HN user

videoappeal

12 karma
Posts2
Comments24
View on HN

[quote] The bitcoin breach seems analogous to Bank of America storing your account information on Linode and trusting it as the Real Data. Does that make sense? [/quote]

//reply to tomg, but seem HN stops nested replies beyond a certain level

At the end of day you can have millions of dollar of security, auditing, PCI compliance tests passing, developers that celebrate every Friday that everything is secure, data is hosted on premise etc... But if you leave the login page javascript to a third party hosted on Linode then you might as well be BoA storing your data on a mySQL linode instance. So in a nutshell it kind of undermines the work you guys do.

Not sure about this PCI complaint stuff, but perhaps this is why major banking companies jumped from Linode to EC2? Much improvement? Although I must say I have friends working on banking websites in the UK that dont know the whole picture, its not unreasonable to assume that these things are fucked up.

Well tomg, when I researched this ~8 months ago there were at least 2 US financial websites that were using the same specialized analytic company that injected JS into banking login pages that were hosted on Linode VPSes.

All this talk about banks being safe yada yada and cloud hosting not safe for US50k. Real banking companies (with billions of dollars on hand) do use commodity cloud hosting including Linode, for even sensitive parts. Take for example Natwest online banking login. On initial login page they load a cookie via an image from www.advanced-web-analytics.com and then once you enter a customer number the next page loads a ...drum roll... javascript file from www.omni-traffic.com. Now who can tell me what one can do when you have control over the Javascript on a banking login page?

Ah crap. It looks they have been moved to Amazon EC2, ~8 months ago they were hosted on conventional Linode VPSs. Points still stands though.

tl;dr - giving an article a skim read it appears these devices wont allow facebook or youtube etc... so my point is probably mute..

Learning begins? Or we further Facebook's cause (along with other activities that are complete waste of time, gaming and streaming poor comedy). In Thailand at lot kids / teenagers / young adults have a netbook or laptop or a smartphone, if you are being a mr nosy you are guaranteed to see the little blue bar at the top of the screen and face palm, the wealth of information that is out there..

I should add "Have you been accessing sensitive sites such as your Google accounts" on a shared computer." The HN reference was to distinguish if the poster's complaint was worth of a discussion or is it one of 100k+ people a day that get caught by keyloggers/phishing/social-engineering through their own stupidity (like accessing Google wallet on a shared computer)

Bad advice.

Coffeescript isnt a framework, it is a language.

So for your DOM manipulation you say you understand the quirks and difference between WebKit and IE7, what about the host of over rendering engines, mobile/tablet/desktop and different OS editions. I bet there exists dozen of bugs in your implementation. But thats how startups waste money I guess. If JQuery isnt your style use another abstraction library or a lightweight version of jQuery, combined with minification, gzipping or a CDN, rolling your own (at your current level) is just STUPID, risky and a waste of money. Typical NIH.

Agreed. But with no transparency it pays to be cynical. In addition, bootstrapping it by asking HN to commit their time and web space whilst drawing a salary is a bit of a slap in the face from day 1. Im sure a consortium of true HN readers could get this off the ground without salary employees, maybe in six months then it would make sense to appoint salary positions such as a treasurer and top-notch biz dev person.

Indeed, but perception is a powerful thing, a non-profit for charities especially. Microsoft and [insert-evil-company-of-choice] could be non-profit if you soak up any remaining revenue by salary/bonuses. I mean ICANN is non-profit and the CEO already has put a down payment on a learjet from his new $185,000 tld registrar. My point is that they are soliciting free work from HN readers on some illusion of acting like a charity (it might turn out legit and verifiable, who knows) whilst being as transparent as a SOPA.

For sure, I hope you dont object I've just registered adsbycappuccino, my idea is to make it a non-profit ad agency that does work for benefit of charities, in my business plan Ive decided to pay myself $120k pa (is yours the same? we can share a coffee and talk) presuming we get that via donations and running some commercial ads in the roration. It should take off as those stupid HN readers will see non-profit and put some rockets behind my startup. Sweet.. :D

>[Clojure] .. example of the emerging trend of evented, asynchronous backend languages.

Clojure is not a great example of this, and certainly doesnt have any event loop magic or async IO libraries built in. There is some in progress such as Aleph etc.. . But hey another great example of people promoting shit they know nothing about.

Statistic is flawed. Most people who use the default white themes probably dont read HackerNews, dont care to optimize their setup or routine. Those that read hackernews with a woren out F5 key are likely to be heavily influenced by the dark theme propaganda (screencasts etc..) that swamp HN. Just saying.. I can draw any reasonable conclusions from your stats, or even my own devil's advocate view.. Does it matter?

Watch it last night. Nothing new of any value. If you read any of the articles when the guy died you'll know the story already. Only interesting bit was steve woz saying how he wasnt bittered but was upset to the point of crying when he read years later than jobs had fucked him over on the money from the split for developing a game in the early days.