Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
omervk
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
omervk
4mo ago
I've been using crit since very early on and it's become an invaluable tool in my arsenal since day one. It really fills that niche of reviewing agent work easily and painlessly. Thanks for building this and for being so attentive
2.
▲
by
omervk
2y ago
(part 1 of 3, with the other two linked from the post)
3.
▲
How we saved millions on AWS
(tech.forter.com)
44 points
by
omervk
2y ago
|
8 comments
4.
▲
by
omervk
12y ago
"Without blocking your users from using your app" Almost every single example on there was blocking my view of the content in one way or another.
5.
▲
by
omervk
12y ago
Please don't send passwords via email. http://plaintextoffenders.com/faq/devs
6.
▲
by
omervk
12y ago
I've been influenced by jetlag more than once and I can say hands-down the most effective and least cumbersome method I've found is just to take a Melatonin pill and drowse off to sleep 10 minutes later. If I'm still feeling
7.
▲
by
omervk
12y ago
Thanks for the feedback. I went back to the article (which we started linking to a couple of years ago) and saw the comments and, along with what you wrote here, removed the preference of scrypt and PBKDF2 over bcrypt.
8.
▲
by
omervk
12y ago
I'd appreciate it if you could post this as a comment on the page itself. :)
9.
▲
by
omervk
12y ago
Hey all, this is @omervk, one of the co-founders and maintainer of plaintextoffenders.com. I was thrilled when OP approached us with the initial version. I'm really looking forward to seeing what you guys can build on top of this :)
10.
▲
by
omervk
12y ago
Good point.
11.
▲
by
omervk
12y ago
That's a great idea! I'll add "I've been listed! What do I do?" to the FAQ. Thanks!
12.
▲
by
omervk
12y ago
I thought of my mom and dad reading this and what they would best understand. I'm worried using something like "one-way encryption" would have their eyes glaze over :)
13.
▲
by
omervk
12y ago
I'd appreciate it if you could post this as a comment to the Dev FAQ page :)
14.
▲
by
omervk
12y ago
Yes, because you might not be the first to use that password.
15.
▲
by
omervk
12y ago
Re: Q8. Security questions are an anti-pattern and the rest are outside our mandate. I do not claim to have written the penultimate guide to password security :) Re: Q9. Again, that's a great pattern, but is not a requirement to not be
16.
▲
by
omervk
12y ago
Fixed. Thanks :)
17.
▲
by
omervk
12y ago
Added. Thanks :)
18.
▲
by
omervk
12y ago
Soon :)
19.
▲
by
omervk
12y ago
I have. Please take a look at another comment that explains the issues with it here: https://news.ycombinator.com/item?id=7943695
20.
▲
by
omervk
12y ago
Thanks, I used your number, too. :)
21.
▲
by
omervk
12y ago
What would you suggest as a sane upper bound?
22.
▲
by
omervk
12y ago
1. You're right. Fixed. 2. Rephrased.
23.
▲
by
omervk
12y ago
Soon :)
24.
▲
by
omervk
12y ago
Because then users would lose faith in your service? Also, your service can then be abused. Think about a hacker ramping up charges on a credit card, only to have fraud detection activated and you losing money (and getting worse rates in th
25.
▲
by
omervk
12y ago
It's a good thought, but the FAQ starts with what we are, why and how to contribute.
26.
▲
by
omervk
12y ago
What would you suggest?
27.
▲
by
omervk
12y ago
That's a good point, but I think it goes a bit over what I was getting at.
28.
▲
by
omervk
12y ago
Thanks, I've added wording for that.
29.
▲
by
omervk
12y ago
Good idea. Implemented.
30.
▲
by
omervk
12y ago
Hence our mentioning that the user must receive a mail notifying of the password change.
More ›