HN user

keturn

34 karma
Posts0
Comments19
View on HN
No posts found.

The thing that bugs me about this model is that it's not challenge-response, so someone can play man-in-the-middle.

While it's possible to hijack someone's phone number, as demonstrated, it requires a relatively high amount of effort per target. Whereas if you compromise a network segment somewhere (with DNS and a rogue SSL cert or whatever you need), you could just sit there, farming authentication cookies. Have your MitM check the "authenticate this computer for 30 days" checkbox and you've got a nice little collection to work with.

I was talking to someone recently who likened it to a shifting pendulum. For a while, he told me, terminal control languages were sufficiently complex that you could send a program to run _on the terminal_, and then things shifted back to running things where you store them on the server.

Now there's HTML5 and javascript, the world's most complicated terminal control language.

Unless your product is something that builds on Twitter's platform, I wouldn't recommend it. It means your users don't have a choice about how they're authenticated to your site, and

A) Failwhale, anyone?

B) Twitter doesn't provide serious options for protecting their users' login credentials. It's the same username/password combo which is easily phished & replayable.

Sadly, I've pretty much given up on the hope that we'll have a healthy ecosystem of OpenID providers, but at least Google's login system does offer some two-factor options.

I had some linting tool yell at me about this recently. It said something like '''forms["formname"] better written as forms.formname'''

Bah. I've been happily using Google services with a non-Google email for years now, but when I created a gmail account for that ID, all my notifications from all google products (e.g. google calendar notifications, notifications from other Google products like Google Code) suddenly started going to the gmail mailbox instead of the address they'd been going to all along.

Fortunately I was able to delete the gmail account to reverse this, but it was relatively difficult to find the "turn off gmail" button. And if all new accounts get gmail, they may stop letting you turn off gmail at all.

Thanks for this comment, as not yet having got into Scala myself, I had to read between the lines to figure out what the problem was here. I thought "Ok, you don't have binary compatibility, so recompile your dependencies. Sure, it may extend your build time somewhat, but it shouldn't make it impossible to use dependencies or test pre-release builds..."

Oh, you don't _have_ the source? Well, there's your problem.

A good reminder of what some of us take for granted in our development environments, I guess.

I've found that when I use the webkit inspector, those unused values don't show in the Closure section of the Scope Variables display, and if I put a breakpoint in there and try to reference the unused variables I get a Reference Error.

Yeah, I keep reading the post, looking for "no new clients" statement that is in OP's headline, and not finding it. I read it as you do; they suggest there's not a whole lot of opportunity in building more clients, but it doesn't read like they'd deny you an API key for it.

Work Less 15 years ago

Status quo for a "40 hour week" at my current employer is 8-5 M-F with an hour lunch. I tried it for six months and decided it was a bad idea.

I was able to renegotiate things to 9-5, but my manager acted like it was this really unusual request and wasn't I lucky that they were willing to let me work "less than 40 hours."

That left me wondering, what do other people consider full time in this industry?

You've been able to do that with OpenID for the last few years, that's why you can just have buttons for Yahoo, Google, or myOpenID instead of needing to type in joe.myopenid.com or google.com/id/aoeiasnexhtsanogysaeig==