HN user

peblos

172 karma
Posts0
Comments52
View on HN
No posts found.

I left in 2010 and the consensus is very much the same among my friends, or at least some of them anyway.

I’m no longer eligible to have an opinion UK or local conversations. “how would you know”, “the city’s changed a lot since you left”, “why are people who chose to leave so interested in X”, statements specific to ex-pats.

For those from outside the UK, ex-pat (expatriate) as a singular term is almost always derogatory regardless of context or publisher.

I realise I’m judging the book (and possibly the authors) by the cover but Nielsen’s book cover is objectively more readable.

It’s also probably the only one that would still look new, or current, if it was released today

I bought a Mac 1 year ago

Capacitors can hold charge for a long time, so no touchy. It probably wouldn’t kill you, because capacitors don’t actually store that much energy9, but that doesn’t mean it couldn’t kill you, so, no touchy!

I'm recalling the time I was trying to load a "backed up" game on my original Playstation using the disc swap [0] method while the chassis was open.

Since I had the top lid off, I had to hold the disc tray closed button for it to spin up. While looking away to pick up the other disc my pinky moved and touched a capacitor and had me on the receiving end of a massive zap.

I've never touched a capacitor since, thank goodness.

[0] https://www.youtube.com/watch?v=yDopEevII3o

I started using testssl after first using slabs.com.

As the other commenter mentioned, testssl.sh lets you can websites that aren’t public yet e.g. test environments or other private networks. As well as testing against starttls if you need to test encryption on a mail gateway.

It’s also configurable, meaning you can have it test tls protocols alone, or ciphers alone, client renegotiation alone making it quicker and easier to read if you are looking at specific areas

I tend to use testssl.sh (https://testssl.sh/), are there any major benefits to sslyze?

I’ve just tried running it a moment ago to compare. The output isn’t as organised/readable and it includes several tracebacks for failed checks (tlsv1.1, tlsv1.2, tlsv1.3, and compliance against Mozilla TLS configuration).

Always open to different tools but it seems testssl.sh is currently more complete

Selling 6 planes is nothing. It wouldn’t even cover the standby aircraft of many fleets. You need large orders to make it feasible, and you need a strong product to secure those orders. FedEx, UPS and co. aren’t going to fund you long term unless you have a product and you need good teams and good funding to even get you to that starting block.

Boom is probably the closest thing to what is suggested but many still doubt they will make it to production. That’s minimal investment though and mostly around options on orders, so they still need massive funding to get there. Rolls Royce and others have said it’s not viable to design an engine for them so now they have to design the airframe and the engine.

Bombardier is an example of why new entrants should be concerned. As soon as you become a close threat, you don’t really trigger competition you trigger massive protectionism which forces them to sell the design to airbus, further consolidating the market

I think the incumbents would have to be broken up to seed any new competition that is remotely viable. The Boeing story has some way to go yet though, who knows

Didn't want to delve into it in the original comment but what you mention is correct and is one of the reasons I mentioned how far back this was.

I haven't read Herman Pontzer's recent research, I'd equate to becoming a more efficient runner; as efficiency increases energy demands are reduced.

Some of today's research just didn't exist when this was written. Of course, some of the advice was already debatable by the time I got to read it in the mid-late 00's, but that can be said for a lot of health and fitness advice even today.

I didn't follow it proscriptively. What it did do was give me a different approach to tackling it as a problem and was the first resource I had read that helped in that regard. Everything else was very much eat less of this and more of that

Like thread's asking which book/resource to use when learning to code, there are many good examples out there. Not all are perfect, and some are occasionally wrong but like that example, this was the one that stuck with me.

Extra ceiling fan remote was my favourite use.

Couldn’t find a ceiling fan remote one time ( I have 3 with the exact same remote ) and used it to manage fan speeds

Still doesn’t justify the cost but I guess it’s like my leatherman. Hardly use it but handy when I do.

I actually bought it when seeing the pwnagotchi comparison and expected functionality from the wifi/marauder dev boards to be included. Meaning I got my flipper in the first batch for my country but couldn’t get a dev board even months later

I don’t think this comment is disputing any of that.

It did mention the financial and public sector industries, which you call out, and only being able to speak for the UK however.

While it didn’t include HFT, that doesn’t employee the same number of heads as the others

In A, the publisher is repeating the claim without validation or substantiation that the passenger was actually kicked of and reason Y is asserted by the passenger. Basically A is hearsay

In B, the publisher is stating as factual that the passenger was indeed kicked off (as opposed to getting off for any other reason) and that it was in fact for reason Y.

B puts the weight of the writer/publisher behind the claim with a higher bar for verification of events

Also, I think the passenger is trying to be helpful but surely he knows that he can’t manage the infotainment system as a passenger. There has to be some detail or interaction not reported here

So many domains send mail that fails one or all of them, some orgs are quite relaxed when it comes to enforcement

Not helped by O365’s previous stance of delivering DKIM failures to junk, although I understand they have or will soon reject them

The timing is just less than ideal.

They started disclosing in July and it looks like everything was very professional and responsible only to publish the week before Christmas.

From the timeline, perhaps CERT/CC could have done more or could have been quicker in their review. 5th December is probably the absolute earliest reporting date, but published on 18 Dec after what I can only guess was nearly 2 weeks for internal review

So, the decision is to publish the week before Christmas or wait until early/mid Jan when staff return and they took the less than ideal option to publish early, presumably in case they were scooped

I Hate MFA 3 years ago

In scenario 1, I can see the reasoning if we’re talking a low value account e.g. pseudo-anonymous account that holds no personal/financial info. In this case the service isn’t worried about you but the platform as a whole where a person or group can control many accounts

Scenario 1.5 is non enterprise but with a financial or something of value aspect e.g. rewards/loyalty programs. The service has to protect against fraud

Scenario 2: if we’re having this discussion about the need for MFA, how it ties us to devices and all the other reasons mentioned already, then using a security key with remote attestation is even more difficult for the end user. I don’t see how this is an improvement. It is in fact MFA itself, just with a different, more cumbersome, type of factor

I Hate MFA 3 years ago

Using a local password manager isn’t MFA. How is that verifiable to the authentication service?

I Hate MFA 3 years ago

“For example, I’ve been using a password manager for the last two years, and now all my passwords have been generated automatically. This means that if you steal my password you’ll only have access to one of my accounts.”

At risk of stating the obvious, this misses the point of MFA.

Password managers are not an alternative to MFA. Also, how do you enforce the usage of a password manager such that you can confidently remove the requirement for MFA?

The whole idea is to protect the one account. If you “only” lose one account that’s still a bad day. Service1 has no ability to protect Service2, so protecting all of your accounts is not something MFA tries to solve

That's true but reading the article in full (again), nowhere does it say what other special features have been added that other companies might require

Even in the referenced article from The Register there’s no mention. Lots more context of the types of threats being faced, but no additional features beyond time keeping and better reliability at low temperature.