Live data from Hacker News

Viewing profile — entuno

entuno

HN member
Joined
Tue, Jul 04, 2023, 8:56 PM UTC
HN karma
1,074
Public activity
217 items

About entuno

No profile information was provided.

Recent public activity

  1. comment
    Comment #48725182

    In most cases I'd think it's more of a deterrent for commercial entities, because spending money create complexity. Most employees are not in a position to just directly spend thei…

  2. comment
    Comment #48658249

    There's an assumption in here that every developer is spending a load of money on the latest and most capable LLMs to scan for bugs in their code before every release. But the last…

  3. comment
    Comment #48658179

    There is a history of companies and organisations threatening legal action against security researchers when they report vulnerabilities in their systems or products. Sometimes eve…

  4. comment
    Comment #48658147

    If I've stumbled across what I think is a security issue in your systems, there is zero chance that I'm going to get out my credit card and pay you for the privilege of responsibly…

  5. comment
    Comment #48644550

    Historically there have been vulnerabilities in various applications due to HTTP method tampering, and in the days of people accidentally leaving WebDAV enabled then methods like P…

  6. comment
    Comment #48644381

    AWS CloudFront blocks GET requests with a body, so it doesn't even have to be a particularly strict setup or an explicit WAF.

  7. comment
    Comment #48553652

    It would be very dependent on the exact circumstances - who made a complaint, what exactly they're accusing you of, what evidence there is, how high profile it is, the current dipl…

  8. comment
    Comment #48553267

    Legally speaking, no - it would still be a criminal offence. Practically speaking, there is zero chance that the USA would extradite someone to Iran, even if they weren't currently…

  9. comment
    Comment #48529660

    The Daily Mail is a trashy tabloid, so it's not surprising. Weird to see it posted here as though it's a credible source for anything.

  10. comment
    Comment #48492343

    They can be pretty shitty if you're a pedestrian or cyclist, because quite a lot of them don't "see" you, so you just get blinded by the full beams.

  11. story
  12. comment
    Comment #47989616

    There's been a lot of nice quality of life changes in the 3.7 builds (which has now become 5.0.0) that make going back to the older versions a bit painful. Also some pretty major g…

  13. comment
    Comment #47822905

    Against the Storm (and excellent rouguelite city-builder) does this in a really cool way. Pausing is a core mechanic of the game, and you frequently pause while you place building …

  14. comment
    Comment #47780394

    > The reason that the rich were so rich, Vimes reasoned, was because they managed to spend less money. The "boots" item feels less true, because expensive doesn't seem to be as cor…

  15. comment
    Comment #47780288

    Expensive doesn't guarantee high quality, but very cheap almost always means low quality. A £200 pair of boots might be great and last for a decade, or might be overpriced and fall…

  16. comment
    Comment #47767347

    Financial costs won't solve the problem for companies, because they're hard to enforce. You'd be weighting up the cost of dealing with the fallout of getting hacked against the cos…

  17. comment
    Comment #47764573

    Plus it gives the ransomware gangs a whole new angle they can use. So, remember how you illegally paid us a ransom a few months ago? Unless you want to go to prison, then you bette…

  18. comment
    Comment #47764288

    It's one of those ideas that sounds nice in theory, but doesn't survive contact with the real world. In the same way that many people would say that you shouldn't negotiate with te…

  19. comment
    Comment #47165891

    I've also seen roads that have these kind of signs, but they only apply during busy hours. However, as with any traffic controls they're useless if they're not actually enforced. W…

  20. comment
    Comment #47139695

    If that'd been the design from the start, then sure. But it's not at all obvious that setHTML is safe with arbitrary user input (for a given value of "safe") and innerHTML is dange…

  21. comment
    Comment #47139636

    It's certainly an improvement over people trying to homebrew their own sanitisers. But that distinction of being XSS-safe is a potentially subtle one, and could end up being danger…

  22. comment
    Comment #47136906

    This kind of thing always makes me nervous, because you end with a mix of methods where you can (supposedly) pass arbitrary user input to them and they'll safely handle it, and met…

  23. comment
    Comment #47089925

    And that it took this long to get an answer to that question.

  24. comment
    Comment #47001733

    "Critical security fixes may be evaluated on a case-by-case basis" didn't exactly give much confidence that they'd even be doing that.

  25. comment
    Comment #46991956

    And hopefully they're the same four same bullet points..