Live data from Hacker News

Viewing profile — disruptiveink

disruptiveink

HN member
Joined
Mon, Jan 17, 2022, 2:36 PM UTC
HN karma
651
Public activity
110 items

About disruptiveink

No profile information was provided.

Recent public activity

  1. comment
    Comment #48568230

    This is stupid/dangerous advice and I will die on this hill. > The JWT specification is specifically designed only for very short-live tokens (~5 minute or less). Sessions need to …

  2. comment
    Comment #47946296

    Killed for Skype, which was already declining by that time. Microsoft was keen on unifying their IM platforms, but failed to realise that unless the migration path is incredibly sm…

  3. comment
    Comment #47945989

    Can't we just normalise publishing whatever you put into the LLM instead? I'm sure the author typed things into their favourite AI assistant that regurgitated that long form, LLM-s…

  4. comment
    Comment #47914834

    You're thinking of this like a game where the only point is to "win". That's not how this would actually work in practice. Blue is the only moral and logical choice. If red gets ov…

  5. comment
    Comment #47059744

    Correct. If you can always either fix it forwards or roll back, which you should be able to unless you're building software that needs to go out in releases with versions tracked s…

  6. comment
    Comment #47059605

    Baseline requirements are not an imaginary problem. All of them have a legitimate reason for existing. You could argue that some "are not that big of a deal", but that's exactly th…

  7. comment
    Comment #46352617

    If you purposely go into your phone settings and turn off auto-capitalization (which is what the kids do, since they're all typing on their phones), isn't it the very definition of…

  8. comment
    Comment #45822316

    Cat's out of the bag there already. We all have general purpose computing devices in our pockets, locked down on purpose. Android used to allow you to gain admin rights but it's be…

  9. comment
    Comment #45668873

    Correct. Age verification and privacy consents belong on the browser. The issue is that on the browser, things work a bit too well (remember https://en.wikipedia.org/wiki/P3P ?), s…

  10. comment
    Comment #45360297

    The insane question here is, why would the EU mandate hardware attestation controlled by two private American companies in order to access services? That seems completely contrary …

  11. comment
    Comment #45087854

    Agreed. I refuse to use the terms "rooting" and "jailbreaking" in professional environments, I always use terms like "admin access to the mobile device". Because that's what it is,…

  12. comment
    Comment #44886053

    Starmer is as authoritarian as the Tories at this point. There is no difference here.

  13. comment
    Comment #44886003

    We have a near perfect system for finding the location of phone thieves, yet the police will not go and knock on the doors of criminals even when explicitly shown proof of "this is…

  14. comment
    Comment #44885982

    I'm not victim blaming here, but does anyone have this nagging feeling that in this case, we, the "techies" caused this by refusing to engage with lawmakers? In the case of E2E enc…

  15. comment
    Comment #44796912

    Usually I would agree with you, but this is an incredibly common initialism, used by not just people in the industry, but also by consumers. Sure, it may not be as widespread as VH…

  16. comment
    Comment #44473381

    I really don't, what is the answer? I assume higher ups at law enforcement, who are detached from the day-to-day operations, make up excuses about "end to end encryption being a ch…

  17. comment
    Comment #44472947

    I don't understand why they keep trying this over and over. It can't possibly be a moral crusade as it keeps happening with different players, but I don't understand the purpose. W…

  18. comment
    Comment #44382843

    It was Bill fucking Atkinson. Not a disposable random contractor you hire by the dozen when you need to build more CRUD APIs. At that time at Apple, even as an IC, Bill had lines o…

  19. comment
    Comment #44285273

    Wait, but didn't TLS 1.0 have significant improvements over SSL 3.0? The article makes it seems that just a couple of things were tweaked just to make it different for the sake of …

  20. comment
    Comment #43495765

    Ah, yes, The color of infinity, inside an empty glass.

  21. comment
    Comment #43171887

    Google ultimately did that for China. The outcome in that case is that the domestic market filled in the gaps, while complying to all relevant authoritarian legislation. I do not b…

  22. comment
    Comment #42932978

    Amusing nomenclature, but it's a legitimate concern. If your SREs use application credentials to connect to the database, your ability to have effective access controls and have ac…

  23. comment
    Comment #41061343

    The value proposition of Crowdstrike is exactly that: something that you can deploy to tick the regulatory checkbox of "we have endpoint protection from a reputable company everywh…

  24. comment
    Comment #41061280

    What do you mean? They wrote the kernel driver. With great power comes great responsability. If you're writing a kernel driver that is deployed throughout a great portion of Fortun…

  25. comment
    Comment #40337236

    You are correct. Steve definitely believed in doing things properly because you know they're there, regardless of who can see it: https://folklore.org/Signing_Party.html > Steve ca…