I’d love to know how that turns out. Me too! If you follow me on twitter you can keep tabs :) https://twitter.
56.
▲
by
zer01
9y ago
Hey all, CEO of Cali Dog Security here. This is our first product and we're excited to show it to the world! We're also looking for feedback! Announcement blog with more details here - https://medium.com/cali-dog-s
57.
▲
Show HN: PhishFinder – Find phishing campaigns before they find you
(phishfinder.io)
5 points
by
zer01
9y ago
|
3 comments
58.
▲
by
zer01
9y ago
Hmm, that's an interesting thing I haven't given much thought to. I think that it would be somewhat difficult to pull off a correlation attack/leakage as the CTLs tend to dump in batches vs every poll returning new results, b
59.
▲
by
zer01
9y ago
Thanks for the heads up! It also isn't displaying the favicon properly it seems :-/. https://media1.giphy.com/media/R54jhpzpARmVy/giphy.gif TL;DR - Curse you Webpack! ::shakes fist::
60.
▲
by
zer01
9y ago
Interesting! I haven't been able to attend Defcon in the past few years so I haven't seen that talk (or heard of his research), but it's something I've thought about for a while now - using CTLs as a means to jump into t
More ›