Live data from Hacker News

Viewing profile — griffinmb

griffinmb

HN member
Joined
Fri, Apr 18, 2014, 2:26 PM UTC
HN karma
987
Public activity
126 items

About griffinmb

byatt.griffin@gmail.com

[ my public key: https://keybase.io/griffinmb; my proof: https://keybase.io/griffinmb/sigs/u-6FMiNO_5m8QCpOTM-1WeHOnVBTJwx9YIjSIJFSsNY ]

Recent public activity

  1. comment
    Comment #47478605

    This is not the same company. The OP Tiny Corp accused them of Trademark infringement on Twitter, due to exactly this kind of misconception.

  2. comment
    Comment #38932711

    Agreed that there’s no way to do this meaningfully and securely. Looking forward to the archeological audits of LLM-developed apps x years from now that are a total mystery to the …

  3. comment
    Comment #38928761

    Yeah, it doesn’t fix the issue at all. Rough to have a security product demo be fundamentally insecure.

  4. comment
    Comment #36121417

    I created/maintained a popular project for years[^1], and recently passed ownership to someone else. It's been great seeing issues resolve, PRs merge, etc, after languishing for a …

  5. comment
    Comment #29593356

    The point is that with a powerful Effects system, devs calling the logger would have to account for the network call in their own code. Someone might have wondered why that was nee…

  6. comment
    Comment #29593300

    Effects can definitely help, but a strong type system allows you to encode security concerns for compile time feedback as well. See https://gmb.is/refinement-types.html for a non-H…

  7. comment
    Comment #27429890

    Given that he's now un-retweeted it, it looks like even amasad agreed it wasn't a good look.

  8. comment
    Comment #27429405

    Based on your retweet[1], you still seem to be publicly punching down. [1]: https://twitter.com/pnegahdar/status/1402018604233732098?s=2...

  9. story
  10. comment
    Comment #25755016

    You probably know this, but correcting for anyone reading. C is generally considered statically but *weakly* typed.

  11. comment
  12. story
  13. story
  14. story
  15. comment
    Comment #22894426

    It’s versioned, which is an improvement on “agility”

  16. comment
    Comment #21477142

    Yep, that’s the way!

  17. comment
    Comment #21476944

    This class of bug (CSRF bypass via route confusion) is probably more common in Phoenix apps. I’ve found a handful of apps vulnerable to this issue with Sobelow. People create (for …

  18. story
  19. story
  20. story
  21. comment
    Comment #20286921

    Sure, the "passive" was what I was calling out as incorrect. And as you noted, a compromised trusted CA affects all domains. Which is another thing this article gets explicitly wro…

  22. comment
    Comment #20286094

    This is a horribly misinformed article, and is incorrect about the most fundamental arguments it is making. E.g. Among many other issues, it implies that a compromised CA would all…

  23. story
  24. story
  25. comment
    Comment #20233811

    Agreed that you don't gain anything if you're using 1Password. But users may be required to set up MFA to access something like GitHub organizations, in which case having it availa…