Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
zwp
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
19 ms
·
151.
▲
by
zwp
15y ago
> can't make a Ruby object falsy You can override ! (see http://www.rubyinside.com/rubys-unary-operators-and-how-to-r... from earlier this week) so !!obj can evaluate to false. But there is still this to solve: ruby-1.9.3-p0 :00
152.
▲
by
zwp
15y ago
getent services 79 (Advantage is that getent will follow your nsswitch.conf configuration to find your actual service database).
153.
▲
by
zwp
15y ago
It's to stop lint(1) complaining that you're not checking the return value from printf(). I see you're an old-timer here but maybe you missed out on lint: http://en.wikipedia.org/wiki/Lint_(software) That page says it dates from the late
154.
▲
by
zwp
15y ago
http://codereview.stackexchange.com/ http://refactormycode.com/
155.
▲
by
zwp
15y ago
I apologize for the slightly tangential response but your post merits more than a POU (Plain Old Upvote). 30 years ago a C64 was My First Computer, a birthday present. Llamasoft's Attack of the Mutant Camels was my first game, swiftly follo
156.
▲
by
zwp
15y ago
That's interesting. Why do you do this?
157.
▲
by
zwp
15y ago
I like the way the API allows us to see how much business your site is doing.
158.
▲
DARPA-RA-11-52 Cyber Fast Track funding
(fbo.gov)
1 points
by
zwp
15y ago
|
0 comments
159.
▲
by
zwp
15y ago
"It's all text!", https://addons.mozilla.org/en-US/firefox/addon/its-all-text/
160.
▲
by
zwp
15y ago
Also tedious: $ ls -Q ls: illegal option -- Q usage: ls -aAbBcCdeEfFghHiklLmnopqrRsStuUwxvV1@/[c | v]%[atime | crtime | ctime | mtime | all] [files] It's succinct but that second line is almost completely useless.
161.
▲
by
zwp
15y ago
As I said in my first post this particular example seemed so stridently wrong that I thought I'd missed something, that there was a level of irony in the article that apparently doesn't exist. > "locate" rather than "find" As it happens
162.
▲
by
zwp
15y ago
This was indeed my interpretation. I read this (second clause) as a linear chronology: "Old english smeortan; related to Old High German smerzan, Latin mordere to bite, Greek smerdnos terrible" Thank you for the correction.
163.
▲
by
zwp
15y ago
Yes! Thank you. Exactly (was later than I thought). http://www.mtholyoke.edu/acad/intrel/orwell46.htm "Bad writers, and especially scientific, political, and sociological writers, are nearly always haunted by the notion that Latin or Gree
164.
▲
by
zwp
15y ago
Hello! I like the hypothesis, I'm sure there must be some research on this. There is a writing style guide written by a well-known English author, Victorian era, that suggests using saxon over romance words for clarity. I feel this is valid
165.
▲
by
zwp
15y ago
I enjoyed this article although I suspect its factual veracity (oops, err, truth). For one thing LEOs don't say "individual" because they're romance language kowtowers but rather because it's an instance of the largest valid superclass of m
166.
▲
by
zwp
15y ago
> way to return a list of four arguments from a method p, q, r, s = * method_that_returns_array_of_4_things * aka "splat operator"
167.
▲
by
zwp
15y ago
> They have an XSS Oh dear. The (short) audio clips on their site are... interesting. Trust Guard's emphasis/value appears to be sales conversions, not security per se. https://www.trust-guard.com/category-s/3.htm First sentences from
168.
▲
by
zwp
15y ago
I understand your point (it is potentially true for more than just the security domain of application development) but I think your premise in this case is false. SQLI (XSS, CSRF, ...) attacks are neither sophisticated nor new. SQLI has bee
169.
▲
by
zwp
15y ago
"a lot of "real" certificates depend on this CA" How many? did you estimate from sequential serial number allocation? I am surprised (even if it turns out this is "just" an encrypted webserver key) that they aren't using hardware keys: (a)
170.
▲
by
zwp
15y ago
Palliative: AllowOverride None As jerf (+1, great answer), stepping back a little... it has been ~fifteen years since we started noticing problems with htaccess. It filled a niche when webserver configuration was hard and when CRUD admin in
171.
▲
by
zwp
15y ago
> I've never heard of Windows being compromised via the serial port! As a point of order: serial port exploits exist for other OSes (Linux, Juniper, Cisco, APC...) and also for windows virtual com ports so whilst probably not trivial it
172.
▲
by
zwp
15y ago
Nessus is probably (still) the best for Linux in this field (certainly in the "free for home use" category): http://www.tenable.com/products/nessus Lots of vendors have offerings in this area. The quality is ... variable. If you are think
173.
▲
by
zwp
15y ago
Stuart Holloway uses something close to this in one of the presentations at infoq.com. He uses a method from Apache Commons stringUtils as an example of battle-tested enterprise java. Whether or not that is truly representative of java code
174.
▲
by
zwp
15y ago
Cool. > only the ones that have been modified by the application code Sounds good (after a quick skim again I still can't see that but I'll take your word for it!). I've had two attempts to build and test but unfortunately failed: curre
175.
▲
by
zwp
15y ago
Bigger potatoes: output sanitization? Eg only whitespace is trimmed from cookies, then in webserver.Outgoing.cc: Socket << "\r\nSet-Cookie: " << Current->Key << "=" << Current->Value; Lacewin
176.
▲
by
zwp
15y ago
No, it will hit the NULL terminator and short circuit.
177.
▲
by
zwp
15y ago
Small potatoes but this: for(char * i = this->URL; *i; ++ i) { if(i[0] == '.' && i[1] == '.' && (i[2] == '/' || i[2] == '\\')) misses the case where the double dot is not followed by a sl
178.
▲
by
zwp
15y ago
> what you mean by "beware the clipboard" It's not that long ago that certain browsers would give up your clipboard to any site that asked for it. IE: http://www.securiteam.com/windowsntfocus/5CP0C1F61O.html Similar (attacks paste), f
179.
▲
by
zwp
15y ago
I avoid browser-integrated password stores. The attack surface is larger than a standalone app; your browser is a popular (and historically ripe) target; your browser sees lots of untrusted input from third parties; you manipulate sensitive
180.
▲
by
zwp
15y ago
Actually Schneier wrote one: http://www.schneier.com/passsafe.html (now OSS) I use one (actually three) but it's not a good solution for everybody (what is?). Mostly the pros/cons are obvious but two less obvious risks: * Beware the clip
More ›