Live data from Hacker News

Viewing profile — mdb31

mdb31

HN member
Joined
Sat, May 12, 2012, 3:00 PM UTC
HN karma
484
Public activity
108 items

About mdb31

No profile information was provided.

Recent public activity

  1. story
  2. comment
    Comment #31277022

    > There is no sync to provider servers on any TOTP implementation I use That's hard to dispute, but will you accept https://guide.duo.com/duo-restore as a counterexample? > Are you…

  3. comment
    Comment #31276948

    > Since when is TOTP obsolete? Since about the moment that teams all over the world discovered they could just paste the enrollment QR code (a.k.a. private key) into their wikis, a…

  4. comment
    Comment #31276385

    The TOTP "private key" can be easily cloned. Targeted malware, a database compromise at your app provider that you "securely" sync your settings to, or just a few minutes access to…

  5. comment
    Comment #31276290

    Yet, if you go into the "enable 2FA" settings on Github, you only get the option to enable insecure TOTP or SMS. Apparently, once you do that, you might be able to add proper authe…

  6. comment
    Comment #31276214

    Oh, that's lovely UX... "After you configure 2FA, using a time-based one-time password (TOTP) mobile app, or via text message, you can add a security key" So, after you enable a br…

  7. comment
    Comment #31276140

    I'm still confused. So, can you zoom any site on Safari on iOS or not? And if you can't, what definition of 'control' is that, again?

  8. comment
    Comment #31276109

    Well, given that Github today doesn't seem to support meaningful 2FA (only TOTP and SMS), wouldn't it be good to fix that issue before starting to talk about requirements like thes…

  9. comment
    Comment #31274947

    I've never experienced any zoom problems (as opposed to Zoom problems...), and I just had a look at all the sites mentioned in TFA. In all cases, I can zoom all elements (text, ima…

  10. comment
    Comment #31249127

    @john_cogs: Are there any plans to connect a self-assessment of mental state to the assignment of issues/pings about mentions/incident-response pages in the GitLab app? So, on "I'm…

  11. comment
    Comment #31249004

    Short-and-easy read that contains much truth. Especially item #10, "Lead by example" which encourages managerial review of recurring meetings (which often boil down to "well, here …

  12. comment
    Comment #31227234

    Well, the race to attract the outflow of the current Russian 'brain drain' is definitely on. If the US is able to attract the majority of that (as it most likely will), while keepi…

  13. comment
    Comment #31227065

    Well, I'm pretty sure you can't even directly sue over ownership of a .com domain? You have to submit to UDNP arbitrage first ( https://www.icann.org/resources/pages/help/dndr/udrp…

  14. comment
    Comment #31226955

    Nope, people communicate like that internally as well, because "that's what's professional " In some cases, you can fix this by asking the sender to be, like, normal. This works ha…

  15. comment
    Comment #31226832

    Nope, not a caricature. Read, for example https://www.atlassian.com/engineering/post-incident-review-a... This is held up as a great example of transparent communication. For me, t…

  16. comment
    Comment #31226736

    Ah, yes, the same kind of guide that brought us "how to professionally respond to outages"... With classics like "We recognize the incident", "a small subset of customers", "degrad…

  17. comment
    Comment #31225046

    > vector instructions are fundamentally necessary For which percentage of users? > AMD is actually adding AVX-512 Which is irrelevant to in-market support for that instruction set.…

  18. comment
    Comment #31224894

    Where do I say that the speedup is surprising? My question is whether Intel investing in AVX-512 is wise, given that: -Most existing code is not aware of AVX anyway; -Developers ar…

  19. comment
    Comment #31224787

    Cool performance enhancement, with an accompanying implementation in a real-world library ( https://github.com/lemire/despacer ). Still, what does it signal that vector extensions …

  20. story
  21. comment
    Comment #31180971

    I've hosted my own email since, at least 1993 (that's on the Internet: I was on UUCP at least some years prior to that). If you have a static IPv4 in a range that is not actively h…

  22. comment
    Comment #31180289

    Tired: exploiting antivirus software for those sw33t 0days. Wired: exploiting the gatekeeper of antivirus software quality for the lulz.

  23. story
  24. comment
    Comment #31180256

    This is actually very cool: a dataset of 3900 CVEs, with a matching fixing commit for 1359 of them. So, lots of opportunity to find a big payout w/r/t the unfixed CVEs. Whether suc…

  25. story