HN user

fulldecent

79 karma

phor.net

Posts30
Comments108
View on HN
news.ycombinator.com 8y ago

Show HN: A classy way to ask for donations on projects

fulldecent
2pts1
news.ycombinator.com 8y ago

Ask HN: What would you change in Linux if building from the ground up?

fulldecent
1pts1
privacylog.blogspot.com 8y ago

What happens when you report a web server vulnerability to Apple?

fulldecent
1pts0
github.com 9y ago

Show HN: A simple machine learning game in PHP

fulldecent
4pts4
phor.net 9y ago

A list of my favorite websites and why you should stop and see them

fulldecent
1pts0
news.ycombinator.com 9y ago

Ask HN: How does your open source project ask for sponsors?

fulldecent
1pts2
twitter.com 9y ago

How to secure an online password manager

fulldecent
1pts0
www.inc.com 9y ago

Developer Broke Decade-Long Silence to Expose This Bank's Cybersecurity Cover-Up

fulldecent
3pts0
privacylog.blogspot.qa 9y ago

What Happens When You Send a Zero-Day to a Bank?

fulldecent
3pts1
news.ycombinator.com 9y ago

Ask HN: How do you avoid staying too late at work?

fulldecent
25pts43
github.com 9y ago

The build system you should use for every website

fulldecent
2pts0
github.com 9y ago

Google rejects resource integrity for AMP standard

fulldecent
2pts0
github.com 9y ago

A great example of MVC in PHP

fulldecent
1pts1
github.com 9y ago

STAT – a standardized format for your acceptance tests

fulldecent
3pts0
news.ycombinator.com 9y ago

Ask HN: Is Let's Encrypt ACME Susceptible to QUANTUMINSERT MITM?

fulldecent
1pts0
github.com 9y ago

NIST recommendation: Use random generated passwords

fulldecent
2pts3
github.com 9y ago

FDWaveformView updates for Swift 3.0

fulldecent
1pts0
github.com 9y ago

Signal issue: “Request for contacts uses creepy wording”

fulldecent
38pts10
privacylog.blogspot.com 9y ago

New UI to guarantee stronger user passwords

fulldecent
3pts1
github.com 9y ago

An opinionated starting point for awesome, reusable Swift 3 modules

fulldecent
1pts0
github.com 9y ago

Recipe to make a reusable, sharable Swift module

fulldecent
2pts0
docs.google.com 9y ago

Security comparison: Apple, Google, Microsoft, services with your personal info

fulldecent
8pts0
news.ycombinator.com 10y ago

Ask HN: Can you find the things Comey missed RE Clinton investigation?

fulldecent
4pts0
pacificmedicaltraining.com 10y ago

How Pacific Medical Training Became Carbon Negative

fulldecent
1pts0
github.com 10y ago

A UITableViewCell with a built-in UITextField

fulldecent
1pts0
phor.net 10y ago

Ask HN: How can this online resume be improved?

fulldecent
1pts0
github.com 10y ago

Lightning deployment for your ~/Sites folders

fulldecent
4pts1
news.ycombinator.com 10y ago

Ask: The Apple bluetooth keyboard hurts my hands, does this affect anyone else?

fulldecent
1pts1
docs.google.com 10y ago

Comparison of wannant-proof, quantum-proof for cloud systems

fulldecent
1pts0
github.com 10y ago

Bounty started for pdftk port to CentOS7

fulldecent
1pts1

I read this article and found it to be a great example of why we should NOT adopt modern PHP techniques at our company.

50 lines of code and contrived examples (is HelloWorld class a view or controller? AwesomeClass is a model?) get one line of HTML emitted in a barely readable way.

This article fails to motivate why each layer of complexity is added. It basically starts with the assumption that you want to use a framework and says "hey look you can do the same thing with 50 lines of boilerplate, not really, but kind of."

I would be much more impressed with an article that starts with the obvious way to write a PHP application (.htaccess, index.php, products.php, library/database.php, library/*.php) and then explains the actual problems that would make you want to opt for more complexity/organization/modern techniques.

The (perceived?) reality is that social grows your user base and RSS doesn't.

Publishers care about growth more than serving existing customers.

A visitor that comes to your site via social is MUCH more valuable than someone that comes via RSS. The economics of this reality are what removed RSS from the limelight.

Dear publishers, let's fix this. Whenever you publish a blog post, etc. please syndicate it on social and then go back to your site to add "DISCUSS THIS ON TWITTER/whatever AT https://t.co/aesou02". Make sure that this also syndicates to RSS.

Dear pubsubbers, let's fix this. In your reader software, please lint these special links and show the discussion below the news. We know you want to get into the content discovery business -- this is the first step.

See the Slashdot RSS feed as a good example, they inline the discussion right in the feed.

This article could be more clear in showing who it is addressed to.

"How to Make the Most Out of Pull Requests -- a guide for project maintainers" or "How to Make the Most Out of Pull Requests -- so that your contributions get accepeted"

I just want to say when iPhone supports external flash I will probably never use Canon again. And I've used it for 10+ years professionally in the studio. Seriously, it's like Japan's products are moving at the same speed as their economy, i.e. not at all in the past 20 years.

1/4" mount with no anti-rotate hole.

I have a 80D and there is a 1/4" mount at the bottom. But if you take a photo in portrait orientation with a long lens then the 1/4" bolt will not be strong enough and the camera will twist out of it. It's a joke!

Is it just me or does anyone else think this will be a lame project just because it of GNU stewardship?

I have closed my account and do not know the answer. Also, please if someone would be able to confirm in the affirmative in this or any other Penson site, then please start a new round of responsible disclosure.

YES. Many authors love to write more than the readers love to read them.

FIRST, be reasonable. This is a good life axiom. Don't expect a large organization to confirm, engineer, test certify, and deploy a change that requires external documentation in less than 14 days. Even if the ship's on fire.

SECOND, be valuable. If you are reporting a vuln that is a bug report. When's the last time you got thanked for /any/ buy report for a non-GitHub project? If your report explains the cost and liability for lawsuit if they fail to fix your reported vuln then you are speaking their language.

---

I have a confirmed vuln reported to Apple under their "responsible disclosure" program since 2015. They have yet to fix it or provide credit as they promised. If you thought Apple was a magic company that "does the right thing", then I hope this dispels that myth.

That's how I started the discussion with Zecco. The next phone call had the FBI on the line. Then I signed the NDA.

Next time I would change 30 to a reasonable number. In this case (multiple vendors and a large installed base) maybe even 180 days may have been fair. And then I would stick to my guns.

Surely Raneri had no authority to speak for FBI.

BUT actually this vuln may have been from upstream with Penson. And then it may affect many broker-dealers. They have many clients in US and Canada. (Don't laugh that such a ridiculous vuln could be in so many places.)

At the time, considering this (and Penson was on the phone) I understood that irresponsible disclosure could have serious consequences. FBI would have been warranted to knock on my door.

That's why I'm now publishing 10 years after the fact.