Viewing profile — nmgsd
nmgsd
HN member- Joined
- Mon, May 23, 2016, 9:34 PM UTC
- HN karma
- 38
- Public activity
- 43 items
- HN profile
- View on Hacker News ↗
About nmgsd
Recent public activity
-
comment
Comment #18784596
You can't forge a JWT without stealing the private key of the valid JWT signer. You can steal a JWT token the same way you can steal a session token.
-
comment
Comment #16756414
The issue becomes very difficult when you need to preserve message history reliably and allow account usage across devices. Because key management becomes tricky and clunky and the…
-
comment
Comment #14431321
I agree strongly with you that the direction to be taken is independent messaging clients for existing messaging channels as long as those channels allow third party API use. What …
-
comment
Comment #14376222
This highlights a major issue with ALL messaging apps, namely that the provider owns the clients AND the backend. Distributed open-source clients that use end-2-end encryption over…
-
comment
Comment #13982911
VPN people, VPN
-
comment
Comment #13878198
It depends what the API is supposed to do of course.
-
comment
Comment #13765459
A cool way to circumvent the keyword filtering: www.seecret.io
-
comment
Comment #13392232
This is why you should never trust proprietary secure messaging solutions that offer you both the client and the channel. The future of trusted secure messaging will be open source…
-
comment
Comment #12995457
of course he does.
-
comment
Comment #12988214
One option is to store the files in Amazon S3 and only serve them over cloudfront signed URLs. There's ways to lock down the S3 access so that only a few Very Important tech leader…
-
comment
Comment #12953890
You can always assume this.
-
story
Show HN: End-to-end encryption for Twitter direct messages
So, you want to avoid mass surveillance and don't trust big tech companies either? But you're tied to your existing network of contacts like everyone else? Well now you can send en…
-
story
Show HN: Hide your tweets in plain sight – Twitter steganography
We built a simple Twitter client that can post and read steganographic tweets at www.seecret.io using the plaintext steganography library from https://github.com/simpledynamics/see…
-
comment
Comment #12801330
From the article:"But take a closer look at that list and you can quickly see that all of these various behaviors could be described by one simple, everyday phrase: You're in troub…
-
comment
Comment #12800772
Are you perhaps thinking of JQuery UI? The core JQuery lib is still used. And for basic front end dev it really does offer most of the utility you'll look for in other libs. 1. Get…
-
comment
Comment #12715893
The App Store run by a central authority with complete control over what can even be available and the ability to modify the delivery at their own whim is certainly a big issue in …
-
comment
Comment #12690323
Most interview processes are a real disservice to the interviewee AND the company. Typically, the team manager will just have his team members all interview the candidate. They wil…
-
comment
Comment #12690135
This is 100% false. Can confirm.
-
comment
Comment #12687089
I have never once attended an all-hands meeting that couldn't have been an email instead.
-
comment
Comment #12687039
A lot of these answers are pointing out the x-browser complexity which is true but that isn't what drives JS package mgmt. It's mostly Node stuff. The mature common JS libs for bro…
-
comment
Comment #12681597
Let's hope they at least hashed their passwords correctly.
-
comment
Comment #12663090
-- "Open source software and decentralization is nice and all but to become a mobile app it'll have to be compiled and run on a closed platform and will almost certainly use APIs o…
-
comment
Comment #12661427
For high value targets yes, they can't really be safe but for avoiding mass surveillance it's good.
-
comment
Comment #12641330
can anyone confirm this is legit?
-
comment
Comment #12637210
Suprising to no one.