This is interesting, but it would help if you could provide .wav files for others to hear and see for themselves.
HN user
z-factor
AMD - $2.7B
You have a strange standard for 'savvy' people.
Yes.
I understand how the attack works, the question was about how a practical exploit would actually be carried out. I've figured out how one would issue GET requests from the right environment, but I don't know if the same is possible for POST.
The request has to be issued by the attacker from the victim's browser. If the attacker can do that, why is he unable to read the response to that request?
Edit: I think I can see a scenario where a third-party website does these requests via an <iframe> or an <img>. I'm not sure there's a way to do POST quite as easily.
The attacker has to be able to issue requests on behalf of the user with injected "canary" strings. I fail to see a practical exploit where one can do this and wouldn't have access to the secret in the response anyway. What am I missing?
gallerix.ru has a lot of relatively hires art: http://gallerix.ru/album/Museums
Speaking from personal experience (Ukraine).
There are plenty of job opportunities and the coders are relatively even more overpaid than in the West, so that's not the reason.
The real reason I believe is that people mostly can do this with impunity. There's very little being done for prevent or prosecute credit card fraud. In Ukraine and Russia CCs are still used very little, so this fraud hurts "the West" which is mostly seen as a good thing by the general population. Rampant piracy is practically encouraged for the same reason.
Of course this creates a barrier for doing legitimate business online. For example PayPal simply does not allow merchant accounts from Ukraine and Russia to reduce fraud. These countries are the safe haven for hosting illegal content etc. It would benefit local programmers to clean up the reputation of the country and to my great annoyance people just do not realize this. Crooks are accepted as keynote speakers at business conferences etc (they do make money, so what's the problem?)
Banks seem to be doing ok.
Funny thing is that code is then compiled with a compiler was not formally verified, so it's still a 'fingers crossed' situation.
> A quality of a great leader.
That or exaggeration.
I remember reading though a page where they listed their employees and I remember it was 100+, I wanted to include the link in my comment, buy couldn't find it this time.
Wikimedia employs a lot of people, I personally do not donate because I believe they employ way too many. Also pretty much all costs are already covered by corporate sponsors like Google.
They were using Akamai and not CloudFront last time I checked (which was a while ago). And of course they must have legacy systems that were built before their in-house solutions were available.
There seems to be a correlation between geek culture and liking engineering, but I'm not convinced there's correlation with being any good at it. I'd say there's negative correlation if any.
Here's a recent video of the last survivor: https://www.youtube.com/watch?v=ayWPnm0JWG0
I want to add that I've been using heapq for scheduling in every piece of software as well and it's never been a problem even in heavily loaded projects.
> people didn't think they could have any kind of meaningful conversations without at least a paragraph of prose
Still can't. (Oh, the irony!)
I asked something similar recently on HN: https://news.ycombinator.com/item?id=5039241
That got zero offers.
Not original source, but close enough http://js2coffee.org/
I think hmexx did not intend the money to be the major incentive. It seems to me that the major incentive there is seeing your idea finally implemented and having someone handle the part that you don't like or don't know how to do. However, as much as my ability is unknown from just this offer, I don't think it can be argued that it's any less than hmexx's marketing abilities -- he claims to be techie, not some hotshot marketeer.
First of all the same problem exists with hmexx offer -- he can stop putting any work in and will still be the 50% equity cofounder.
Second, if the business is promising and I have a significant equity in it, of course I'll pour more work into it. I'm on the next project only while the other party does their part marketing until we evaluate in a couple months if it's working out.
And I also want to point out that my work is not something you can buy on elance at all, and most definitely not for cheap anywhere.
Does it make you cringe in both my and hmexx's offers?
There's value in getting it done fast and right the first time and having quality talent invested in the success. The upfront money is more of a way to guarantee that the idea person is invested in the success as well.
You could be right as well and then it's a testament to disproportionate leverage money has in our world.
Well, the consensus is that the value of an idea is almost certainly zero, so the only way to make it worthwhile is to get one runaway success in a big pool of attempts. Everyone knows the VC version of this approach. This is how it would look like for a programmer. I'm not dead-set on these specific upfront costs and equity split, this is just the reverse of the original offer.
I got that. Imagine this chain of 50% companies growing to some length. That could lead to a subprime mortgage crisis in a teapot. =)
Well, my offer is to get 50%, not 25%. If you want to reduce my share you can increase the upfront payment, so I guess you can spend some money out of your pocket to get a portion of the company. This can get out of hand fast =)
Yes, of course. Still, given all the people who make the claim that the ideas do not matter, only execution does, how many will act on that belief?
Here's a counter-offer. If you have an idea and I like it, I'll take your $5000 and will build an MVP. You'll have to commit to spend at least $3000 more on marketing right after it. And I'll take 50% of the business.