HN user
tam7t
Developer.
Kickstarter requests access to "your public profile, friend list, email address, hometown, current city and likes" from Facebook on logon. With stolen access tokens the attackers could query Facebook for that information with limitations:
1) only available until the tokes were revoked
2) if enabled, attacker must also obtain the 'app secret' and sign requests
3) if enabled, attacker must use the tokens from a white-listed IP address
The post only makes reference to encrypted passwords. Not sure if Facebook access tokens are included in that or not.
In case you need someone to send a postcard to...
The White House
1600 Pennsylvania Avenue NW
Washington, DC 20500
and you can lookup your representative here:Interesting. This along with amalcon's posting of the actual bill text seems a lot more fair than my previous notion of a first-to-file system.
http://www.hover.com/ I haven't used it but some of my friends have. They do private registration, DNS management, and forwarding for $15/year.
I see that you and I think alike... http://editmole.com (also on appspot).
I'm lazy so I went with the "notepad" style editor.
clickable link: http://ourbunny.com
Whenever I get any account information emails from "facebookmail.com" I spend 10 minutes trying to figure out if it's a phishing attempt. My opinion: Just use your real domain or if you must a subdomain, ie notify@mailer.startup.com.
Lots of information there, I'd just like to throw my support behind google webfonts. It's very easy to use:
The labs for that course look awesome. Seems like a great way to tie together OS and computer architecture material.