HN user

theginger

675 karma
Posts5
Comments200
View on HN

Cors is hard to understand because the browser is protecting you and the server from malicious code that the developers are not expecting to be there. Its a hypothetical threat you cannot see during development unless you really go out of your way. If you can't see the threat it's hard to understand it, it you don't understand the threat it's hard to understand the protection against it.

Its one of those situations where you need to think like an attacker to see the whole picture.

We don't use unit of measurements. We use metrics because we have a lot more context. Rps, requests per second is a commonly used unit but it has no defined standard, you could and often do average it over time for reporting but no one says you have to. For scaling however you'll probably want to use the max not the average, because no one wants a web application where in business as usual 60% of the time it works every time.

Looking at the amount of wires going into this, my instinct is that this cannot scale, in 5-10 years this won't be doable for a Pentium chip, at least not as an at home hobby project. But I actually think it could go the other way, and in 5-10 years you'll be able to do this at home for far more sophisticated kit, unlocking crazy amounts of reverse engineering possibilities that were once thought of as near impossible, or at least only possible for a nation state scale setup.

It's not impossible that the Aws charges were wrong, it's pretty unheard of. I don't understand why the details of the charges aren't mentioned in the post. If you think it's unlikely you could have a $1500 bill because you 'barely use' it then that's just wrong. In the cloud single unoptimised choices can cost thousands if you don't keep an eye on your costs, you need to look at the charges.

Cloudflare was down 8 months ago

I don't want to criticize cloud flare, I love what they do and understand the scale of the challenge, but most people don't and 2 in a month or so like this is going to hit their reputation.

This appears to be backfiring spectacularly. It is a shame in many ways because a decent digital ID system would be very beneficial. The problem is the approach is completely wrong. There are already 10+ competing ID system which are now largely digital. A solution on how to bring all that together done well could make things significantly more secure by reducing the attack surface and make it much more reliable.

Instead it looks like they are going for 1 more competing system, the implementation of which will be steered by politics and ideology rather than technology and technical requirements.

Is this anything to do with them taking passwords without consent? I rarely use windows, and when I do one of the first things I do is switch from edge to chrome. I think I set up edge and used it once to see what it was actually like, but I was pretty careful about the data syncing / sharing settings. I have the Microsoft authenticator app on my phone, I was pretty careful about the privacy settings on that too, but it's been through a couple of phone upgrades. Somehow all of my passwords were making their way into Microsoft authenticator, so I must have missed something somewhere. I can only imagine how many millions of people must have had their passwords unintentionally slurped by Microsoft if they have been that aggressive with it.

Best part of 20 years ago, which is a long time in anything, it's a lifetime in tech. About 15 years ago I used to work on some projects for greater London authority, we seemed to mostly be squatting on transport for London servers and they seemed to have good tech and people seemed to like using it. 5 years later they couldn't get away fast enough.

Something I also remember from tv was what I think they called data bursts, at the end of certain TV shows they would play a few seconds of still frames full of information, like flicking through a magazine in 10 seconds. You would record this on a VCR and play it back frame by frame, occasionally it included some computer code to manually type in, it was pretty terrible because paused video frames tended to be a bit unstable.