Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
globie
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
globie
10mo ago
D'oh!
2.
▲
by
globie
10mo ago
We're talking about this line, right? >The precision of outages (at :29 and :44) matches a network-synchronized clock (NTP). I think this just correctly points out that if the trigger was something unsynchronized like animals chewin
3.
▲
by
globie
1y ago
When writing this inflammatory post, you seem to have forgot the bigger picture of the thread you are flaming. We're discussing whether it's right to take a second look from a security standpoint when a software implements WebRTC.
4.
▲
by
globie
1y ago
I'm really surprised they do it at all. I always thought they'd be crazy to.
5.
▲
by
globie
1y ago
That's a good point. I suspect as the renewal period is shortened, scripts will attempt renewal faster and faster. I hope they don't go any shorter than a month. Let the user pick, any value up to a year should do.
6.
▲
by
globie
1y ago
Right you both are! I had no idea.
7.
▲
by
globie
1y ago
Like many others have pointed out, Apple is obsessed with avoiding antitrust scrutiny. A fun (edit: incorrect) example: they are fine owning the device you use to connect to their own streaming service to watch their own produced TV shows,
8.
▲
by
globie
1y ago
Were you running certbot multiple times per day? Looking at the relevant limit, "Consecutive Authorization Failures per Hostname per Account"[0], it looks like there's no way to hit that specific limit if you only run once pe
9.
▲
by
globie
1y ago
Yep, the embedded video in the article really says it all. Proven Industries' wording here at at the very least ambiguous as to whether or not a shim that works on one lock will work on another of the same model. If you had to take apa
10.
▲
by
globie
1y ago
Here's a (very) small sample gathered from a search for "webrtc" on cve.org and picking high-severity CVEs affecting browsers: * CVE-2015-1260 * CVE-2022-4924 * CVE-2023-7010 * CVE-2023-7024 * CVE-2024-3170 * CVE-2024-4764 *
11.
▲
by
globie
1y ago
I assume autoexec is referring to the plethora of WebRTC vulnerabilities which have affected browsers, messengers, and any other software which implements WebRTC for client use. Its full implementation is seemingly difficult to get right. O
12.
▲
by
globie
1y ago
A "Fiduciary responsibility to shareholders" means exactly what I said: "legally bound to extract profit without these silly notions of empathy or trust". The only notions of empathy or trust you see from publicly traded
13.
▲
by
globie
1y ago
I know, we're locking everything down behind WAFs and repeating captchas so only attested identities can get access in the end.
14.
▲
by
globie
1y ago
From the article it's sure starting to seem like people across the internet are just starting to realize what happens when you don't have just 3-4 search engines responsible for crawling for data anymore. When data becomes truly d
15.
▲
by
globie
1y ago
My bad, I forgot I'm a liquid. It's too late to edit, but s/po\w*/poured over/ anyway :)
16.
▲
by
globie
1y ago
>I don’t think people appreciate the degree to which information is siloed, intentionally and unintentionally, in the federal government. Thanks for that. Information can be completely siloed and the statements "If a company knows s
17.
▲
by
globie
1y ago
Do you believe the disaggregation of those monoliths helps to put the "hypothesis to bed"? It sure seems like you were listing "constant litigation" over "records request" as counterevidence of the claim that &
18.
▲
by
globie
1y ago
They only need to pay off or install a single employee to get total or near-total access. Consider this chart from 2013 showing when various tech companies were added to PRISM: https://upload.wikimedia.org/wikipedia/com
19.
▲
by
globie
1y ago
>In the vast majority of cases, the US government at least, has to obtain a warrant to collect data on US citizens, so those two sets are not the same If only that were true[0][1][2][3]. [0] (2022): https://fedscoop.com/d
20.
▲
by
globie
1y ago
I... you're right. I was wondering why the world was only 9x9x9, there's 46k lines showing each block can have air, stone, grass, dirt, log, wood, leaves, or glass. I kind of like it.
21.
▲
by
globie
1y ago
Without a doubt the most impressive thing I've seen with CSS. This immediately brought "A Single Div"[0] to mind, which stood as the coolest CSS demo I'd seen for... 11 years! This one takes the cake. I'll be pourin
22.
▲
by
globie
1y ago
The people behind Cloudflare engineer this issue for profit, which is a very different motive than to "solve" the problem. The people most interested in doing away with the problem altogether are not Cloudflare, but its customers.
23.
▲
by
globie
1y ago
If you have a single server flooding spoofed traffic, it appears as a DDoS to the victim. It's at this point that the distinction between DoS/DDoS breaks down slightly. It is very much not "trivial" to buy 100Gbps+ of DD
24.
▲
by
globie
1y ago
Do you ever find that advocating for these tenets feels "weird" nowadays? As in, don't you know these publicly traded companies are legally bound to extract profit without these silly notions of empathy or trust? What do you
25.
▲
by
globie
1y ago
This conclusion stems from that it is much easier to launch a DDoS from a single server w/ spoofed traffic than to use a botnet. If you have a single 10Gig server, you will likely not be able to take down another 10Gig server unless th
26.
▲
by
globie
1y ago
What website? I'm guessing it is not health related or a "critical resource" if you are cheery about 1% of users being blocked? For people who put stuff online to help people as well as to extract pure profit, knowing the ang
27.
▲
by
globie
1y ago
Simple: Connect larger NICs and do "dumb" DDoS filtering at your fattest point. Consider an HTTP daemon serving static content on a physical server. If that physical server has a 10Gig NIC it will withstand 90%[0] of the real-worl
28.
▲
by
globie
1y ago
Of course it could claim lives. Hopefully Prince has considered people have also likely died as a result of Cloudflare's repeating captcha which holds the next page in front of you like a carrot on a stick, never letting you know that
29.
▲
by
globie
1y ago
>You understand the problem here may repeat itself elsewhere as well, right? I do, and how is this to cap off our discussion: >You move your money to another bank, because the increased security annoys you. On my way out, I would quot
30.
▲
by
globie
1y ago
To those who see securing genetic privacy rights as a critical issue, what would you recommend they do? Just wait and Vote Harder Next Time? I think Americans overall would very much support their PII being recognized as such, and to preven
More ›