Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
marcinw
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
marcinw
10y ago
(I am one of the developers of Doorman). Some background, from osquery's site: "osquery allows you to easily ask questions about your Linux, Windows, and OS X infrastructure. Whether your goal is intrusion detection, infrastructur
2.
▲
How Well Can You Hear Audio Quality?
(npr.org)
2 points
by
marcinw
11y ago
|
2 comments
3.
▲
by
marcinw
12y ago
Proper Python would use the csv module for this operation, as your CSV export would break if `header` or `dataset[key]` contains a comma.
4.
▲
by
marcinw
12y ago
Matt Levine sheds more light on this story[1], backed by evidence whereas the NYTimes is just hearsay. Why would Barclay's screw over institutional investors who account for a large majority of their $4 billion in revenue for HFT who b
5.
▲
by
marcinw
12y ago
In addition to SQL injection, many "advanced search" engines will compile regular expression patterns from user input. Depending on the language, this can range from a simple Regex DoS to Code Execution (I'm looking at you P
6.
▲
Why JavaScript Crypto is Useful
(vnhacker.blogspot.com)
5 points
by
marcinw
12y ago
|
0 comments
7.
▲
by
marcinw
13y ago
Right, like getting access to the DOM was ever a hard thing to do. I was specifically referring to web apps in that point, but because you insist, I'll just reference [1]. Another vector to get rogue JS into a user's browser is c
8.
▲
by
marcinw
13y ago
Java, Python, etc don't have a DOM to consider. When you're just an XSS away from an attacker doing: function encrypt(plaintext) { $.post(plaintext, ...); return plaintext; } then you lose. The post talks about t
9.
▲
Reducing the Roots of Some Evil
(codeascraft.com)
43 points
by
marcinw
13y ago
|
8 comments
10.
▲
by
marcinw
13y ago
And that's your problem. I was the same way, though I live in NYC. With every pay raise I upgraded my lifestyle. Whether I was making $50k/year or $100k/year, I wasn't saving anything more besides the shit I was contr
11.
▲
by
marcinw
13y ago
Quitting social networks and using Tor and PGP isn't going to protect you from a nation-state intelligence agency. To suggest so is laughable and naive. We're not even at amateur hour yet. You're better off reading Grugq&#x
12.
▲
by
marcinw
13y ago
I hear people say all the time they drink a lot of water, but when you ask them to measure it out, it's a joke. The answer to this problem is to sit at your desk with a gallon of water. You'll find you've finished at least 3/4 before the en
13.
▲
by
marcinw
13y ago
We've solved this in the Matasano NYC office by: * Going downstairs for coffee * Playing a round or two of darts
14.
▲
by
marcinw
13y ago
When I worked in machining, we all had anti-fatigue mats at our stations. Everyone wore Red Wing boots (sneakers are terrible for you), and I heard no complaints of foot pain.
15.
▲
by
marcinw
13y ago
For one, a built-in theme editor that exposes you to remote command execution in the presence of another vulnerability, such as cross-site scripting (XSS).
16.
▲
by
marcinw
13y ago
We're working on it, but you can expect to start them this evening.
17.
▲
by
marcinw
14y ago
Neils Ferguson, et. al of Cryptography Engineering (p. 95) suggest that truncating a HMAC-SHA-256 to 128 bits should be safe, given current knowledge in the field.
18.
▲
by
marcinw
15y ago
When it comes to the social stigma of taking a nap at work, just ask if they'd prefer you take a smoke break every hour. Usually, people will get the hint. If not, too bad.
19.
▲
by
marcinw
15y ago
Am I only the person ever to like Load? I know it's not their best, but I still enjoyed it.
20.
▲
by
marcinw
15y ago
Hmm, where to even begin.... I take it you've never ridden the subway.
21.
▲
by
marcinw
15y ago
-I is an HTTP HEAD request (which may return a different response code than a traditional GET). To print the headers in any kind of request, use lowercase -i.
22.
▲
by
marcinw
15y ago
Wow, 61% of websites that responded with an Access-Control-Allow-Origin header had a value set to "*". This allows for the website to be access in a cross-domain manner (think XSS, global wild cards in crossdomain.xml, etc). I'm worried to
23.
▲
by
marcinw
15y ago
That's the trick. I find having a coffee and then closing my eyes for 15 minutes leaves me more relaxed yet full of so much more energy than before to take me through the rest of the day.
24.
▲
by
marcinw
15y ago
There's plenty of those to go around...
25.
▲
by
marcinw
15y ago
I must admit, as an American male, a little older than you, my score was also so low, I'm too embarrassed to even mention. All those years of cheating on vocabulary tests (merely by memorizing the words 5 minutes prior to taking the test)
26.
▲
by
marcinw
15y ago
Accept header is all but useless these days. Servers rarely look at the Accept header that is sent with the request, and browsers can rarely know ahead of time what type of content to expect when merely clicking on a URL. Check out this bl
27.
▲
by
marcinw
15y ago
Carriers of today hold 90 aircraft, 2 RAMs, 3 Phalanxs and 2 Sea Sparrow launchers (specs from Wikipedia page on George H.W. Bush aircraft carrier). I'm pretty sure with all this they can defend themselves pretty well.
28.
▲
by
marcinw
15y ago
I'm semi-alright with them moving towards four commercials per hour (every 20 min would be better). One thing I hope they do not do, as other stations have done, is place those ridiculous promotions (often for other shows) in the bottom cor
29.
▲
by
marcinw
15y ago
How many of you treat conferences as mini-vacations? I find that in my field, going to a couple conferences throughout the year makes up for a couple days of vacation, as long as I don't have any work on my plate. Also, I find that being s
30.
▲
Why is America the 'no-vacation nation'?
(cnn.com)
413 points
by
marcinw
15y ago
|
412 comments
More ›