It's been a long time, but I've always cherished our late night conversations at the Alexis Park. Truly a great hacker. RIP my friend
HN user
nbk_2000
@nbk_2000
Years back i was enamored with this concept and sought out various staple-less stapler solutions. Most were realistically only good for binding 3-5 sheets. My use cases required more, so i moved on. But I still admire them as lovely bits of engineering.
Other zines have filled the void left by 2600, one of my favorites being PoC||GTFO. (pocorgtfo.hacke.rs)
I think the author isn't considering that people's bubbles have gotten smaller and more opaque. There's still plenty of weird hackers innovating, they just do it with their chosen peers, not in mass-culture.
As predicted "The revolutions are not being televised."
I was thinking the same. In the meantime, here you go: https://snippetshare.dev/c/aoNWbZvSlYkJtGDHnQLohY4BnHd6hGgk8...
Same here, and with good results, but a note of warning, according to my doctor 10,000 - 20,000 are considered in the protocol a normal daily supplement for adults with vitamin D issues. Dosages above that require medical supervision (in the form of regular blood and urine analysis). Also at those high doses there are potential negative side effects that must be mitigated (osteoporosis being among them). So please don't just YOLO massive doses of vitamin D.
Same here, small panic attack ensued ;P
Glad I wasn't the only one! ;)
Back when I was shooting on film, various "Toy Cameras" came in and out of vogue. I enjoyed the subtleties of the Lomos and Dianas, so when digital cameras became mainstream, I kept a lookout for similarly quirky DCs. My favorite was the JamCam (640x480) which was fun for awhile. But soon realized, the same quirkiness could easily be achieved with digital filters applied to photos from cameras that were more enjoyable to work with. That's about when my interest in toy digital cameras died. But I have to admit, do miss the 9v consumer battery of the JamCam :P
This reminds me of the famous Taco Bell Programming post [1]. Simple can surprisingly often be good enough.
[1] http://widgetsandshit.com/teddziuba/2010/10/taco-bell-progra...
90 days since last view, or 1 year if you can afford to be generous. For "slow burn" projects with other people checklists easily go longer than a week without being looked at.
I used to operate as you're describing and appreciate the skill required to do so, but I eventually found it impacted my ability to transition a fixed scope engagement into an open-scope engagement. I've since found it more enjoyable, profitable, and beneficial to the client, to bill daily rates and let the client stretch the scope as much as they like (which they often do once they see the value my company brings).
Don't feel weird. I'd even itemize the task being being requested on their invoice (e.g. "reporting requirement fulfillment"). My perspective changed on this after doing a gig for Boeing, where they charged us for invoicing them. When we complained about this, they instructed us to bill them for their invoice fee, which they explained was how their internal cost structures worked so that the accounting department could calculate their profitability. After that revelation, I stopped asking questions and just put in the contract that all reporting requirements are considered billable work (duh).
Their tag in ASCII Art via console.log() would earn equivalent cred, and not annoy fellow users of a useful service, IMHO
After initial setup the Q Revo does not need internet connectivity. So you can set it up using an ephemeral hotspot and afterwards control it exclusively with the buttons on the top of the unit. Any errors are spoken by the device.
Octosql does this as well as a few other formats. I've found it useful several times.
Just OOC, do you currently run a stock Ubuntu distro or a derivative? (and if so, may I ask which one?)
Rinsing your eye(s) with milk will alleviate the pain far quicker than water.
Something I learned googling with one eye open while the other was burning from being touched with a habanero contaminated finger :/
I imagine they're referring to things like this (a read through the comments should give you the gist of the concerns people have voiced):
Starting to sound like the "iPhone Killer" we've all heard about... for the past 15+ years
That's not how the "free until it's not" pricing model works :P
IMHO it's just the price finding model that CF has adopted, I expect in the future they'll release limit numbers... unless they decide not releasing numbers is more profitable (i.e. the used car sales pricing model)
Such dog, much sad
"Rubber Hose Cryptography" comes in the form of a PR.
"Rubber Hose Cryptanalysis" comes in the back door and waits for you in the dark.
Thanks for the recommendation! Reminds me of Amadou & Mariam.
I'm often saddened by how hard it is as a Westerner to discover modern African music.
OctoSQL[1] does a pretty good job of allowing you to query JSON (and CSV) with SQL.
Similarly to how Journalists feel justified in stories that have negative repercussions for some parties being reported upon. One way of assessing these decisions is answering the question "Is more harm done than good by releasing information this to the public?"
From my perspective, I'm happy that Martin Vigo released this information (in 2019) as it helped me inform my employers (and now my clients) to additional threat model vectors to consider before deciding how to best perform password resets.
Also in his defense: 1) He originally released a rather crippled form of the PoC 2) It requires a Twilio account, which raises the barrier to entry and provides a data point for analysts were the tool to be used criminally.
If you're a large company that's actually serious about security, you'll have a Red Team that is intimately familiar with your tech stacks, procedures, business model, etc. This team will be far better at emulating motivated attackers (as well as providing bespoke mitigation advice, vetting and testing solutions, etc.).
Unfortunately, compliance/customer requirements often stipulate having penetration tests performed by third parties. So for business reasons, these same companies, will also hire low-quality pen-tests from "check-box pen-test" firms.
So when you see that $10K "complete pen-test" being advertised as being used by [INSERT BIG SERIOUS NAME HERE], good chance this is why.
Counter point: Most of the top rated Bug Bounty hunters have a background in penetration testing.
I think it's more accurate to say Bug Bounty only covers a small subset of penetration testing (mainly in that escalation and internal pivoting are against the BB policy of most companies).
Just thought I'd plug Octosql[1] which I've enjoyed using for this. It parses CSV and JSON, which are the file types I parse the most.
In case anyone wants to see the Gary Larson illustration mentioned in the RFC: https://www.researchgate.net/publication/2245214_Choosing_a_...
Here's a more direct link to what I was referring to: