Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
griffinmb
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
griffinmb
6mo ago
This is not the same company. The OP Tiny Corp accused them of Trademark infringement on Twitter, due to exactly this kind of misconception.
2.
▲
by
griffinmb
3y ago
Agreed that there’s no way to do this meaningfully and securely. Looking forward to the archeological audits of LLM-developed apps x years from now that are a total mystery to the product owners…
3.
▲
by
griffinmb
3y ago
Yeah, it doesn’t fix the issue at all. Rough to have a security product demo be fundamentally insecure.
4.
▲
by
griffinmb
3y ago
I created/maintained a popular project for years[^1], and recently passed ownership to someone else. It's been great seeing issues resolve, PRs merge, etc, after languishing for a while :) [^1]: https://github.com/
5.
▲
by
griffinmb
5y ago
The point is that with a powerful Effects system, devs calling the logger would have to account for the network call in their own code. Someone might have wondered why that was needed and gotten this addressed before it was ever widespread.
6.
▲
by
griffinmb
5y ago
Effects can definitely help, but a strong type system allows you to encode security concerns for compile time feedback as well. See https://gmb.is/refinement-types.html for a non-Haskell example.
7.
▲
by
griffinmb
5y ago
Given that he's now un-retweeted it, it looks like even amasad agreed it wasn't a good look.
8.
▲
by
griffinmb
5y ago
Based on your retweet[1], you still seem to be publicly punching down. [1]: https://twitter.com/pnegahdar/status/1402018604233732098?s=2...
9.
▲
CSRF Protection in Plug and Phoenix
(gmb.is)
2 points
by
griffinmb
6y ago
|
0 comments
10.
▲
by
griffinmb
6y ago
You probably know this, but correcting for anyone reading. C is generally considered statically but *weakly* typed.
11.
▲
Mezzano – An Operating System Written in Common Lisp
(github.com)
4 points
by
griffinmb
6y ago
|
0 comments
12.
▲
Secure Meteor
(securemeteor.com)
1 points
by
griffinmb
6y ago
|
0 comments
13.
▲
Faking Useful Refinement Types in Racket
(gmb.is)
2 points
by
griffinmb
6y ago
|
0 comments
14.
▲
by
griffinmb
6y ago
It’s versioned, which is an improvement on “agility”
15.
▲
by
griffinmb
7y ago
Yep, that’s the way!
16.
▲
by
griffinmb
7y ago
This class of bug (CSRF bypass via route confusion) is probably more common in Phoenix apps. I’ve found a handful of apps vulnerable to this issue with Sobelow. People create (for example) a get ‘/profile’ and a post ‘/profile’, a
17.
▲
Sobelow: Security Scans for the Phoenix Framework
(github.com)
1 points
by
griffinmb
7y ago
|
0 comments
18.
▲
Das Q Vulnerabilities
(griffinbyatt.com)
1 points
by
griffinmb
7y ago
|
0 comments
19.
▲
by
griffinmb
7y ago
Sure, the "passive" was what I was calling out as incorrect. And as you noted, a compromised trusted CA affects all domains. Which is another thing this article gets explicitly wrong. > If DigiCert’s Key Management System is
20.
▲
by
griffinmb
7y ago
This is a horribly misinformed article, and is incorrect about the most fundamental arguments it is making. E.g. Among many other issues, it implies that a compromised CA would allow passive MitM.
21.
▲
The Phoenix Router
(griffinbyatt.com)
1 points
by
griffinmb
7y ago
|
0 comments
22.
▲
Secure Meteor
(securemeteor.com)
1 points
by
griffinmb
7y ago
|
0 comments
23.
▲
by
griffinmb
7y ago
Agreed that you don't gain anything if you're using 1Password. But users may be required to set up MFA to access something like GitHub organizations, in which case having it available in 1Password is convenient.
24.
▲
Stellar’s ‘decentralized’ blockchain crashed for 2 hours and nobody realized
(thenextweb.com)
2 points
by
griffinmb
7y ago
|
0 comments
25.
▲
Private Key Extraction from Qualcomm Hardware-Backed Keystores
(nccgroup.trust)
305 points
by
griffinmb
7y ago
|
56 comments
26.
▲
by
griffinmb
7y ago
The docs don't seem to disagree with me. > Besides, you shouldn't need to plug it that way to pair it either. Agreed. And glad that's not necessary for the latest generation.
27.
▲
by
griffinmb
7y ago
> You missed charging the Apple Pencil on the ipad pro. You plug the Pencil into the iPad to pair it. It comes with an adapter that you use to charge it with a regular cable.
28.
▲
Phoenix Is Not Magic
(blog.griffinbyatt.com)
2 points
by
griffinmb
7y ago
|
0 comments
29.
▲
Announcing Building Git
(blog.jcoglan.com)
291 points
by
griffinmb
7y ago
|
52 comments
30.
▲
Identifying Cobalt Strike team servers in the wild
(blog.fox-it.com)
1 points
by
griffinmb
8y ago
|
0 comments
More ›