Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pb2au
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
pb2au
12y ago
The DNS solution has the benefit of working regardless of how the session is initiated. But only for domains. Whereas the browser handling could say that the trusted-web-server on (common name) told me that X is a valid fingerprint for t
2.
▲
by
pb2au
12y ago
but that they can't afford a $10 domain name The reason they would spend the money on the ownership of the IP and cert isn't because they can't afford the domain name. It's generally done for "mission critical&qu
3.
▲
by
pb2au
12y ago
explain a real world scenario where you have a web server with a valid certificate but you don't have a DNS entry for the server? For example, if the certificate is assigned to an IP address. Not extremely common, but some people us
4.
▲
by
pb2au
12y ago
Sorry, I re-worded "solution" to the lighter "suggestion" after posting, and I agree that there is likely a more fool-proof architecture (e.g. one not vulnerable to XSS; even HTTP headers would be an improvement, I suppo
5.
▲
by
pb2au
12y ago
The parent's suggestion would work if accessing the server by IP address directly, rather than DNS lookup. Assuming that the integrity of the data has been verified by the transport, I don't see the downside to the server providi
6.
▲
by
pb2au
12y ago
Does your university actually block all other wireless networks near / on campus? This is prohibited by the FCC. At my university, the wireless APs would scan for others and try to detect if they were on-network using a student's
7.
▲
by
pb2au
12y ago
glibc 2.18 and greater were already patched, but it wasn't recognized as an RCE vulnerability at the time. See the first bullet under the "Mitigating factors" section in the link. You can check your libc version with: ld
8.
▲
by
pb2au
12y ago
It isn't the format string syntax that is the problem that they're trying to solve. I see this as being an iterative, backwards-incompatible improvement on the existing format convention. Changes in convention don't have to
9.
▲
by
pb2au
12y ago
Hi again, No. Copyright can be used to protect moral rights, [...]. In places where moral rights are in the law, they are not subject to copyright at all. It doesn't matter. [...] Whether there are legal systems without copyright is
10.
▲
by
pb2au
12y ago
For example, here in civil law countries, there's commonly no "copyright" as such; there's Moral Rights (which protect stuff like attribution) and Economic Rights. Therefore, there's no implication that abolishing
11.
▲
by
pb2au
12y ago
Also in a previous comment by the author, before the DMCA: I also believe that it's not in Trello Inc. interest to try to censure us because of the Streisand effect, and it would be overly complex (I live in France, Yaşar lives in Tur
12.
▲
by
pb2au
12y ago
It depends on your meaning behind "free distribution", but arguably most open source licenses don't exist to provide that specifically -- they exist to permit it while abiding by the other conditions on the license. For examp
13.
▲
by
pb2au
12y ago
The argument that I recall for Chrome not having an optional master password was that it was often less secure than using the system's encrypted data store for their account, if available. Requiring a master password to decrypt the net
14.
▲
by
pb2au
12y ago
Reddit does intend to have the /r/blog posts on the front page, but they don't necessarily need to rig the votes. As mentioned in the article, the algorithm for selecting which posts appear on the homepage seems to allocate s
15.
▲
by
pb2au
12y ago
The LGPL references the terms of the GPL in the context of the library released under the license. For both versions 2 and 3 of the GPL, it states that build instructions must be made available [1]. [1] https://www.gnu.org/
16.
▲
by
pb2au
12y ago
In addition, the overzealous, erratic clicking originating from an obscure extension could make it pretty easy to detect these users. The only result would be filtering out their traffic from counting towards any PPC ads and more accurate t
17.
▲
by
pb2au
12y ago
Thanks for the second example. It's a more clear use-case than the mischievous do_damage() function I had in mind. I think intent would definitely play a role in establishing liability for damaged equipment (i.e. the user misusing the
18.
▲
by
pb2au
12y ago
A NAS box "only compatible with brand X drives" is nowhere near a NAS box that intentionally bricks non-brand X drives when attached. As a side note, are there any known cases where a vendor has released open source code that inte
19.
▲
by
pb2au
12y ago
While it may not be much of a stretch, it still hampers his point. If the goal is to convince an audience of people who are evaluating the technical aspects of systemd that there is a viable alternative to using it, the continued reference
20.
▲
by
pb2au
12y ago
Pretty cool hack, but not one I'd hope to run across in any real code. Between the nondescript function header and the inability to differentiate between an unset argument and a zero-set one, this macro would too quickly become a head
21.
▲
by
pb2au
12y ago
I disagree. When you use a password manager and separate passwords for each website, you're effectively eliminating an entire class of potential attacks, because any leaks from the website will not affect your accounts elsewhere (espec
22.
▲
by
pb2au
12y ago
The great-grandparent suggested: echo "Testing status update" >> /facebook/me/posts I think appending content to a file path (with or without the trailing slash) is clearer than the analogy of a truncat
23.
▲
by
pb2au
13y ago
It took me a couple seconds to figure out there was content below the auto-resizing header image. I tried to click on both the "Documentation is easy" and "FLATDOC" text to see if either were links to the content before realizing there was