HN user

gaunab

73 karma

frando.unbiskant.org / github.com/frando / twitter.com/frandocita

Posts3
Comments11
View on HN

Congratulations on releasing 1.0. This will be a huge milestone in making async programming very approachable to newer Rust devs and a solid base to build upon. There's a lot to like about async-std: It keeps things as similar as possible to std, and the general focus on a well-designed public API, relies on small and shared abstractions for library authors (through futures-rs), good documentation from the start, and a very encouraging community attitude. Keep it going :-)

Is there a more-or-less similar thing in Open Source? I'm looking for something like this for quite some time, but would need it to be self-hosted, and what would be even better, end-to-end encrypted (e.g. with shared secret).

They also discovered how to succeed as a tech company: Better use at least three 'O's in your brand name.

"Choosing the right name is hard. To find the perfect name, we analysed the names of top internet companies. We discovered a direct correlation between the company valuation and the number of 'O' in its name. The graph below shows the average valuation of the top 10 internet companies according to the number of 'O' in their names.

With three 'O' in its name, 'Odoo' is in phase with our ambitions."

Ads is one thing, Links titled "Recommended content" something completely different. As the OP writes, the way Disqus presents its Ads make them seem like regular content endorsed by the site's editor. And THIS is the total no-go area Disqus just ventured into, without even taking the minimum precursions by defaulting to opt-in. Bye bye Disqus.

So for this to work, an attacker needs to be a Man In The Middle, and get the attacked client to execute some malicious Javascript, which in turn crafts requests to a target site which uses TLS and SPDY. The MITM intercepts and compares the encrypted and compressed payload for recurring patterns that result when using DEFLATE. By playing with the crafted requests, he can e.g. guess cookie values that were added by the browser to the request (as many XSS attacks work) by comparing the lengths of the encrypted payloads.

See http://security.blogoverflow.com/2012/09/how-can-you-protect... for technical details.

This seems to be a very basic attack, wondering why this attack vector wasn't publicly known much earlier...

Very true words, and this irony is what should really be the matter here. It's "objectionable content" to receive reports on death penalties issued by the US government, carried out by unmanned planes at some part of the world no one in the US really cares about? Well, yeah. Thanks, Apple, for keeping your sweet and "entertaining" app store clean of this ugly and objectionable thing called reality.