Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
devrand
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
devrand
3y ago
It seems pretty clear to me: > How precisely does Hetzner calculate the hourly billing? > The beginning of the hourly billing starts as soon as the product becomes available to you. So for a dedicated server you start paying once the
32.
▲
by
devrand
3y ago
Yeah, that was basically my only reason for having it on the desktop. Thankfully I can just install the ipad app on my macbook as a workaround. More than likely though I'll just move all my TOTPs to 1password.
33.
▲
by
devrand
3y ago
I use this pattern but I'm starting to move away from it. Some things just don't work (ex. linking accounts between companies) and it also throws customer service agents into a panic when they see their own company name in the e-m
34.
▲
by
devrand
3y ago
ah! Good catch. I missed that the alternative terms were opt-in.
35.
▲
by
devrand
3y ago
From the article: > iOS apps distributed from the App Store and/or an alternative app marketplace will pay €0.50 for each first annual install per year over a 1 million threshold. So App Store or not, you need to pay the fee.
36.
▲
by
devrand
3y ago
Ubiquiti did come out with their U7 Pro which is only $189, which is really not bad considering their AC Pro is $149 and their U6 Pro is $159. I ended up upgrading since I do now have a couple of Wifi 6E devices and I live in a very dense a
37.
▲
by
devrand
3y ago
Even if they just replicate what these companies are doing I think there's two main benefits: 1. less waste. The entire case is being thrown away immediately by these volume consumers. All the packaging and what not is also wasted.
38.
▲
by
devrand
3y ago
Troy seems to disagree in the linked blog post: > That last number was the real kicker; when a third of the email addresses have never been seen before, that's statistically significant. This isn't just the usual collection of
39.
▲
by
devrand
3y ago
This particular dataset appears to have been collected by malware. So it wasn't a breached company, it was malware on some machine that impacted users used that logged usernames/passwords.
40.
▲
by
devrand
3y ago
Generally I don't have a choice as you tip when money is exchanged. At some places that means when you place the order (but before you've gotten the food), and at others it means when the bill is satisfied at the end of the meal.
41.
▲
by
devrand
3y ago
The big difference is that before, the tip you picked before placing the order directly reflected the offers that the dashers would see. If you put no tip then very few dashers would be willing to take the order. This is what effectively ma
42.
▲
by
devrand
3y ago
I think you're misunderstanding the change to tipping. DoorDash is effectively eliminating it (or at least making it truly optional). The city's study [1] advocates for this explicitly: > Beyond productivity, there also exist s
43.
▲
by
devrand
3y ago
My understanding is that the PSL is good-enough and avoids somewhat costly/unreliable TXT lookups for every domain when only a very tiny fraction of domains would actually want this treatment. There is also a bit of security risk since
44.
▲
by
devrand
3y ago
If you only care about English.
45.
▲
by
devrand
3y ago
> One proposal is that you should need full legal identification to file a takedown claim How exactly? Require a government issued ID? What if it's fake? How would you validate that the ID is authentic? Even if it is authentic, how
46.
▲
by
devrand
3y ago
It must be quite expensive to maintain. It predates Plaid, so unless they migrated, they're maintaining all the scraping logic and the services to actually do it. The credit card ads are probably not generating enough revenue to justif
47.
▲
by
devrand
3y ago
I suspect that given all the partners involved in these projects, it's likely infeasible to go back to those partners and ask for retroactive extended support from all of them. If any of them (or transitively any of your partners'
48.
▲
by
devrand
3y ago
They probably are writing it off anyway. I've never had an employee actually check -- they always just scan their barcode and clear the error.
49.
▲
by
devrand
3y ago
I've never understood that check. Anyone attempting to steal something just wouldn't put an item they didn't scan in the bagging area. It's almost certainly always a false-positive, which is confirmed by most store emplo
50.
▲
by
devrand
3y ago
And what if the request isn’t made via DoH (very few today are)? Do we just fallback to the existing Web PKI? If so we’d now have two systems to support until everything is migrated to DoH, which can very well be never. Also, how do we know
51.
▲
by
devrand
3y ago
Sort of. Let’s Encrypt checks multiple DNS operators, so you’d need to compromise multiple from LE’s perspective. Whereas putting the public key in DNS only requires compromising a user’s nearest DNS server. For example, in my home network
52.
▲
by
devrand
3y ago
That's not really any better than what we have now. In your model you need to have full trust in the DNS operator and that your DNS responses weren't MITM'd (which are still generally unencrypted!!). In other words, you'
53.
▲
by
devrand
3y ago
Yeah this was confusing to me. They both state that Google is making money from the certificate racket, while also suggesting that Google might come out with their own CA and kick out LE to corner the market. It's contradictory. It was
54.
▲
by
devrand
3y ago
> But if someone is able to perform a man-in-the-middle attack against your website, then he can intercept the certificate verification, too. In other words, Let's Encrypt certificates don't stop the one thing they're supp
55.
▲
by
devrand
3y ago
The same people willing to spend $130k on a SUV?
56.
▲
by
devrand
3y ago
Obviously don't narc on yourself!
57.
▲
by
devrand
3y ago
I feel like this would be particularly easy at self checkout stations where there's usually like 1 employee handling a dozen or so stations. You can also get someone else to go "accidently" scan a pack of gum twice and hit th
58.
▲
by
devrand
3y ago
It would still be prone to DoS though. The request is unencrypted so a MITM could just not respond to those requests. This would effectively block clients from being able to update/get new definitions.
59.
▲
by
devrand
3y ago
According to the article the issue is non-military originating emails. They used an example of a doctor’s office sending x-rays to a patient but mistyped the TLD.
60.
▲
by
devrand
3y ago
> Ideally, an automated transfer to another region with automated forwarding. It's okay to have poor performance, but it's not okay to go "poof" entirely. If the data is moving between countries then this is not an op
More ›