I'm not sure how that is supposed to work. You would have to rewrite every webapp so that it's data can be protected by sandstorm. Which seems hugely impractical. And as long as the webapp has access to it compromising it will compromise the data.
HN user
Sarien
I compromise an app, add myself admin account, log-in, download everything. What's stopping me?
That's just marketing bullshit. Unless the API is magic (and I don't mean advanced technology "magic" but Harry Potter "magic") it has no way of knowing what the application is allowed to send or not and therefor cannot filter. It's like saying it cannot leak data because it has to use HTTP.
How can a COMPROMISED WEBapp ever not be able to leak data while being usable?
Host authentication is a job of SSL though. So you should simply not log-in on a website if it cannot be verified that it is actually Paypal. This holds for both SQRL and passwords and seems to be an independent issue. It also applies to this case because the ssh server is supplied by the website.
@nly How does this system prevent me from setting up a website that looks like Paypal and giving you the address of my ssh server?
It's pretty much the same thing but using QR codes.
One thing that SQRL has is automatic management of different keys for each site. It wouldn't be hard to add that to the ssh version, though.
Using QR codes for getting the challenge is also nice because you can just read them with your phone on an untrusted computer.
It's better because your browser doesn't have a button to clear your ssh private keys. Cookies simply aren't meant for storing important data.
Q: "What does it do?"
A: "A utility library delivering consistency, modularity, performance, & extras."
Q: "Yeah, but what does it do?"
A: "Oh, nothing but it does it consistently, modularly and performant. We also have functions for string handling in the extras module."
"there are legitimate uses for such keys" - not for crypto
Doesn't this violate the minecraft ToS?
But paypal/ebay is a third party. Something that this system tries to avoid.
In short: The protocol is not even remotely thought through. It is incomplete and cannot work the way it is described.
I wonder if it is theoretically impossible to create a protocol that punishes cheating when the cheating occurs outside the system (when the physical goods change hands).
And even if it isn't you would also somehow have to consider the fact that things get lost or damaged in the mail and assign blame to one party on the protocol level.
Oh, sorry! Confused.
Well, at least I'm not the only one who apparently didn't pay attention for half of the tutorial. :)
Oh, I thought it was in the same row. Well, that makes more sense. I treated it like a form of sudoku with only 2 symbols and 3 repetitions allowed.
I would like to know how this is different from jabber/xmpp and how likely it is that these differences are worthwhile. They say their API is more "pragmatic" and writing a full-blown XMPP client certainly is very tricky but I wonder if improving the way XMPP works wouldn't ultimately create a better result. After all, a lot of thought and experience has by now gone into it.
Best screenshot ever.
It is a shitty generalization slandering all articles which (possibly poorly) chose a question as headline.
This is obviously an "article" where the author was legitimately interested in answering the question in the title. This is one of the cases where Betteridge's law does not apply.
Betteridge's law may be useful to remind people to watch out for poor journalism and fact checking. In that case, I propose that all articles shall henceforth use questions as titles because people should do that anyway.
Well, could anybody sum this up? Because I'm definitely not going to read Part 2 since it seems Fowler didn't even bother to produce correct sentences.
Another headline completely bereft of any information.
It's true and important why wouldn't it be enough?
I am totally in favor of good tools with good visual representations but those almost always have to be handcrafted for every specific problem. Which is probably why Bret has never delivered anything useful.
And if you're going to talk about ideas and inspiration: Lighttable does nothing that emacs didn't do 20 years ago except a little prettier.
This! And tons of other things that would have been better if this had been made using inform.
How does this kind of crap make it to the front page? What's next a vegan programming language? Gluten free mathematics? Dear god, for years I have been using a terminal with a black background and I AM WHITE!
Contrary to common belief the Great American Invention of soap is being imported and used in large parts of Europe now! ;)
I have tons of possessions and when I don't feel like it I just don't maintain them! Guess what, plants aside my possessions don't give a shit and I have just the same time gain.
"What I've been up to for the past year" another one of those hn typical "I'm not telling you anything until you click me"-links.
I think you make a very important point that I haven't seen in any of the other comments: There are lots of goods that are not traded within the economy.
The original comment is valid, many people are not relevant to the economy and indeed there are lots of articles on how we are all just wasting our time in meaningless jobs. Some studies have even found that certain jobs (like investment banking) have a net negative creation value.
Isn't the kind of activity like reading your child a story, working for free in a social group and the entire maker movement targeted at the kinds of goods that are both great and beautiful and desirable but also non-essential? Exactly the kinds of goods that people will stop paying for when they have less money to spend.
So maybe we just need to find a way to distribute the essentials and some money differently so that we can all work on beautiful but useless things instead of trying to get us all the kind of job that everybody will immediately admit they don't even want.
Just some random thoughts. ;)