PHP has always escaped forward slashes to help prevent malicious JSON from injecting tags into JavaScript I believe. Because it was common for PHP users to json_encode some data and then to write it out into the HTML in a script tag. A malicious actor could include a closing script tag, and then could inject their own HTML tags and scripts etc.
HN user
daviddoran
Same — it’s absolutely other-worldly. Like being in an alien spaceship. Truly breathtaking. One of my favourite places in the world.
I agree with a lot of the comments that (1) giving heartfelt thanks (which you can do more than once over the years) and (2) being there to help them if they ever need it and (3) paying it forward is the best you can do.
You could throw money at it or try to make big gestures but to the people that helped you just knowing how much it meant to you is the best reward.
Like other commenters I used Game Maker 20 or so years ago and not only made games but also programmed little utilities to solve problems at my Dad’s work. It was a phenomenal blank canvas for creating games and programs and learning to program (because there’s both Scratch-style drag and drop programming, and a programming language).
A family member works in banking phone support and the scams people get caught by are unbelievable. Every week people are convinced by scammers to give their bank cards to a taxi that arrives at their house (supposedly sent by the bank), they transfer 1,000s of euro to foreign bank accounts (supposedly at the request of the bank to safeguard the funds), they lie to the bank (somehow convinced by the scammers), etc.
Bought and played this as a "non-Computer-Science" developer and really enjoyed it and learned from it. It helped with understanding intuitively some concepts that I hadn't deeply understood.
I found it a little buggy or unpolished in places (like the scrolling/zooming behavior or how hint videos are only sometimes available) but that's a pretty minor complaint.
No. Half way through the article she specifically starts doing everything on the B+ (the old RPI with the issue).
Same! I created numerous games with early GameMaker as a pre-teen. I even managed to use it for making various useful little programs, like an interactive calculator to show my Dad’s company that the bandwidth required for multiple security cameras would eat up all the bandwidth available on the relatively slow internet connections. It definitely had an enormous positive effect on my career in software.
Box’s “influence over authority” is a good read: https://boz.com/articles/influence-over-authority
Yes, business and first class commonly have power-operated seat adjustments (recline, lay flat, extend foot rest).
Interviewers not showing up seems really weird and surprising. At that point the hard work of scheduling etc. is done.
Even then, whenever you’re dealing with large amounts there’s risk. E.g., early on in Bitcoin’s development a user lost a lot of Bitcoin by making a small test transfer, not realising that the change (their remaining balance) was sent to a new address in their wallet. But they were running a bootable Linux Distro from a CD and didn’t save the wallet back to a USB or other permanent storage. So they’ll never have access to those keys.
Tuple’s audio quality really is good enough to feel noticeably different to Zoom or other VC. Much more like your pairing partner is in the room talking into your ear.
We use the described setup at our company and the VPN software (Viscosity) auto connects so seamlessly that you never really need to do anything manually. Works really well.
Very clever approach, I like the simple text-based format.
This is typically so you can't simply subscribe someone else using their email. The 'victim' would only get a single email and they'd have to subscribe to keep receiving them. It also avoids typos etc.
I'm delighted they're finally doing this. I've a 2011 Macbook Pro sitting on a shelf for the last year because the graphics went haywire and eventually it wouldn't start at all.
I think a slightly more practical approach would be to make an easily self-hosted web proxy with an accompanying Google Chrome (or other) extension that can rewrite all network requests.
Searching for "voice calling" changes the input to "voice\ calling". And then there are no results :(
The "Favorite Languages" need a little updating. I wanted to pick OCaml, Rust and Hack.
I think that was addressed by the author: '... the long S is that it occurs only in the middle of words, never at the beginning or end.'
Lots of ways actually: it could be hosted on the web but use HTML5 offline storage and caching; it could use something like node-webkit or atom-shell; it could be a Chrome extension.
I'm delighted to see Atom open sourced. I tried it out a few weeks back and came across a bug where the editor would lock up when a few empty files were created. Then I couldn't dig into the code to fix the issue but now I can.
The actual behaviour (the link with a random email address) is so far from the expected behaviour I'm finding it hard to believe how it happened. Probably search indexing/ranking error as others have speculated.
Guy discovers critical vulnerability and could have completely fucked the company over.
We all frequently have the opportunity to cause damage, but we don't get rewarded for _not_ doing so. I think Prezi may have given the cash reward if the pentester hadn't logged in and browsed around. They probably don't want to set a precedent (take the data you find, get cash reward).
... because if the credentials were invalid (quite likely), it goes from CRITICAL to MINOR.
Agreed, but either way the pentester won't be able to fix it. All he can do is report his findings.
... but better that than black hats.
Agreed, but if you stray outside the terms of the bounty then you're no longer guaranteed the rewards. I think the pentester tried his best to report responsibly but I don't think Prezi are obligated to give the reward, based on the terms.
I think they acted pretty fairly by pointing out that it's the logging in that they have issue with. Although it's not as satisfying, I think Shubham could have submitted the link and credentials to Prezi without actually accessing the repo. In particular, the report email contains the snippet "... I explored the nexus console to confirm that ..." and I can understand Prezi not wanting to encourage pen testers to explore their systems, even if they find them open to the world.
I've been interested in the benefits of something like http://www.guardtime.com/ for a while. Using a distributed network like Bitcoin seems perfect.
Using the right language for different buyers is a good lesson. First thing I'd A/B test on the page is the section mentioning "Cheap". I think business purchasers rarely want cheap, they want value and cost effectiveness.
Nice work. Might be interesting to be able to add our own backends, e.g. allow a URL to be entered in preferences and then SnappyApp just does a regular POST of multipart/form-data and the "Location: ..." returned by the server is copied to the clipboard as the shareable URL.
I think they're trying to interest actual girls (read "from 7 to 22") in technology and coding.