HN user

jamescun

2,285 karma

Twitter: @jamescun Github: https://github.com/jamescun Blog: http://www.jamescun.com/ Email: hackernews [at] jamescun.com

[ my public key: https://keybase.io/jamescun; my proof: https://keybase.io/jamescun/sigs/eg-YzEEaRcyzNwlxW6095oWVjkLanjoACl6O7WSxk0U ]

Posts37
Comments277
View on HN
lethain.com 3y ago

Digg's v4 launch: an optimism born of necessity (2018)

jamescun
246pts327
riskledger.com 3y ago

Building Our Public API Alpha

jamescun
2pts2
riskledger.com 3y ago

How we approach virus scanning uploaded files

jamescun
5pts0
thetaxcollectorman.medium.com 4y ago

Valve Isn’t a Company Interested in Mods Anymore

jamescun
2pts0
riskledger.com 4y ago

Floating point numbers, and why they suck

jamescun
24pts47
riskledger.com 4y ago

Git techniques

jamescun
86pts77
riskledger.com 4y ago

A Tale of DNS and BGP: The Facebook Outage, October 2021

jamescun
66pts16
www.nxnsattack.com 6y ago

NXNSAttack: A new vulnerability that exploits DNS recursive resolvers

jamescun
5pts0
medium.com 7y ago

Announcing TokenCard Visa Debit Cards

jamescun
3pts0
www.cuvva.com 7y ago

Showing off our fancy new K-sortable IDs

jamescun
12pts1
github.com 9y ago

Go Interface Fuzzer

jamescun
1pts0
www.macrumors.com 10y ago

UK Developing Digital Driving License Stored in Apple Wallet App

jamescun
2pts0
stephenradford.me 10y ago

What's going on with Fetch?

jamescun
2pts0
jamescun.com 10y ago

Binary Sizes in Go

jamescun
2pts0
www.moserware.com 11y ago

The First Few Milliseconds of an HTTPS Connection (2009)

jamescun
82pts0
medium.com 11y ago

Shareable title about designers and code

jamescun
2pts0
gocardless.com 11y ago

Coach: An alternative to Rails controllers

jamescun
5pts0
github.com 11y ago

Show HN: Run SSH and HTTP(S) on the same port

jamescun
165pts65
gocardless.com 11y ago

Introducing Logjam

jamescun
4pts0
www.montulli.org 12y ago

The Origins of the Blink Tag

jamescun
13pts8
www.newyorker.com 12y ago

The Many Lives Of Iron Mountain

jamescun
3pts0
torrentfreak.com 12y ago

Private Torrent Sites Run Their Own Mini-PRISM to Share Data on Users

jamescun
3pts0
torrentfreak.com 12y ago

Sky's Court Ordered Piracy Filter Blocks TorrentFreak

jamescun
6pts0
arstechnica.com 12y ago

New attack plucks secrets from HTTPS-protected pages

jamescun
233pts55
jamescun.com 13y ago

How "Traceroute 216.81.59.173" Works

jamescun
5pts0
agilecdn.org 13y ago

Show HN: AgileCDN

jamescun
3pts1
jamescun.com 13y ago

Amazon didn't kill HMV

jamescun
5pts0
jamescun.com 13y ago

Masterless Puppet

jamescun
7pts0
github.com 13y ago

PHP drops world domination from TODO list

jamescun
11pts0
jamescun.com 13y ago

Young Rewired State to Silicon Valley

jamescun
6pts0

This post touches on a realisation I made a while ago, just how far you can get with the guarantees and trade-offs of object storage.

What actually _needs_ to be in the database? I've never gone as far as building a job queue on top of object storage, but have been involved in building surprisingly consistent and reliable systems with object storage.

UK citizen and 23andMe customer here. How likely is the sale of UK/EU customer data, or is it worth submitting a GDPR deletion request anyway? Get my data deleted before it's sold.

I was recently in hospital with not-so-great WiFi.

With the mobile app, I would often notice Spotify loading album artwork, lyris, artist information and even video before playing the music. It's network prioritisation is deeply disconnected from the users wants.

I remember when Spotify heavily optimised to play music in the quickest possible time. Enshittification indeed.

Why is silently patching considered a "no-no by the infosec community"?

If your product's automatic update functionality can reach most users within the responsible disclosure window, that sounds like a net positive? We still learn about the vulnerability but limits the potential fallout of the disclosure.

I'm very much in-favour of the private vulnerability research and responsible disclosure, but the "no silently patching vulnerabilities" sounds more like wanting to own the press to me than actually wanting to improve people's security.

The ICO has always been a bit of a wet blanket. Never really uses its powers effectively. From pathetic fines to putting out press releases about raids before they happen. £140k is just the cost of doing business with 79 million spam emails and 1 million spam texts.

I don't like this. Is there a reason for using a stringified method prefix?

I'd prefer the type safety of verb-specific methods (i.e. mux.Get, mux.Post etc) than magic strings validated at run time. Additionally editors can autocomplete/intellisense methods.

Risk Ledger | Remote/Hybrid London, UK | Full-Time | Backend, Frontend and Product Design | https://riskledger.com

We're a London-based startup, with a mission to solve the problem of security risk in the supply chain, globally. The world runs on data, with every business relationship involving a great degree of trust. We facilitate that trust. Risk Ledger offers a secure social network model for organisations to connect and share their security and risk data.

Risk Ledger is backed by multiple high-profile VCs, including Lifeline Ventures, firstminute capital, Seedcamp, Village Global and Episode 1. We're already working with a number of great companies across multiple verticals to achieve our vision, including the likes of ASOS, Snyk, BAE Systems and the NHS.

Senior Backend Engineer https://riskledger.com/careers/senior-backend-engineer

Senior Frontend Engineer https://riskledger.com/careers/senior-frontend-engineer

Product Designer https://riskledger.com/careers/product-designer

I bought a Dyson V7, and the battery life even from new is atrocious. On a full charge, unable to cover my very modest London flat, and of course, it cannot be used while charging.

I even fitted a larger aftermarket battery. Still awkward to use. Eventually I gave up, and bought a corded Henry from Numatic.

I cannot recommend a cordless Dyson for anything except light dust busting.

+1 for the C920.

Got lucky and got one before the prices of webcams went crazy due to pandemic demand. Think they are back to around ~£60 now.

It just works. Plugged it in, picked up within macOS without a problem, immediately usable in Google Meet. Picture is fine, audio is fine. No complaints.

Risk Ledger | On-site/Hybrid London, UK | Full-Time | Backend, Frontend and Product Design | https://riskledger.com

We're a London-based startup, with a mission to solve the problem of security risk in the supply chain, globally. The world runs on data, with every business relationship involving a great degree of trust. We facilitate that trust. Risk Ledger offers a secure social network model for organisations to connect and share their security and risk data.

Risk Ledger is backed by multiple high-profile VCs, including Lifeline Ventures, firstminute capital, Seedcamp, Village Global and Episode 1. We're already working with a number of great companies across multiple verticals to achieve our vision, including the likes of ASOS, Snyk, BAE Systems and the NHS.

Senior Backend Engineer https://riskledger.com/careers/senior-backend-engineer

Senior Frontend Engineer https://riskledger.com/careers/senior-frontend-engineer

Product Designer https://riskledger.com/careers/product-designer

Misbrands 5 years ago

I'm sure somebody has a project to link Rust from Go, and are thrilled to have this as their project logo!

Risk Ledger | On-site/Hybrid London, UK | Full-Time | Backend, Frontend and Product Design | https://riskledger.com

We're a London-based startup, with a mission to solve the problem of security risk in the supply chain, globally. The world runs on data, with every business relationship involving a great degree of trust. We facilitate that trust. Risk Ledger offers a secure social network model for organisations to connect and share their security and risk data.

Risk Ledger is backed by multiple high-profile VCs, including Lifeline Ventures, firstminute capital, Seedcamp, Village Global and Episode 1. We're already working with a number of great companies across multiple verticals to achieve our vision, including the likes of ASOS, Snyk, BAE Systems and the NHS.

Backend Engineer https://riskledger.com/careers/backend-engineer

Senior Backend Engineer https://riskledger.com/careers/senior-backend-engineer

Senior Frontend Engineer https://riskledger.com/careers/senior-frontend-engineer

Product Designer https://riskledger.com/careers/product-designer

What you'll find difficult is establishing trust.

I have no reason to believe your review site is a shill for another company, but I have no reason not to believe that either. It was recently revealed that Kape Technologies, a former malware distributor and now owner of PrivateInternetAccess and ExpressVPN, are doing this.

The first step would be clearly identifying ownership and benefactors.

.plan 5 years ago

This is neat. I am more surprised however that the `finger` utility is still shipped with macOS!

Risk Ledger | London, UK | Full-Time | Senior Backend, Frontend and Product Managers | https://riskledger.com

We're a London-based startup, with a mission to solve the problem of security risk in the supply chain, globally. The world runs on data, with every business relationship involving a great degree of trust. We facilitate that trust. Risk Ledger offers a secure social network model for organisations to connect and share their security and risk data.

Risk Ledger is backed by multiple high-profile VCs, including Lifeline Ventures, firstminute capital, Seedcamp, Village Global and Episode 1. We're already working with a number of great companies across multiple verticals to achieve our vision, including the likes of ASOS, Snyk, BAE Systems and the NHS.

Backend Engineer https://riskledger.com/careers/senior-backend-engineer

Frontend Engineer https://riskledger.com/careers/senior-frontend-engineer

Product Manager https://riskledger.com/careers/product-manager

Risk Ledger | London, UK | Full-Time | Senior Backend, Frontend and Product Managers | https://riskledger.com

We're a London-based startup, with a mission to solve the problem of security risk in the supply chain, globally. The world runs on data, with every business relationship involving a great degree of trust. We facilitate that trust. Risk Ledger offers a secure social network model for organisations to connect and share their security and risk data.

Risk Ledger is backed by multiple high-profile VCs, including Lifeline Ventures, firstminute capital, Seedcamp, Village Global and Episode 1. We're already working with a number of great companies across multiple verticals to achieve our vision, including the likes of ASOS, Snyk, BAE Systems and the NHS.

Backend Engineer https://riskledger.com/careers/senior-backend-engineer

Frontend Engineer https://riskledger.com/careers/senior-frontend-engineer

Product Manager https://riskledger.com/careers/product-manager

Another one, ensure the password validation on sign up and login are the same.

Happened at least once with a large broadband provider in the UK where I was able to sign up with a password but never able to log in due to stricter validation on login!

I welcome the return to brands using serif fonts.

Nothing against sans serif, but there are only so many times you can see Helvetica or Gotham!

Before the internet, that meant car ads in car magazines and watch ads in the Economist. Ads were based on context, and on inferring the audience from the context.

You can still do this. Car ads on car websites. Watch ads on the Economist website.

Has there been any research on the effectiveness of retargeting?

This mirrors my experience.

I've seen more problems caused by the JVM, by default on some configurations, caching DNS indefinitely, regardless of TTL, than caused by a short TTL.