Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mdb31
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
mdb31
4y ago
> There is no sync to provider servers on any TOTP implementation I use That's hard to dispute, but will you accept https://guide.duo.com/duo-restore as a counterexample? > Are you perhaps referring to the Googl
2.
▲
by
mdb31
4y ago
> Since when is TOTP obsolete? Since about the moment that teams all over the world discovered they could just paste the enrollment QR code (a.k.a. private key) into their wikis, and thereby continue unlimited sharing of their role acco
3.
▲
by
mdb31
4y ago
The TOTP "private key" can be easily cloned. Targeted malware, a database compromise at your app provider that you "securely" sync your settings to, or just a few minutes access to your "authentication" device,
4.
▲
by
mdb31
4y ago
Yet, if you go into the "enable 2FA" settings on Github, you only get the option to enable insecure TOTP or SMS. Apparently, once you do that, you might be able to add proper authentication. But no word on whether that then repl
5.
▲
by
mdb31
4y ago
Oh, that's lovely UX... "After you configure 2FA, using a time-based one-time password (TOTP) mobile app, or via text message, you can add a security key" So, after you enable a broken-by-design 1.5FA method, which you don&#x
6.
▲
by
mdb31
4y ago
I'm still confused. So, can you zoom any site on Safari on iOS or not? And if you can't, what definition of 'control' is that, again?
7.
▲
by
mdb31
4y ago
Well, given that Github today doesn't seem to support meaningful 2FA (only TOTP and SMS), wouldn't it be good to fix that issue before starting to talk about requirements like these? Maybe it's just my account, but I can'
8.
▲
by
mdb31
4y ago
I've never experienced any zoom problems (as opposed to Zoom problems...), and I just had a look at all the sites mentioned in TFA. In all cases, I can zoom all elements (text, images, the works) just fine, up to 500%. Firefox 100 on W
9.
▲
by
mdb31
4y ago
@john_cogs: Are there any plans to connect a self-assessment of mental state to the assignment of issues/pings about mentions/incident-response pages in the GitLab app? So, on "I'm on top of the world" days, I get a
10.
▲
by
mdb31
4y ago
Short-and-easy read that contains much truth. Especially item #10, "Lead by example" which encourages managerial review of recurring meetings (which often boil down to "well, here is my Excel sheet, you tell me how you'r
11.
▲
by
mdb31
4y ago
Well, the race to attract the outflow of the current Russian 'brain drain' is definitely on. If the US is able to attract the majority of that (as it most likely will), while keeping out the Putin-aligned plants and/or otherw
12.
▲
by
mdb31
4y ago
Well, I'm pretty sure you can't even directly sue over ownership of a .com domain? You have to submit to UDNP arbitrage first ( https://www.icann.org/resources/pages/help/dndr/udrp-en ). It doe
13.
▲
by
mdb31
4y ago
Nope, people communicate like that internally as well, because "that's what's professional " In some cases, you can fix this by asking the sender to be, like, normal. This works half the time, the other half involves re
14.
▲
by
mdb31
4y ago
Nope, not a caricature. Read, for example https://www.atlassian.com/engineering/post-incident-review-a... This is held up as a great example of transparent communication. For me, this is true, but only for the meaning
15.
▲
by
mdb31
4y ago
Ah, yes, the same kind of guide that brought us "how to professionally respond to outages"... With classics like "We recognize the incident", "a small subset of customers", "degraded performance" and
16.
▲
by
mdb31
4y ago
> vector instructions are fundamentally necessary For which percentage of users? > AMD is actually adding AVX-512 Which is irrelevant to in-market support for that instruction set.
17.
▲
by
mdb31
4y ago
Where do I say that the speedup is surprising? My question is whether Intel investing in AVX-512 is wise, given that: -Most existing code is not aware of AVX anyway; -Developers are especially wary of AVX-512, since they expect it to be dis
18.
▲
by
mdb31
4y ago
Cool performance enhancement, with an accompanying implementation in a real-world library ( https://github.com/lemire/despacer ). Still, what does it signal that vector extensions are required to get better string perfor
19.
▲
Removing characters from strings faster with AVX-512
(lemire.me)
146 points
by
mdb31
4y ago
|
85 comments
20.
▲
by
mdb31
4y ago
I've hosted my own email since, at least 1993 (that's on the Internet: I was on UUCP at least some years prior to that). If you have a static IPv4 in a range that is not actively hostile, and you have proper SFF/DMARC records
21.
▲
by
mdb31
4y ago
Tired: exploiting antivirus software for those sw33t 0days. Wired: exploiting the gatekeeper of antivirus software quality for the lulz.
22.
▲
Remote Code Execution via VirusTotal Platform
(cysrc.com)
1 points
by
mdb31
4y ago
|
1 comments
23.
▲
by
mdb31
4y ago
This is actually very cool: a dataset of 3900 CVEs, with a matching fixing commit for 1359 of them. So, lots of opportunity to find a big payout w/r/t the unfixed CVEs. Whether successful or not, those attempts will definitely str
24.
▲
Commit Level Vulnerability Dataset (For Android)
(blog.quarkslab.com)
1 points
by
mdb31
4y ago
|
1 comments
25.
▲
by
mdb31
4y ago
Yeah, this particular myth is common in many EU countries as well. Apart from the minimal amount reportedly saved (30 GBP per annum in real currency is 37 EUR/USD per year, less than 10 cents a day), it does not seem to be particularly
26.
▲
by
mdb31
4y ago
This seems to take on recent Google developments. Now, for good measure, I would like to see something that perverts GitHub Copilot to a similar extent...
27.
▲
A satirical app that draws attention to problems with AI-powered correction
(goodwrite.app)
5 points
by
mdb31
4y ago
|
2 comments
28.
▲
by
mdb31
4y ago
Most interesting observation here: Short GC pauses do not assure low latency. Anyway: this paper is mostly about Java, which I rarely use and basically only known from Elasticsearch (where log entries about GC pretty much always seem to i
29.
▲
by
mdb31
4y ago
Cool idea, bad implementation. This really needs to be a local tool: uploading any kind of key material to a remote site is a privacy risk, and the disclaimer that "uploading private keys is obviously discouraged" is not sufficien
30.
▲
by
mdb31
4y ago
I guess this is supposed to be some Jabbascript trickery, but for me, a 'paste' action in the second text field just yields... blankness... Which is a pretty good trick, I have to admit, exposing the nothingness of life. Kudos!
More ›