Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
zwp
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
16 ms
·
91.
▲
by
zwp
9y ago
I know an email address that appears in this leak but not in any other leak that hibp knows about. That might invalidate that hypothesis (or alternatively hibp's dataset might not be as complete as it could be).
92.
▲
by
zwp
9y ago
> i milanesi hanno percorso in media 18,6 miglia > in bici per andare al lavoro... > velocità media a Milano 14,8 miglia all’ora "The Milanese cyclist averages 18.7 miles per day to go to work... at an averag
93.
▲
by
zwp
9y ago
> Sounds like a bug in GNU's ld.so more than anything. It's neither unique to glibc (AIX, Solaris) nor to LD_LIBRARY_PATH (PATH), nor trailing colons (leading colons, adjacent colons). This de facto standard becomes a little mo
94.
▲
by
zwp
10y ago
> should have "set -eu" at its second line Do you have a strong reason to prefer "set" over shebang flags? I have a slight preference for shebang flags so I can deliberately override them from the command line (but it
95.
▲
by
zwp
10y ago
I too don't see how it is useful but it's certainly a thing. The Solaris implementation looks like this: #!/bin/ksh -p # ... cmd=`basename $0` $cmd "$@" I just noticed that the what(1)-stri
96.
▲
by
zwp
10y ago
My intermediate steps were: "word equivalence classes" and "[flawed] fundamental theorem of arithmetic^Wspelling", and then you have it.
97.
▲
by
zwp
10y ago
> regret not recording the source of it The googlable nugget is actually "organizational scar tissue" (it caught my attention too). It's from Jason Fried. On twitter: https://twitter.com/jasonfried/sta
98.
▲
by
zwp
10y ago
Link to the comment in V6 at Diomidis Spinellis' unix-history-repo: https://github.com/dspinellis/unix-history-repo/blob/Researc...
99.
▲
by
zwp
10y ago
The seals aren't signed by election officials? I'm not familiar with seals used on voting machines but that's common in other "tamperproof container" scenarios.
100.
▲
by
zwp
10y ago
https://www.schneier.com/crypto-gram/archives/2002/0515.html... "He used $10 of ingredients you could buy, and whipped up his gummy fingers in the equivalent of a home kitchen. And he defeated eleven dif
101.
▲
by
zwp
10y ago
CVE-2008-5983 ( https://bugs.python.org/issue5753 ) "Untrusted search path vuln... prepends an empty string to sys.path when the argv[0] argument does not contain a path separator" Check out the "yes"es in
102.
▲
by
zwp
10y ago
That'll certainly help keep the wolves at bay (though I still will not install firejail 4755...). ~1000 commits since I last looked at firejail, keep up the good work!
103.
▲
by
zwp
10y ago
> this approach could lead to new vulnerabilities? Yes. The first line of the article ("a SUID program that reduces the risk of security breaches") should be enough to raise a quizical eyebrow from security-minded users but ove
104.
▲
by
zwp
10y ago
Great initiative, thanks. Your aim to keep the db open forever is commendable. I'd like to know how you might address two of the problems that [AIUI, paging @attritionorg] osvdb struggled with: 1. BigCo pillages (resells) your data and
105.
▲
by
zwp
10y ago
We also see TZ "CLT" aka "Chilean Standard Time" (4 hours left of UTC, 6 hours left of Spain) which fits neatly with previous speculation (here and elsewhere) of Chilean origin (language characteristics). Assuming it
106.
▲
by
zwp
11y ago
The commit to fix this appears to be "validate Version full_name": https://github.com/rubygems/rubygems.org/commit/1067ab7e0871... Cause: a "full name" is a dash-seperated join of its comp
107.
▲
by
zwp
11y ago
Funky! This feels like the connect(2) is returning before it has actually done its work, async-style. Rachel, could you write a small sneaky program (using eg libpcap) to see if the TCP handshake has completed by the time connect(2) returns
108.
▲
by
zwp
11y ago
Is there an easy config for that? Suppose I want to push to eg github and bitbucket (without sharing my creds with ifttt or similar)? Is a post-receive hook on a local pseudo-master the way to go?
109.
▲
by
zwp
11y ago
> `egrep 'PATTERN|PATTERN'` instead of `grep PATTERN | grep PATTERN` Oops? Ironically (assuming two distinct values of PATTERN) I think you just answered your own question. (They are different: first is disjunction of patterns,
110.
▲
by
zwp
11y ago
> dick measuring contest A more experienced colleague: "Pah, that's just a crutch". Well, yes. And? My personal tipping point was watching a sysadmin edit resolv.conf and type "namesrever": vim picked it out in r
111.
▲
by
zwp
11y ago
Since this doesn't cause a system panic... multiple userland utilities have MAXPATHLEN problems? Is this reproducible with longer filenames and less depth? (If not: what cares about depth?)
112.
▲
by
zwp
11y ago
Zork-alikes aside... I'm looking for practical applications :) I recently re-watched Yaron Minsky's "Effective ML" talk where (towards the end) he talks about making read-only and read-write types. That's where I th
113.
▲
by
zwp
11y ago
I want a small hardware, non-connected tablet that acts exclusively as a password manager. It connects to the computer I'm using as a USB keyboard device and only "types" a password when I physically tell it to ("yubikey
114.
▲
by
zwp
11y ago
Is this such a thing: https://github.com/raymontag/rust-keepass/blob/2b7b701b69541... unsafe { ptr::write_bytes(self.encrypted_string.as_ptr() as *mut c_void, 0u8, self.encrypted_string.len()) }; ?
115.
▲
by
zwp
11y ago
"I tried - and failed - to come up with a reasonable grep pattern" Is there a nice, light, better-than-betterthangrep[1] static analysis tool that would help with this sort of question? (I suspect the decay to pointer would, for e
116.
▲
by
zwp
11y ago
This is correct. For v3, with P' the key derived from stretching the password: "2.6 B1 and B2 are two 128-bit blocks encrypted with Twofish [TWOFISH] using P' as the key, in ECB mode. These blocks contain the 256 bit random k
117.
▲
by
zwp
11y ago
And servers that are authenticating client certs? (clearly there are far fewer of those around but they do exist)
118.
▲
by
zwp
11y ago
> As of two days ago, there is a hostile version of PuTTY A small correction -- from the symantec blog post: "this file has been in the wild since late 2013 and it was first seen in Virus Total around the same time. However, we have
119.
▲
by
zwp
12y ago
> If it affects gethostbyaddr The release at http://www.frsag.org/pipermail/frsag/2015-January/005722.htm... says that it affects both gethostbyname() and gethostbyaddr().
120.
▲
by
zwp
12y ago
Yes. See, for example: https://en.wikipedia.org/wiki/Christmas_tree_packet https://en.wikipedia.org/wiki/Ping_of_death
More ›