Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
disruptiveink
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
disruptiveink
3mo ago
This is stupid/dangerous advice and I will die on this hill. > The JWT specification is specifically designed only for very short-live tokens (~5 minute or less). Sessions need to have longer lifespans than that. Your auth token sho
2.
▲
by
disruptiveink
5mo ago
Killed for Skype, which was already declining by that time. Microsoft was keen on unifying their IM platforms, but failed to realise that unless the migration path is incredibly smooth, people just won't do it. And the value of any cha
3.
▲
by
disruptiveink
5mo ago
Can't we just normalise publishing whatever you put into the LLM instead? I'm sure the author typed things into their favourite AI assistant that regurgitated that long form, LLM-speak style version. I'm sure the original pro
4.
▲
by
disruptiveink
5mo ago
You're thinking of this like a game where the only point is to "win". That's not how this would actually work in practice. Blue is the only moral and logical choice. If red gets over 50% and you picked it, therefore cont
5.
▲
by
disruptiveink
7mo ago
Correct. If you can always either fix it forwards or roll back, which you should be able to unless you're building software that needs to go out in releases with versions tracked separately that need to keep getting fixes, trunk-based
6.
▲
by
disruptiveink
7mo ago
Baseline requirements are not an imaginary problem. All of them have a legitimate reason for existing. You could argue that some "are not that big of a deal", but that's exactly the point, the overbearing and overly specific
7.
▲
by
disruptiveink
9mo ago
If you purposely go into your phone settings and turn off auto-capitalization (which is what the kids do, since they're all typing on their phones), isn't it the very definition of pretentiousness? You're going into extra tro
8.
▲
by
disruptiveink
11mo ago
Cat's out of the bag there already. We all have general purpose computing devices in our pockets, locked down on purpose. Android used to allow you to gain admin rights but it's been getting more and more impossible to do so while
9.
▲
by
disruptiveink
11mo ago
Correct. Age verification and privacy consents belong on the browser. The issue is that on the browser, things work a bit too well (remember https://en.wikipedia.org/wiki/P3P ?), so the big players are incentivized to
10.
▲
by
disruptiveink
1y ago
The insane question here is, why would the EU mandate hardware attestation controlled by two private American companies in order to access services? That seems completely contrary to the spirit of EU laws and regulations, which tend to be a
11.
▲
by
disruptiveink
1y ago
Agreed. I refuse to use the terms "rooting" and "jailbreaking" in professional environments, I always use terms like "admin access to the mobile device". Because that's what it is, despite the extremely su
12.
▲
by
disruptiveink
1y ago
Starmer is as authoritarian as the Tories at this point. There is no difference here.
13.
▲
by
disruptiveink
1y ago
We have a near perfect system for finding the location of phone thieves, yet the police will not go and knock on the doors of criminals even when explicitly shown proof of "this is where the thief is currently".
14.
▲
by
disruptiveink
1y ago
I'm not victim blaming here, but does anyone have this nagging feeling that in this case, we, the "techies" caused this by refusing to engage with lawmakers? In the case of E2E encryption, it's definitely a hill to die o
15.
▲
by
disruptiveink
1y ago
Usually I would agree with you, but this is an incredibly common initialism, used by not just people in the industry, but also by consumers. Sure, it may not be as widespread as VHS (global) or API (tech-adjacent), but anyone who is in the
16.
▲
by
disruptiveink
1y ago
I really don't, what is the answer? I assume higher ups at law enforcement, who are detached from the day-to-day operations, make up excuses about "end to end encryption being a challenge" because it's a meme, much like
17.
▲
by
disruptiveink
1y ago
I don't understand why they keep trying this over and over. It can't possibly be a moral crusade as it keeps happening with different players, but I don't understand the purpose. We now live in a world where the opposite rout
18.
▲
by
disruptiveink
1y ago
It was Bill fucking Atkinson. Not a disposable random contractor you hire by the dozen when you need to build more CRUD APIs. At that time at Apple, even as an IC, Bill had lines of communication to Steve and was extremely valued. There
19.
▲
by
disruptiveink
1y ago
Wait, but didn't TLS 1.0 have significant improvements over SSL 3.0? The article makes it seems that just a couple of things were tweaked just to make it different for the sake of being different.
20.
▲
by
disruptiveink
1y ago
Ah, yes, The color of infinity, inside an empty glass.
21.
▲
by
disruptiveink
2y ago
Google ultimately did that for China. The outcome in that case is that the domestic market filled in the gaps, while complying to all relevant authoritarian legislation. I do not believe that the same would happen for every market where the
22.
▲
by
disruptiveink
2y ago
Amusing nomenclature, but it's a legitimate concern. If your SREs use application credentials to connect to the database, your ability to have effective access controls and have accurate access audit trails are severely hampered.
23.
▲
by
disruptiveink
2y ago
The value proposition of Crowdstrike is exactly that: something that you can deploy to tick the regulatory checkbox of "we have endpoint protection from a reputable company everywhere" without consuming outrageous system resources
24.
▲
by
disruptiveink
2y ago
What do you mean? They wrote the kernel driver. With great power comes great responsability. If you're writing a kernel driver that is deployed throughout a great portion of Fortune 500, with the money that that entails, then you shoul
25.
▲
by
disruptiveink
2y ago
You are correct. Steve definitely believed in doing things properly because you know they're there, regardless of who can see it: https://folklore.org/Signing_Party.html > Steve came up with the awesome idea of hav
26.
▲
by
disruptiveink
2y ago
Struggled with the context as well: https://sunrise-ev.com/projects.htm
27.
▲
by
disruptiveink
3y ago
I use a XP VM on a ARM Mac as it's a handy way to run most Win16/32 exes that won't run properly in Wine. Old random utilities, random OEM software required to upgrade old devices' firmware, silly Win16 apps, the works.
28.
▲
by
disruptiveink
3y ago
That's an unfortunately common misconception. Your example is not security though obscurity any more than password authentication is, though. Security through obscurity means substituting security for a flawed algorithm that is usually
29.
▲
by
disruptiveink
3y ago
I've never worked with someone who ever stated "How long is a piece of string?" and wasn't a total pain to work with. Doesn't even matter which side I was on, it's painful to hear it even if you're part of
30.
▲
by
disruptiveink
3y ago
They are reminding you that the reality you are experiencing is not normal and should not be normalised. They are stating that it is not only possible to not be like this, but it's actually a baseline expectation in most of the rest of
More ›