HN user

sysadm1n

1,889 karma
Posts247
Comments273
View on HN
cs.sjoy.lol 2y ago

CSS Joy Webring

sysadm1n
2pts0
www.zap.org.au 2y ago

Console Fonts from Linux and BSD Distributions

sysadm1n
2pts0
sprotty.org 2y ago

Sprotty: Diagram Visualization Tools for Your Web Applications

sysadm1n
1pts0
www.eenewseurope.com 2y ago

Fully-coherent RISC-V Tensor unit boosts AI applications

sysadm1n
2pts0
newsreleases.sandia.gov 2y ago

Detecting nuclear materials using light

sysadm1n
2pts0
docs.aws.amazon.com 2y ago

AWS Best Practices for DDoS Resiliency

sysadm1n
1pts0
meyerweb.com 2y ago

Blinded by the Light DOM

sysadm1n
1pts0
www.deque.com 2y ago

How to Design Useful and Usable Focus Indicators

sysadm1n
3pts0
cirosantilli.com 2y ago

Markdown Style Guide

sysadm1n
4pts1
1ft.io 2y ago

F*** Paywalls

sysadm1n
63pts88
www.psychologicalscience.org 2y ago

Zombie Ideas

sysadm1n
1pts0
silvanhagen.com 2y ago

Laravel Passwordless Magic Login Link with Breeze

sysadm1n
2pts0
www.cssfontstack.com 2y ago

CSS Font Stack: Web Safe and Web Font Family with HTML and CSS Code

sysadm1n
1pts0
cloudfour.com 2y ago

When to Nest CSS

sysadm1n
2pts0
blog.rot13.org 2y ago

WordPress comment spam – what to do about it and how

sysadm1n
1pts0
nts.strzibny.name 2y ago

Deploying Rails on a single server with Kamal

sysadm1n
1pts0
www.geocities.ws 2y ago

Pokemon Flames – The Hottest Site on the Net

sysadm1n
2pts0
pdx.su 2y ago

CSS Is Fun Again

sysadm1n
3pts0
www.fastly.com 2y ago

How Fastly Protects its customers from DDoS threats

sysadm1n
3pts0
matduggan.com 2y ago

Help Everyone Do Better Security

sysadm1n
2pts0
chriscoyier.net 2y ago

Attribute Superpowers Taken All the Way

sysadm1n
1pts0
blog.gitguardian.com 2y ago

Yes, GitHub's Copilot Can Leak (Real) Secrets

sysadm1n
3pts1
vaibhav111tandon.github.io 2y ago

Vov.css – Pre built CSS animations

sysadm1n
1pts0
csswizardry.com 2y ago

The Three CS: Concatenate, Compress, Cache

sysadm1n
1pts0
nooshu.com 2y ago

Remove Subresource Integrity (SRI) from the Gov.uk Assets Domain

sysadm1n
2pts0
academy.hackthebox.com 2y ago

Hack the Box Academy

sysadm1n
1pts0
radapp.io 2y ago

Radius – Open-source, cloud-native, application platform

sysadm1n
2pts0
sarajoy.dev 2y ago

Do you know color-scheme?

sysadm1n
2pts0
kizu.dev 2y ago

Scroll-Driven State Transfer

sysadm1n
2pts0
www.fatherly.com 2y ago

Your Happiest Time in Life Is Still Ahead of You

sysadm1n
1pts0

For smartphones, assume an always-on wiretap situation. But for laptops, it may be harder depending on how hardened your setup is, and how tight your opsec is. There is the possibility that if you're a high value target and you bought your laptop online that it could be bugged, but you would have to be someone like a drug trafficker or a journalist or some other high profile person.

whom I chat with over IRC

What, IRC is still used in 2023? There is a panoply of other discussion forums to shill your talent/products/services.

How do you defend against hackers using these to attack your SaaS server?

This is a broad question. There are multiple ways to defend, besides basic security like firewalls. Blocking nefarious IPs or domains only gets you so far, as something will slip through the cracks. Try reading this: https://opsec101.org/

It does not matter that much, relatively speaking. People include 1MB font libraries in their site without a care in the world, and force 1-2MB PNGs and JPEGs down the wire without caring. A few extra bytes in jQuery is nothing compared to that.

I try and find books that are not popular, since if you want to Think Different, you have to read what others are NOT reading, so you have an advantage over your competition who are all indoctrinated by the latest trend or groupthink. Old dusty libraries & bookshops with obscure literature are my favorite for procuring these items.

Why not fork it into a separate product? I understand the Everything App premise, but companies like Meta have their products in distinct buckets (Instagram, Whatsapp, Threads, etc). That way people's pseudonymous accounts are not tied to their finances. I know for me, I don't want my Twitter/X alt account anywhere near my finances.

Should have been nationalized and made a public utility IMHO. Musk just wanted a new toy to play with, and has trolled Twitter from day one. Billionaires buying up the media is nothing new.

“I've come up with a set of rules that describe our reactions to technologies:

1. Anything that is in the world when you’re born is normal and ordinary and is just a natural part of the way the world works.

2. Anything that's invented between when you’re fifteen and thirty-five is new and exciting and revolutionary and you can probably get a career in it.

3. Anything invented after you're thirty-five is against the natural order of things.”

― Douglas Adams, The Salmon of Doubt

Seriously considering running a JIT-less JavaScript free browser should be the standard for surfing these days, and only whitelisting sites you trust (like your online banking site or Amazon for example). Disabling JS wipes out entire classes of attacks. I know developers assume the user has JS enabled and codes their site to that end, but a small minority disables JS to get rid of various annoyances and for accessibility reasons, and, malware issues in the browser.

This attack can still be pulled off without JS though: using plain old CSS & HTML. It seems these attacks are targeted to the non tech savvy, but even I (tech savvy) get duped by persuasive messages in my browser. This is why I advocate for a Phishing/Malware 101 course which is mandatory for all types of tech-related courses and learning.

I remember downloading demos from Pouet and testing them out on my machine. I quickly realized some of these only worked on higher-spec'd machines than mine, and some of them were laggy and glitchy af, but they still worked.

What I gathered is that every line of code counts in a demo, and the hardware constraints were a good thing as you had to push the envelope of the hardware. Now people spin up bloated Electron apps on their machines which could be slimmed down substantially if more effort was put into reducing lines of code and all those wasted CPU cycles are embarrassing.

But people have beefy setups that can run Electron and a host of other apps simultaneously, so they don't care to put in the effort anymore.

Always code as if you're coding a demo is my mantra.

90% of serotonin is made in the gut. So if you look after your gut, you will feel less gloomy / depressed. I take probiotics, kimchi, eat plenty of fiber, and get good fats into my diet (avocados, eggs, nuts).

How do you tackle this?

Disabling JS in Safari gets rid of a lot of annoyances whilst surfing. You could also try the Brave browser or the DuckDuckGo browser on iOS which block ADs by default.

But this is just a bandaid for the problem. What I would like to see is DNT (DoNotTrack) being honored and taken as a sign that you've opted out of tracking, instead of tracking happening even though the DNT flag is set to true.

I'd also like if all browsers including Safari on iOS shipped with a Consent-o-matic / 'I dont care about cookies' type of functionality which globally & automatically opts you out without having to press buttons or close a modal window / popover.

That's the reason you see websites requiring phone number or credit card verification these days

And this is trivial to overcome (depending on how eager the registrants are). The pro freeloaders have access to many different numbers and typically order SIM cards in bulk, and CC's can be spun up easily too all using different names. The real pros buy these in bulk from the dark web, so it's a non-issue for them. Passport scans and a 3D selfie that matches is the gold standard for auth now.