HN user

hbz

160 karma
Posts3
Comments48
View on HN
[dead] 10 years ago

One of the biggest complaints about the curl - bash paradigm are the security implications. URLs can point to different content at different times. Project maintainers can (and have) changed the content at these URLs for malicious or other reasons. A lot of people will not examine the source of what they're piping into the shell.

To me, https://github.com/jbenet/hashpipe addresses a lot of these issues by pinning the content to a hash.

You can't force somebody to read and understand the install script, but at least those who do can know it's the one they verified in advance.

Vim GIFs 10 years ago

Does anybody know what program was used to generate the gifs?

  My mistake was that I didn't enable 2 factor authentication.
Kind of aggressive calling out Google's engineers when you couldn't bother protecting yourself with their free and easy to use security mechanisms.

Technically incorrect. WebSockets handshake over HTTP and then "work" over TCP. I'm actually curious which HTTP stacks are non compliant and what you mean by that.

As to my original comment, you can probably get by without having full TCP load balancing.

Did Snowden reveal anything about "Mujahideen Secrets" or whether the NSA was able to unscramble communications made using that program? If it really was using homebrew cryptography, one can imagine it was already vulnerable to the types of attacks that programmers make when rolling their own security schemes.

Github.com is down 13 years ago

Right in the middle of a deploy for us! Thankfully we're getting enterprise so hopefully this is last time a DDoS messes with our productivity.