Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
zsims
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
zsims
2y ago
Tradeoff is all the edge cases of cookies, CSRF etc. It's not a simple "cookies are better"
2.
▲
by
zsims
2y ago
> The U.S. government wants everyone to abandon C/C++ -- how will they do this if they depend on SQLite3? ABI, the same way you don't need the Linux kernel to be rewritten to remove your app dependency on C/C++
3.
▲
by
zsims
2y ago
We do, I want to know if it's going to rain on my birthday
4.
▲
by
zsims
2y ago
> Whilst Crowdstrike are going to cop a potentially existential-threatening amount of blame, an application shouldn't be able to do this kind of damage to an operating system. It doesn't operate in user space, they install a ke
5.
▲
by
zsims
2y ago
Blame for Flash? Or celebrated for killing Flash? Flash was a security nightmare
6.
▲
by
zsims
2y ago
There are other paths to the attack he mentioned. Eg you find an API that accepts ciphertext or part of. Or a cloud backup/restore flow. Likely you need another vulnerability but it does happen.
7.
▲
by
zsims
2y ago
The problem is, it's not their software. No control over Slack, Outlook etc
8.
▲
by
zsims
2y ago
Useful because you can support existing passwords without requiring everyone to login or reset their password. Still has flaws though, like password shucking.
9.
▲
by
zsims
2y ago
Western Australia could be the ongoing emu war - https://en.wikipedia.org/wiki/Emu_War
10.
▲
How the Talkback infosec aggregator works
(elttam.com)
1 points
by
zsims
3y ago
|
0 comments
11.
▲
by
zsims
3y ago
Nix has no security guarantees, nor sandboxing primitives. So not really comparable.
12.
▲
by
zsims
3y ago
It's from https://mathiasbynens.be/demo/url-regex and rather fantastic. Thanks for sharing
13.
▲
by
zsims
3y ago
I'd say at this point the most important part is "correctness" (rendering etc) and security
14.
▲
by
zsims
3y ago
Doesn't that argument apply to tabs also? Eg IE6 days where there were no tabs, and everything was deferred to the OS/desktop window management. It was clunky and painful.
15.
▲
by
zsims
3y ago
You mean like http://www.lambdashell.com/ ?
16.
▲
by
zsims
3y ago
I haven't been maintaining this much lately. Suffers from the same problems as other tools - the accessibility APIs are slow
17.
▲
Discovering Headroll (CVE-2023–0704) in Chromium
(canvatechblog.medium.com)
15 points
by
zsims
3y ago
|
1 comments
18.
▲
by
zsims
3y ago
Discovery of Headless Chromium security vulnerability, how it works, and mitigations that should be applied to similar configurations
19.
▲
by
zsims
3y ago
Unless they see Bard as fulfilling that.
20.
▲
by
zsims
4y ago
You're worried about performance but want x86 emulation on ARM?
21.
▲
by
zsims
4y ago
You're just making up things trying to find a reason. HTTP was only invented in 1989, so these imaginary early 80s clients likely don't exist
22.
▲
by
zsims
4y ago
> $18321AUD Is that a typo? Or are they actually that exxy?
23.
▲
by
zsims
4y ago
Flatpack only came out in 2015
24.
▲
by
zsims
4y ago
And the commercial fork: https://www.bsimm.com/
25.
▲
by
zsims
4y ago
Um excuse me, how will people know I had an açai bowl for lunch?
26.
▲
by
zsims
4y ago
At that point, how much of the internet is that?
27.
▲
by
zsims
4y ago
Partial mitigation. It's not SSRF "proof" but I suppose nothing really is.
28.
▲
by
zsims
4y ago
Unsure if joking. XUL was awful.
29.
▲
by
zsims
4y ago
If the patch gap is small, yes. But are you patching V8? Node generally isn't.
30.
▲
by
zsims
4y ago
> It was reasonable to overlook this option 170 years ago, when the Rails Blog Tutorial was first written. Woah. Rails is really old
More ›