Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
_phred
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
_phred
3y ago
A very cursory internet search shows that your history is entirely wrong: https://agileforall.com/history-of-tdd-as-told-in-quotes/ Djikstra proposed the idea in the 1970s. Rails did not in any way pioneer TDD. They we
2.
▲
by
_phred
4y ago
Very helpful y’all, thanks! Gonna see if I feel up to tackling the repair (good excuse to buy a reflow setup) and or get in touch with this gentleman. Cheers!
3.
▲
by
_phred
4y ago
I’ve got two first gen HomePods here which died slightly out of warranty, and AppleCare wanted $300 a piece just to take a look at them. Makes me quite gunshy about spending yet another $300 on a product which may not last more than 2-3 yea
4.
▲
by
_phred
13y ago
Hmm, yes, I think I conflated the asymmetric vs symmetric cases. Shor's algorithm is very tasty, but when the real world demonstrations at top research facilities are saying, "yes, we factored 21 into 7x3, but WITH ENTANGLEMENT&qu
5.
▲
by
_phred
13y ago
Ah shoot, you're right. I'm an armchair crypto geek at best. In any case, you can choose a public key exponent large enough to still make it a hard problem to crack in a reasonable amount of time. Barring some huge vulnerability i
6.
▲
by
_phred
13y ago
The best publicly known attacks on RSA reduce the attack time by a few orders of magnitude at best. A functional quantum CPU could reduce that by a few more orders. Your 4096-bit RSA key is still 2^3072 times harder to break, so even with r
7.
▲
by
_phred
13y ago
Yes: call/SMS forwarding. It depends on how good your first factor (e.g. password policies) are, and how your reset process works. Getting someone's phone number and setting up call forwarding doesn't require much social engi
8.
▲
by
_phred
13y ago
Looks like it's built around KVM (Kernel Virtualization Modules), i.e. "containers", rather than full-blown virtual machine emulation like Xen or VirtualBox/Vagrant. It appears to be a configuration management / dep
9.
▲
by
_phred
13y ago
Wow, that comment thread... does not lend itself to confidence in their project's security. It also illustrates a really key point about crypto: because it looks simple (oh, just run the bytes through that function/hash/se
10.
▲
by
_phred
13y ago
Hackers built Facebook. They hire hackers. If there's a group that's hardest to pigeonhole in terms of beliefs it's hackers . The idea that a company composed if hackers could have not a single whistleblower , no single p
11.
▲
by
_phred
13y ago
Interesting, thanks!
12.
▲
by
_phred
13y ago
I have a theory that the accelerometer-linked 3D "layer" effects might make the flat interface more usable in person. As in, the subtle perspective shift would make it obvious that a button is a button, etc. Can you comment on th
13.
▲
by
_phred
13y ago
A lot of API authentication is half-assed, like the examples in the article. "OAuth is hard, roll your own" is a common approach. Even with, e.g., OAuth 2, who's to say that the scheme is completely safe and that your implementation is corr
14.
▲
by
_phred
13y ago
Right. If the attack vector is "break SSL" I'm going to try some other attacks first. There's an underlying assumption in the question: my app (and everything else hosted on the box) is safe from XSS, CSRF, injections, and other information
15.
▲
by
_phred
14y ago
O, cruel fortune! I rue my talent.
16.
▲
by
_phred
14y ago
So as a sort-of-amusing counterpoint to this article, I know at least one ASV who insists that the only way to mitigate BEAST is to disable all ciphers but RC4. Still scratching my head on that one. That tool you posted is great, hugely he
17.
▲
by
_phred
14y ago
There's nothing like good old plain text. :) Nowadays I'm downright spoiled and use org-mode[1] to keep my systems journals. Org files are plain text as well, and org-mode takes care of setting up the tree by date. I can also add a journal
18.
▲
How I spend my first 5 minutes on a Server -- with Ansible
(practicalops.com)
3 points
by
_phred
14y ago
|
0 comments
19.
▲
by
_phred
14y ago
I'm throwing my hat in the ring. I took the author's original post and implemented it as an Ansible playbook in a little less than an hour. http://practicalops.com/my-first-5-minutes-on-a-server.html Happy to answer questions about it. :
20.
▲
by
_phred
14y ago
Very, very difficult, unless the host relies on a single timesource. Best and common practice is to use 3-4 sources from different organizations in the ISC pool. It also wouldn't surprise me if most implementations of ntpd would have furthe
21.
▲
by
_phred
14y ago
Whoa, your terminal playback thing is pretty neat. Did you use GNU Screen to record the session?
22.
▲
by
_phred
14y ago
Your last point is DEFINITELY a +1 over Heroku. Although I'd be pissed to lose my deployment & monitoring tools and have to piece it all back together (especially after I thought it was "solved"). Just sayin', this is a tough business,
23.
▲
by
_phred
14y ago
At $9/month I suspect you are drastically under-valuing the service you provide. Sysadmin time is expensive, and your value proposition is the same as Heroku: pay us so you don't waste time sysadmining your boxes. Time is unimaginably prec
24.
▲
by
_phred
14y ago
Now, on alert completion do this: window.location.href = 'nyan.cat'; Neat little app, nice to see a simple non-Flash version of http://e.ggtimer.com
25.
▲
by
_phred
14y ago
Flip side: don't feel tiny in comparison to this guy's achievements. Did he bang out LZEXE the first time he sat down at a terminal? Probably not. But over time, through pursuit of a passion and hard work, his skill has progressed incredibl
26.
▲
by
_phred
14y ago
>> Depression robs you of the ability to: 1. remember happiness 2. feel happiness 3. anticipate happiness 4. make considered decisions Just a friendly reminder that depressed people cannot, for the most part "snap [ourselves] out."
27.
▲
by
_phred
14y ago
Yep, learned metric as well as imperial, and how to convert between the two. Primary school was ~20 years ago for me. High school science was all in SI, of course.
28.
▲
by
_phred
14y ago
See whoownsmyavailability.com for details.
29.
▲
by
_phred
14y ago
Somewhat like a Skiplist, which is introduced in a 1990 paper: http://en.wikipedia.org/wiki/Skip_list I'm certain that at least one older algorithms text I own mentions skiplists, and there is no doubt much other prior art here, seems li
30.
▲
by
_phred
14y ago
Nice to see Zabbix getting some love, it's a good and simple monitoring system. I've already got my Zabbix install talking to Hubot, Twilio integration is next on the list. :)
More ›