Viewing profile — griffinmb
griffinmb
HN member- Joined
- Fri, Apr 18, 2014, 2:26 PM UTC
- HN karma
- 987
- Public activity
- 126 items
- HN profile
- View on Hacker News ↗
About griffinmb
[ my public key: https://keybase.io/griffinmb; my proof: https://keybase.io/griffinmb/sigs/u-6FMiNO_5m8QCpOTM-1WeHOnVBTJwx9YIjSIJFSsNY ]
Recent public activity
-
comment
Comment #47478605
This is not the same company. The OP Tiny Corp accused them of Trademark infringement on Twitter, due to exactly this kind of misconception.
-
comment
Comment #38932711
Agreed that there’s no way to do this meaningfully and securely. Looking forward to the archeological audits of LLM-developed apps x years from now that are a total mystery to the …
-
comment
Comment #38928761
Yeah, it doesn’t fix the issue at all. Rough to have a security product demo be fundamentally insecure.
-
comment
Comment #36121417
I created/maintained a popular project for years[^1], and recently passed ownership to someone else. It's been great seeing issues resolve, PRs merge, etc, after languishing for a …
-
comment
Comment #29593356
The point is that with a powerful Effects system, devs calling the logger would have to account for the network call in their own code. Someone might have wondered why that was nee…
-
comment
Comment #29593300
Effects can definitely help, but a strong type system allows you to encode security concerns for compile time feedback as well. See https://gmb.is/refinement-types.html for a non-H…
-
comment
Comment #27429890
Given that he's now un-retweeted it, it looks like even amasad agreed it wasn't a good look.
-
comment
Comment #27429405
Based on your retweet[1], you still seem to be publicly punching down. [1]: https://twitter.com/pnegahdar/status/1402018604233732098?s=2...
- story
-
comment
Comment #25755016
You probably know this, but correcting for anyone reading. C is generally considered statically but *weakly* typed.
- comment
- story
- story
- story
-
comment
Comment #22894426
It’s versioned, which is an improvement on “agility”
-
comment
Comment #21477142
Yep, that’s the way!
-
comment
Comment #21476944
This class of bug (CSRF bypass via route confusion) is probably more common in Phoenix apps. I’ve found a handful of apps vulnerable to this issue with Sobelow. People create (for …
- story
- story
- story
-
comment
Comment #20286921
Sure, the "passive" was what I was calling out as incorrect. And as you noted, a compromised trusted CA affects all domains. Which is another thing this article gets explicitly wro…
-
comment
Comment #20286094
This is a horribly misinformed article, and is incorrect about the most fundamental arguments it is making. E.g. Among many other issues, it implies that a compromised CA would all…
- story
- story
-
comment
Comment #20233811
Agreed that you don't gain anything if you're using 1Password. But users may be required to set up MFA to access something like GitHub organizations, in which case having it availa…