How do I read this site with uBlock? Graylisting all requests/scripts only gave me a header and a footer.
HN user
kecks
Modern browsers... except Google Chrome, which has at least 40% market share.
Google Chrome does not support applets in any way since the deprecation of NPAPI.
I accidentally had appletviewer.exe it from the JDK, however the applet is served over http. I do appreciate this because I'd accidentally turned off HTTPS Everywhere and hadn't noticed (in weeks I suppose).
I think I'm not the target audience, I hope OP finds some good physicists to show this to :)
Sorry, but I'm not running your Java applet.
Perhaps you could port your game to something like Processing.js? It allows for very Java-like syntax, compiles to html5/js and is good with graphics.
I don't see it?
I'm probably using the most aggressive blocking setup possible, though: I have a bunch of filter lists, I don't ever make exceptions to them, and instead deny all scripts and 3rd party resources, then graylist by hand (using the matrix).
Key points:
* Spoil your users like you're their grandparent.
* Aim for getting powerusers who love you.
---
Wouldn't really recommend this article, read this article by PG instead: http://paulgraham.com/ds.html ("Do Things that Don't Scale"). The PG article is a lot longer and has more substance.
I regret taking the time to unblock them in uBlock; had to unblock 3 domains just to get anything but a blank page, and usually it's just the one domain.
No?
The link you posted is indeed a MITM proxy for SSL, but it will generate certificate errors, as my grandparent said. Users will know the MITM attack is going on (unless the website doesn't use HSTS and the attacker has stolen/bought a signing key from a CA registered in your device's trust store).
Oh, thanks, it worked now!
I'm proposing we write a simple canary spec, for canaries that are both human and machine readable. A format could be, for instance:
* canary.txt in the root of the site.
* Optional text introduction, describing the canary's purpose, the way rsync.com does.
* PGP signed message with expiration date; content optional.
* Replaced by either a 404 or a 451, the 451 for those who want to be more explicit and like to live dangerously.
You probably shouldn't state you're compliant with the spec if you implement it.
.
I'm personally very willing to run a replacement canary watch, I'll see what I can set up over the weekend. I'm thinking of writing it in PHP, so it's easy to copy for others.
I'm thinking it'd be nice to couple it with a spider that automatically indexes these canaries, and to also have captcha'd "add your own" option.
Could anyone point me to a guide to setting up a HN-proof PHP server?
It didn't work for me at all; the red dot never appeared on my screen, though the face-outline in the preview image did fit my face quite well (when it wasn't detecting my chin as my mouth).
I haven't yet, but mine is underway.
The model I got has 8gb ram, 240gb SSD, 1tb HDD, Core2Duo processor, and is upgradeable to a Core2Quad.
However, I'm strongly considering just keeping it as a backup. To me it represents the best possible backup computer, durable and auditable.
It's backup for when my current computer breaks down, but also for when new sinister surveillance and encryption laws are passed. Or for when the web turns into even more of a wild-west with hackers and nation-states doing whatever they feel like.
I kinda feel like it was a bad idea to even discuss my ordering of this on a non-throwaway, from an IP vaguely linked to me.
.
That went kinda dark. Guess I haven't been taking enough Soma.
What if you make your core competence as a programmer "gaining steady footing in new tech", along with basic like code structuring, version control and some automation (CI/testing etc.)?
That way you might not become "the greatest X86 assembly programmer" or whatever niche you like, but you might become a very proficient system integrator, which is useful in its own right.
Buy a Libreboot T400? It comes without Intel ME and is FSF-certified: https://minifree.org/product/libreboot-t400/
It is pretty expensive for the amount of performance you get, but you are getting a fully documented, auditable and free product. It comes with instructions on how to update/build/flash/modify your firmware. You're also supporting the Libreboot project.
An atheist doesn't believe in the existence of god(s); a theist is the opposite and believes in the existence of god(s). The difference lies in lack of faith v. faith.
An agnostic believes it's not possible to be sure whether one or more gods exist.
Combinations are possibly; an agnostic theist believes in the existence of gods, but also thinks it's impossible to be sure.
There are also apathetic agnostics; they don't know nor care whether one or more gods exist. This usually seems to go with atheism.
I suppose there should also be a word like nontheists; those who have faith in the non-existence of gods.
I think he meant this:
https://lkml.org/lkml/2015/9/3/428
(It's Torvalds on a bug made harder to spot by using array arguments in C, which you shouldn't do.)
hard
A 1-char password can be guessed in as many attempts as the size of the allowed character set, and in half the guesses on average. Even less guesses are required on average if passwords aren't distributed uniformly and this distribution is known (i.e. from previously cracked password databases you know most users pick "e" for a password, so you start with that character and get into the accounts of 40% of all other users in a single guess).
More generally, the average number of attempts required to crack a password with a known length is 1/2 * charsetsize ^ length. So with alphanumeric case-sensitive 1-char passwords the number of attempts required on average is 31. That's not a lot.
The only thing that salt + hash does is make it possible to check the password without having to store the passwords on server; it only serves to protect user passwords after the password (hash) database has been stolen by attackers.
The only way to keep a semblance of security when user passwords are very short is to aggressively rate-limit password attempts, but in the case of 1 char passwords that doesn't help, you'd have to lock the user out after a single wrong password entry, and even then attackers would have a chance of 1/62 (26 lowercase letters, 26 uppercase letters and 10 numbers) chance of getting into your account.
I thought the default look of the site was a bit hard to read, so I made two themes for Stylebot. If you have Stylebot installed you can go to the site, click the Stylebot icon and load either of them from "Stylebot Social".
Stylebot is only available for Chrome though; does anyone know an alternative to Stylebot which is as user-friendly as Stylebot but also available on a broad range of browsers?
... which is empty as well.
I don't have this problem, I got a perfectly clean page without any ads or social media icons.
I'm running the latest Chrome with uBlock Origin (bunch of filters incl. privacy, social and anti-anti-adblock) and Ghostery. I don't know why you're having this problem, maybe try adding a few blocklists?
Did you mean anything by that?
VISA debit isn't available in NL either. I get the impressions very few countries actually give out these cards.
This is an exploit as well, just a different kind. It doesn't require any programming errors in the clients, instead it relies on the non-standardization of clients.
I'm not really clear on what azk actually does...
Is this an alternative to Vagrant?
Why wouldn't I use Docker instead of azk?
This can leak the user's client by changing links per client.
Make a link per identifiable client, show only the one for the current client, and give each link a post/get parameter identifying the client. Quite easy to do, but a lot of work to have broad client support.
Tada! I now know you read your email on your [obscure and bugged client], which is susceptible to [this and that exploit].
Took 6 seconds on a Samsung Galaxy S6, Firefox. I definitely would've closed the tab if I hadn't read this.
No, because every language has one specific set of abstractions and interfaces chosen by the language's developers. This is the same for textual and visual programming languages alike.
What might well be very hard is making a language where all abstractions and interfaces map to useful graphical representations; I imagine it's much, much easier to represent a JSON object graphically than it is to represent a piece of C code this way.
For instance, how would jumps look? Lines going from far-removed boxes, producing code that literally looks like spaghetti? Moreso, do you even want to graphically represent things like pointer arithmetic, will this be easier to work with? How do you represent variables, globals?
Maybe you would only represent course features such as data flow graphically, and hide finer grained details and code in "blocks" with labels and defined in- and outputs. You would still mostly write your code, but the graphical view might help you mentally model your program.
Wow, that's oddly similar to an idea I've been playing with.
Who do you see as the core users of these tools?
Oh, I haven't spotted moderation in action before. Does this mean this thread will be merged into the old one? Or will it be removed?
He might've just got hashes from those private keys, for proof. It's not clear if he actually took all these keys. To me this would seem like a responsible, easy and realistic way of proving you could've taken the keys if you were malicious.
The whole point is kinda moot, seeing how they did not have proper auditing and can't know if the keys were taken either way.
Whose privacy did Wes violate? Do webservers have data personal to them?