Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
theboss
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
theboss
12y ago
414141. I know I'm not alone out there =]
2.
▲
by
theboss
12y ago
I'm curious. To people who have purchased bitly, why? I feel like setting it up would take as long as writing your own. My very first web project I ever did was to write a url shortener and it took me less than an afternoon. A good eng
3.
▲
by
theboss
12y ago
What's sad is that not even wrong security was in place here. They didn't even try. There was NO XSS prevention. <script>javascript</script> is the first payload you try when looking for the stupidest XSS you can
4.
▲
by
theboss
12y ago
As someone who has only just entered the `real world', I found it so incredibly odd that people's employers very often get involved in these internet dealings by firing someone because they use a sexist/racist/whatever-i
5.
▲
by
theboss
12y ago
This actually starts before steroids were invented.
6.
▲
by
theboss
12y ago
What's a native client do if Google still stores all your emails, receives all your email's, etc. It's not like once you read the email in your client Google forgets it ever saw the email.....
7.
▲
by
theboss
12y ago
Ah thanks I never realized.
8.
▲
by
theboss
12y ago
I'm seeking work to freelance as a security consultant on short engagements or small projects. Because of this my going rate is quite low. I specialize in webapp security, cryptography, android security, and love PHP (developers nightm
9.
▲
by
theboss
12y ago
I'm a recent grad with my MS in CS. I mostly focus on information security and cryptography. I want to know everything about the two subjects. I'm about to start working at a SaaS startup security company.
10.
▲
by
theboss
12y ago
This is like....seriously one of the worst documents I've ever read.
11.
▲
by
theboss
12y ago
My post is "on paper". In reality, projects are squeezed for nickels and dimes. My point is that while open-source should be better, right now it seems that everything is equally not good enough.
12.
▲
by
theboss
12y ago
There are pros and cons to both closed source and open source. Open source is nice because the community can audit the code and see for themselves, but closed-source is nice because a company generally has the resources to maintain and buil
13.
▲
by
theboss
12y ago
There's a difference between not allowing spaces and not hashing. They could have just written a bad PW policy that doesn't completely make sense You're drawing conclusions from information that doesn't lead you to one.
14.
▲
by
theboss
12y ago
In high school, I didn't know there were such things as "top colleges". I knew Harvard and Yale existed and were good...but beyond that I honestly didn't even know MIT existed. It's probably because my family has be
15.
▲
by
theboss
12y ago
I think you're going to see a huge amount of digitaloceans since "production" for me isn't exactly getting a lot of traffic, so it's on a $5 instance.. So I predict digitalocean will rack up a lot of $5 instances an
16.
▲
by
theboss
12y ago
I accidently upvoted you and now I have NP idea how to remove it. It depends on what you do. A secretary will make far less than the chief of police but they both happen to be government workers....how is that not obvious..?
17.
▲
by
theboss
12y ago
I mean...there are plenty of really good people who don't smoke marijuana too, and they do an exceptional job recruiting them from schools in the DMV area. At the University I went to, anyone who expressed interest in security and had
18.
▲
by
theboss
12y ago
I don't know what you mean. Cross fit undoubtedly has pretty good equipment compared to a globo-gym, but globo-gyms will have everything you need 99% of the time. A squat rack, a bench, and some barbells...Places to do pull-ups, dips,
19.
▲
by
theboss
12y ago
Like I said, there are a lot of reasons for backlash. I didn't even touch on most of them. I disagree that their goal is "Sports conditioning training". Because this is not consistent with their who their clientele is. Their
20.
▲
by
theboss
12y ago
cross fit is really an infiritating thing. The people who do it are sometimes diehard fans with absolutely no knowledge of how to build strength or an "elite athlete". A lot of people just like the brand... But the diehard fans ar
21.
▲
by
theboss
12y ago
I learned not a whole lot happened in Spain in the year 2000. http://en.wikipedia.org/wiki/2000_in_Spain
22.
▲
by
theboss
12y ago
Funny. I typed up my edit2, hit enter, and had a reply from you basically saying the same thing. Also, I never said anything about use-cases, signing code, etc. Only "does this safely get you the primitives", not about what you c
23.
▲
by
theboss
12y ago
There are a ton of other problems associated with crypto code. I'm talking about crypto primitives being provided by the browser. The rest of the problems associated with it, I'm not asking about. You're echoing the problem t
24.
▲
by
theboss
12y ago
I'm only talking about solving this 1 problem related to js crypto...
25.
▲
by
theboss
12y ago
Why can't browsers just build crypto primitives in that can be called from js? I don't understand what people's obsession with browser crypto is...but I don't know enough about browser's to think of a reason this so
26.
▲
by
theboss
12y ago
Also all browsing, including your cart, is served over HTTP until you go to the checkout page. You can't browse over https even if you explicitly ask for it. They don't need to ask Amazon for data if they have a router between you
27.
▲
by
theboss
12y ago
I don't know about that. Have a source? This is a pretty bad practice so I would be very surprised to see google doing this.
28.
▲
by
theboss
12y ago
Oh yeah. It's impossible to know who has your plaintext password on the backend (even steam who RSA encrypts your pw with a public key before sending), but this certainly is a bad practice and certainly makes it look like they do not h
29.
▲
by
theboss
12y ago
I actually have no idea what you're talking about. All I know is they sent her plaintext passwords to her, which she redacted before sending to me....
30.
▲
by
theboss
12y ago
She's a computer person too so she knows all this jazz.
More ›