[flagged]
HN user
nathanmills
ycombinator is a fraud
Then why is it whenever I watch someone use their computer they always accept cookies?
They're doing it because of a preceived result, not an actual result.
Sounds like your projecting a bit.
They seem pretty human to me.
I don't see many people upset at Stripe over this, I certainly am not.
No, vagueness gets me much more upset, but there's just nothing to write about in those cases.
If you never give it back, then there can't be any more rage from turning it off.
Bias is usually the result of something, yes, but it's still bias.
Then what is it?
You must be a child.
Wow, that means 13 minutes ago must've been the first time they've ever used the site
The fact we have no clue how it works or why it happens just proves that they are plain lying
Whenever I throw slurs at them they just refuse to respond
Not actually possible though. Humans have constraints.
Yeah buddy dude I read it. Thats just not possible.
He would've just gambled it all anyway.
You are Evil.
I don't remember that being there, maybe it was edited. But 2 buttons are not "aggressive". C'mon. Really dude? You believe that shit?
WebUSB next? I would like to be able to configure my keyboard but it can only be done via their website which requires WebUSB.
What makes it aggressive?
Not pulled, just no new purchases on Steam. Existing owners like yourself can still use it and get updates: https://store.steampowered.com/app/252950/Rocket_League/
It works on Linux with Proton.
No, I will not send you malware. This scenario is about post-hacked where the malware is removed, but the attacker still has the cookies they collected. There should be a way to invalidate those cookies, just like how you can change your password if they got your password.
If you want, however, we can simulate the scenario. Find your JWT token, change your password (commonly invalidates tokens aswell), and then post it here post-invalidation. If it works still, then thats the issue. Though, changing your password commonly requires your current password and not just a cookie, so I wouldn't be able to do that. But I could probably change your username as proof. If it doesn't work, then it was checked against some revocation database that the article talks about, where at that point, where you have you check a database anyway, you might as well just store the session on the server, since the JWT is no longer stateless and provides no advantage over typical sessions.
Why would it require immediate action? Most chat services have a rate limit, stopping them at ANY point prevents it from spreading further. The messages don't get all sent at once, they will use the full access period to send as much as they can. Accounts can't typically be taken over with just a cookie, changing passwords normally requires you to confirm your current one. I hope you haven't designed any services where a cookie is enough to lock people out.
Geez, I need to re-sign in every time my mobile data switches IP?? IPs are NOT static. Mobile networks change IPs CONSTANTLY. What if I use a VPN (I do) and my IP changes constantly? What if an IOT device on your network is serving as a public residential proxy that anyone can use (more common than you may think), or hell, you have CGNAT and your neighbor does? What if an entire country only goes through one IP[1]? Have you done this in practice?
Can you explain how 30 minutes of unauthorized access is safe enough for most use cases? I feel like you glossed over that.
No, it's called an example. I refuse to provide an example for every possible scenario, as that would not fit in the Hacker News comment limit.
Let's say a friend sends you an exe file, a game they made. You run it, and immediately realize it wasn't actually your friend. The attacker has stolen your JWT session cookie. The attacker hasn't done anything yet - they are configuring their browser cookies to match yours. You go to invalidate your session / change your password, but it doesn't help. The attacker has a full hour to do whatever they want on your account. They use it to send the same malicious exe from your account. If you would've been able to invalidate the session, you could've stopped it.
I am tired of pretending JWT is fine.
I don't get it. Why were you lying to people??? Why were you pretending? Thats not healthy and pretty anti-social.
Was the /s needed?