Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
entuno
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
entuno
3mo ago
In most cases I'd think it's more of a deterrent for commercial entities, because spending money create complexity. Most employees are not in a position to just directly spend their organisation's money, so that $0.05 will
2.
▲
by
entuno
3mo ago
There's an assumption in here that every developer is spending a load of money on the latest and most capable LLMs to scan for bugs in their code before every release. But the last couple of decades have shown us that huge numbers of d
3.
▲
by
entuno
3mo ago
There is a history of companies and organisations threatening legal action against security researchers when they report vulnerabilities in their systems or products. Sometimes even when the testing has been completely offline - I know peop
4.
▲
by
entuno
3mo ago
If I've stumbled across what I think is a security issue in your systems, there is zero chance that I'm going to get out my credit card and pay you for the privilege of responsibly disclosing it to you. Especially if it's t
5.
▲
by
entuno
3mo ago
Historically there have been vulnerabilities in various applications due to HTTP method tampering, and in the days of people accidentally leaving WebDAV enabled then methods like PUT and DELETE could be very damaging. Plus the issues with T
6.
▲
by
entuno
3mo ago
AWS CloudFront blocks GET requests with a body, so it doesn't even have to be a particularly strict setup or an explicit WAF.
7.
▲
by
entuno
3mo ago
It would be very dependent on the exact circumstances - who made a complaint, what exactly they're accusing you of, what evidence there is, how high profile it is, the current diplomatic position (which changes by the hour), etc, etc.
8.
▲
by
entuno
3mo ago
Legally speaking, no - it would still be a criminal offence. Practically speaking, there is zero chance that the USA would extradite someone to Iran, even if they weren't currently at war with them. Whether they did anything about it w
9.
▲
by
entuno
3mo ago
The Daily Mail is a trashy tabloid, so it's not surprising. Weird to see it posted here as though it's a credible source for anything.
10.
▲
by
entuno
3mo ago
They can be pretty shitty if you're a pedestrian or cyclist, because quite a lot of them don't "see" you, so you just get blinded by the full beams.
11.
▲
YellowKey Bitlocker Bypass Vulnerability
(github.com)
87 points
by
entuno
4mo ago
|
20 comments
12.
▲
by
entuno
5mo ago
There's been a lot of nice quality of life changes in the 3.7 builds (which has now become 5.0.0) that make going back to the older versions a bit painful. Also some pretty major gameplay and balance changes, some of which are pretty c
13.
▲
by
entuno
5mo ago
Against the Storm (and excellent rouguelite city-builder) does this in a really cool way. Pausing is a core mechanic of the game, and you frequently pause while you place building or things like that - and all the visual animations stop (fi
14.
▲
by
entuno
5mo ago
> The reason that the rich were so rich, Vimes reasoned, was because they managed to spend less money. The "boots" item feels less true, because expensive doesn't seem to be as correlated with "good quality" as i
15.
▲
by
entuno
5mo ago
Expensive doesn't guarantee high quality, but very cheap almost always means low quality. A £200 pair of boots might be great and last for a decade, or might be overpriced and fall apart after six months. But a £5 pair are definitely g
16.
▲
by
entuno
5mo ago
Financial costs won't solve the problem for companies, because they're hard to enforce. You'd be weighting up the cost of dealing with the fallout of getting hacked against the cost of paying the random and the chance that
17.
▲
by
entuno
5mo ago
Plus it gives the ransomware gangs a whole new angle they can use. So, remember how you illegally paid us a ransom a few months ago? Unless you want to go to prison, then you better... We're already seeing this against companies who
18.
▲
by
entuno
5mo ago
It's one of those ideas that sounds nice in theory, but doesn't survive contact with the real world. In the same way that many people would say that you shouldn't negotiate with terrorists or kidnappers; but if it's the
19.
▲
by
entuno
7mo ago
I've also seen roads that have these kind of signs, but they only apply during busy hours. However, as with any traffic controls they're useless if they're not actually enforced. Which is a shame, because it'd be absolut
20.
▲
by
entuno
7mo ago
If that'd been the design from the start, then sure. But it's not at all obvious that setHTML is safe with arbitrary user input (for a given value of "safe") and innerHTML is dangerous.
21.
▲
by
entuno
7mo ago
It's certainly an improvement over people trying to homebrew their own sanitisers. But that distinction of being XSS-safe is a potentially subtle one, and could end up being dangerous if people don't carefully consider whether XSS
22.
▲
by
entuno
7mo ago
This kind of thing always makes me nervous, because you end with a mix of methods where you can (supposedly) pass arbitrary user input to them and they'll safely handle it, and methods where you can't do that without introducing v
23.
▲
by
entuno
7mo ago
And that it took this long to get an answer to that question.
24.
▲
by
entuno
7mo ago
"Critical security fixes may be evaluated on a case-by-case basis" didn't exactly give much confidence that they'd even be doing that.
25.
▲
by
entuno
7mo ago
And hopefully they're the same four same bullet points..
26.
▲
by
entuno
7mo ago
I've argued for a long time that adblocking isn't just a quality of life thing, it's an essential security control for browsing the Internet in the same way that patching your system and running malware protection is. I didn&
27.
▲
by
entuno
8mo ago
Also depends on the size of your fuel tank and how full it already is. The time taken to refuel is (almost) the same regardless, but if you've got a 40l fuel tank vs a 70l one or you're only half-empty then it's going to be l
28.
▲
by
entuno
8mo ago
Set's an good precedent for places that offer electric charging having to do the same thing in future though.
29.
▲
by
entuno
8mo ago
I almost never go out of my way for fuel, because as you say, it's rarely worth it once you factor in your time (never mind the fuel spent). But it's still useful to know about price variation so that you can plan ahead. I regular
30.
▲
by
entuno
8mo ago
The variation in even a couple of miles can be pretty big. I almost never go out of my way to visit a cheaper petrol station because that's usually a false economy, but there are definitely some local places that I favour or avoid beca
More ›