I like the slider puzzle Mercury built into their 404 page:
My high score today is 33.
HN user
micah@qwerjk.com
I like the slider puzzle Mercury built into their 404 page:
My high score today is 33.
is having me click on an email going to make it more secure?
We implemented this at Mercury recently to stop phishing attacks, and I believe Coinbase implemented it for the same reason [1].
TOTP authenticators are super ineffective at combating phishing. If a user is willing to give their email and password to a phishing site, there's very little standing in the way of them also providing their TOTP code.
WebAuthn solves this by working with the browser to tie authentication to a particular domain, but not everyone has a WebAuthn authenticator yet.
Meanwhile, email verification links are a really simple and effective way to shut down these phishing attacks. The phisher can't click the links, because they don't have access to the user's email. The user can't click the links on behalf of the phisher, because clicking the link only verifies the device that clicks the link.
1. https://www.reddit.com/r/Bitcoin/comments/2rp9o4/beware_coin...
FWIW this is configurable. Edit `browser.tabs.tabMinWidth` in about:config
I've been using DDG for around six months now, largely because I love their keyboard shortcuts. Weirdly there doesn't seem to be a shortcut to help insert bang commands.
I've been using this greasemonkey script[1] as a workaround, but I'd love to have an official solution.
[1] https://gist.github.com/m5/247631d8258ff6f52383b417acd8516f
In a related move, Facebook disabled embedded videos from youtube/vimeo/etc last month.
https://vimeo.com/forums/help/topic:291071
https://developers.facebook.com/bugs/1963535797258090/?hc_lo...
This has come up a few times, but I liked ribbonfarm's take on the same topic.
http://www.ribbonfarm.com/2010/08/09/how-to-take-a-walk/
hn discussion:
Update: On a more detailed examination of those two states, I’m convinced the contrast here is due to differences in the sizes of the blocks. North Dakota’s blocks are more consistently small (StDev of 3.3) while South Dakota’s are more varied (StDev of 9.28). West of the Missouri River, South Dakota’s blocks are substantially larger than those in ND, so a single inhabitant can appear to take up more spaaaaaace. Between the states, this provides a good lesson in how changing the size and shape of a geographic unit can alter perceptions of the landscape.
Mine has phrase-length, plus some highlighting to help keep your place in the text.
First, it looks like this scheme is broken due to cpu constraints. However...
It had looked more like the encrypted bloom filter was intended to prevent the client from obtaining the list of registered users.
With (1) + (2), the server only has a few bits of information about each of the phone's contacts. It would be analogous to just having the area codes.
Good point. Now I understand why they were suggesting bucketing.
I came up with this method for maintaining privacy while retrieving installed apps (to give app recommendations). Sounds like it might not translate across so well.
What about this?
1) Client uploads a bloom filter with all contacts on phone
2) Server responds with a bloom filter with all registered contacts that match the client's bloom filter
3) Client displays contacts that match server's bloom filter
You can optionally trade contacts back and forth again with a larger bits/contact ratio to decrease false positives.
I think it works out so that in exchange for 7 bits of information about each contact from the client, you can reduce the server's response by a factor of 128.
First, yes, this is really cool.
However, it's even worse than you think. It's making a lot of references to minified/obfuscated names. Things like $('.nH.hx'). When I was working on a gmail script[1] a year or two ago, many of those were changing every few hours.
It's solvable, but not easy.
It's not enough to find 33 independent questions that evenly split the world's population.
An optimal, though inelegant solution to that goal might look something like this:
"Is the {1..33}th bit of sha1(name : location : date of birth) 1?".
Clearly you'll have tons of collisions with that solution, as you would have with any solution using 33 independent questions.
To uniquely identify people, we'd either need to use more bits, or look very closely at the population and derive very specific questions.
Interesting. I was going to complain, as I thought "probably" meant the probability of occurrence was greater than 50%.. That doesn't seem to be the case.
Probably: almost certainly; as far as one knows or can tell
I would guess waynecochran thought something similar.Sorry I don't have anything more constructive to say, but you have Europe and Asia reversed.
5:00 PT is midnight UTC, so Europe is more likely to have just gone to bed.
I don't know if intrinsic value is the right term, but I've been thinking along the same line.
A Bitcoin is essentially a tradable hashcash, which has direct value in spam filtering.
"Isn't it enough that I ruined a pony, making a gift for you?
It's not just about confidence.
If the price is being driven by new speculative investment (ie, a bubble), the price should stagnate as fewer speculators join the pool. If the price stagnates, there will be little incentive for purely speculative investors to keep their money in BTC.
The last cynic buying in is just an indicator of late-adopters hitting the market, signaling little gains left to be had.
Thanks to $elemMatch and automatic parameter parsing, this vulnerability is easier to exploit than it would seem.
In rails, both of these are usually considered safe:
MysqlCollection.create(:name => params[:name])
MysqlCollection.where(:name => params[:name]).all
MongoCollection.create(:name => params[:name])
MongoCollection.where(:name => params[:name]).all
However, the mongo version is vulnerable to this exploit. /create?name[0][whatever]=anything
/get?name[$elemMatch][$where]=exploitcodeIf you've had good luck with RSVP on your phone, I built a RSVP bookmarklette[1] a while back for reading articles on the web. I never had much luck reading with it, but it might be useful if RSVP works for you.
"...indeed, we were capable of inducing a complete compound eye on an antenna, on a wing, or on a leg... We actually showed, later, that the fruit flies can see with these eyes."
Wow, that really is fascinating.
Someone should release a tool to scrape craigslist and post to padlister. Wouldn't craigslist have to counter-scrape and file a DMCA takedown notice for each listing?
You can actually still use the old interface for a little while longer, even if you've been forced over to the redesign.
Another favorite of mine: Learning to be Me - Greg Egan
Better still, increment hotness by 2^(dt/λ) where dt is the time since the site was launched (epoch), and λ the halflife of an upvote. No worker process needed.
Doubles will go to infinity after a few years, but you can either reset the epoch at that time, or store the significand and the exponent seperately.
Thanks! I've added a unicode charset, but it's pretty sparse.
I didn't see anyone mounting or dismounting the unicycle in the video. If it's awkward to stop and start, it's going to look much more dorky than the Segway.
Seeing an opportunity to play with metaphones, I generated a homophone-free dictionary.
You're welcome to plug it in if you decide to tinker with the project any more.
Less magic. Ubuntu is a complex system, and hard for a beginner to learn and customize. However, there's no need to switch while you're happy with Ubuntu.
Last week, I posted something similar to proggit using the youtube redirect exploit.
During its three-hour run, nearly 6000 people (20%) tried to give me their google account credentials.
http://www.reddit.com/r/programming/comments/bpy7h/think_you...
> I know that I can choose not to work overtime, but if I don't work overtime, then I am stuck with only 770 RMB [$112.67 per month] in base wages.
I'm not sure which to believe.