You’re right, the math is slightly more complicated than rent v. mortgage payment.
Ben Felix, a popular financial YouTuber, made many a video about the math:
https://youtube.com/watch?v=j4H9LL7A-nQ https://youtube.com/watch?v=lBG-g1CKfgs
HN user
[ my public key: https://keybase.io/whymarrh; my proof: https://keybase.io/whymarrh/sigs/z4egYPE7ZfGGxpW0Jjs4Lpf7DsWGzz8XsxsLqELfz68 ]
You’re right, the math is slightly more complicated than rent v. mortgage payment.
Ben Felix, a popular financial YouTuber, made many a video about the math:
https://youtube.com/watch?v=j4H9LL7A-nQ https://youtube.com/watch?v=lBG-g1CKfgs
I don't think this is a useful comparison. This is Google's bug with Google's software vs. Project Zero's discoveries are (as I understand them) typically in software used by multiple people and thus there's a higher urgency to fix them.
https://confs.tech/ has a decent crowd-sourced list
Even if your Master Password is “hunter3”, 1Password, as an example, will mix in a locally generated Secret Key to increase the entropy [1]
GitHub Pages also doesn’t (yet) support custom headers and you can add them with Cf via Workers. So if you’re concerned about the results of securityheaders.io, for example, you can add those in.
1Password's cloud offering architecture has a few important distinctions from other offerings. Namely the use of a password authenticated key exchange (PAKE) and a "Secret Key" that is never transmitted to 1Password servers. [1, 2] If you ultimately trust the app for local vaults, there's a case for extending that trust to the cloud offering.
[1] https://blog.1password.com/what-the-secret-key-does/
[2] https://old.reddit.com/r/1Password/comments/rp8t02/security_...
And what does this revocation accomplish? The app still has your unique address. This revocation is simply "don't log me in next time." You still need to use the app to delete any data, if that's even possible (highly-dependent on the app). This is no different than going to your GitHub account (in the parent comment's example and revoking https://docs.github.com/en/authentication/keeping-your-accou...).
I don't disagree that having a keypair on the client for authentication is a cool idea, but it's hardly specific to "Web3" (e.g. https://developer.apple.com/documentation/authenticationserv...).
Web3 is by far the easiest way to provide auth to a web app right now
Easiest by what measure? As I understand it, few browsers (read: only one or two) have built in wallets and outside of that the UX for this auth isn’t great. It’s hard to see how this is better/easier to use than existing OIDC/"Sign In With X" solutions.
Similarly, basically everyone using Ethereum just uses Infura nodes [1]. Web3 is no more decentralized than anything it purports to improve upon.
This is something that folks are working on via the `passwordrules` attribute https://github.com/whatwg/html/issues/3518
With that and a well-known endpoint for changing passwords (not quite the same thing as what you’re describing; https://w3c.github.io/webappsec-change-password-url/) we are moving in that direction.
Small plug for LavaMoat (https://github.com/LavaMoat/LavaMoat) which includes tools to more granularly disable dependency lifecycle scripts via @lavamoat/allow-scripts.
Yeah they’re similar feature-wise but the communities that exists on GitHub vs. GitLab aren’t remotely comparable.
"If you like this you might also like" https://ferd.ca/awk-in-20-minutes.html
I too am happy to see more Awk material in the world, once I learned a bit about it I started reaching for it more and more.
The author linked to https://en.wikipedia.org/wiki/California_Unfair_Competition_... (I can't speak to its relevance)
Even inside in the web world, this approach wouldn't quite work for features with even a modicum of state.
Yup, there's quite a few different configuration options available: https://docs.github.com/en/code-security/supply-chain-securi...
There could be a simple explanation for this: Mozilla has its own browser stack whereas Edge is Chrome.
Let's be honest here. Curl to 98% of people is http/1 requests with some post params and maybe json body, with some custom headers.
100%, that's why we see so many smaller projects pop up (on GitHub and the like) that support basically just this. No shade to those projects, improving the UI for this subset is a worthy cause, it's just not anything near cURL.
I was surprised that "Awk '!a[$0]++'" works too (on Mac at least). If I "ls Awk" in \usr\bin, it says Awk is there. If I "ls awk" it says awk is also there—but it seems they're the same file, and it's only pretending Awk is a file. AWK also... I never noticed that before!
I presume this is a side-effect of the macOS default filesystem being case-insensitive. I'm running macOS with a case-sensitive fs and that does not work:
$ awk
usage: awk [-F fs] [-v var=value] [-f progfile | 'prog'] [file ...]
$ Awk
-bash: Awk: command not found
This default is a topic of great debate.There are platforms that don't use PoW that are becoming quite popular. The NBA's Top Shot platform is built [on Flow](https://www.onflow.org/primer) which does not use PoW.
I'm not making _any_ claim about the worthiness/sustainability of the platform, just that it is what is being used. The list of "communities" on the Flow landing page suggests that it's being considered for a couple of high-profile platforms.
today when you sell crypto art it's PoW.
I think more specifically when you sell crypto art on a platform that uses PoW, which makes this sentence a truism.
This is the result of rendering everything to a <canvas> element.
If the accessibility story isn't rock-solid, frankly this is a non-starter for a lot of applications. Web apps suck in a lot of ways but regular HTML has pretty great accessibility properties.
I don’t understand, so what? They’re doing their best and if users go somewhere else so be it. I’m sure if they could avoid the outage they would.
They’re not losing profits or anything. They’re hosting a free service. When they get the service back online users will have a secure messaging option that is even more battle-tested.
I had similar issues with their macOS app using a pretty basic headphone+microphone setup (EarPods). I ended up leaving it off and not re-installing in on my latest setup.
I've had a subscription from mid-2019, though I no longer use it. I find Zoom's basic noise suppression good enough for calls.
Where does one find VPSs this cheap?
And this is via Rosetta 2?
I was just about to bring up mutation testing. I've had some pretty great success with PIT [1] when writing Java. Code coverage and mutation test coverage pair wonderfully together.
[1]:https://pitest.orgwhere by they tell upstream what they are doing and if upstream wants to continue to be "Github compatible" well upstream better adopt it as well....
Do you have an example of this? This seems like it would be a hard sell as there haven't been many (any?) breaking changes to Git itself in a long while.
At their scale I do believe there’s a benefit to authenticating to see logs: a lot of people scrape GitHub for secrets. CI logs are at high risk for user error, errors where a user unintentionally marks something as non-secret when it should’ve been secret. Putting these logs behind auth feels like an easy filter for some scraping.
Maybe this is a bit nitpicky, but Snowden himself does offer Signal to people [1] and is listed on the Signal homepage as "using Signal every day" [2].
[1]:https://twitter.com/Snowden/status/986277159252750336?s=20
[2]:https://signal.org