HN user

leigh_t

28 karma
Posts0
Comments15
View on HN
No posts found.
[GET] "/api/user/leigh_t/stories?hitsPerPage=30&page=0": 500 Failed to fetch user stories
3D Printed Sugar 12 years ago

I apologise for my impulsive reply. I should have better discipline (usually I don't reply at all because I know I'm pretty dickish)

This is how the site looks to me: http://s13.postimg.org/uduowd0if/sugar.png

In my opinion this is pretty terrible. We all know the importance of first impressions (case in point, people reading my initial response).

due to a vulnerability in the extract() command

No.

This is due to insane usage of the extract() function. Not a vulnerability with the function itself.

You can pass user-supplied input directly to plenty of other functions which have equally idiotic outcomes, it doesn't mean that they have vulnerabilities, it means the author is a liability.

It was indeed an excellent course and for any would-be participants I recommend buffing up on discrete mathematics and number theory already if they're not your strong suit.

I found the course pretty hard as programmer with a strong interest in crypto, but no formal CS/maths background. The coding pieces were fairly straightforward, but the maths hurt.

Please please please email out to past participants when it is available, the first one was amazing amounts of fun.

Well there seems to be some misunderstanding about who released what. I have not released anything because I didn't have to.

All I have done is link to some items that she released into the public domain on a previous occasion.

Sharing the stupidity of others is a long-lived internet tradition. It's almost adage status; be careful what you post, it may come back to haunt you later. The same is true of this, I suppose.

This has a tinge of pettiness to it

I don't think it's petty at all to link to publicly available information, when others have requested that information. Google-fu differs between individuals.

I do find it particularly petty that someone would go to great lengths to expose the private details of the life of a man who just wants to be left in peace.

It's a little premature to be recommending scrypt. There have been some posts on openwall suggesting it may be weaker than bcrypt, although it is also still a work-in-progress. I'd hold off until it is more battle-hardened before either recommending it or using it.