Live data from Hacker News

Viewing profile — rjst01

rjst01

HN member
Joined
Thu, Apr 09, 2015, 12:25 PM UTC
HN karma
328
Public activity
84 items

About rjst01

No profile information was provided.

Recent public activity

  1. comment
    Comment #44490727

    Are you able to share how you evaluated this? Is this based on gut-feeling or is it data-driven?

  2. comment
    Comment #44488725

    If you're involved in the hiring process at your org at all, and they ask these type of questions, I'd encourage you to try to as-objectively-as-possible evaluate how much of a sig…

  3. comment
    Comment #44434901

    Thanks for the suggestion. I'm on iOS but the notification settings look the same. I already had all but one of the settings you mentioned disabled, along with most of the others. …

  4. comment
    Comment #44426749

    Yes, but once that access is revoked, that is enough to be certain that the attacker can no longer issue certs. With your proposal, I would then have to audit my TXT records and de…

  5. comment
    Comment #44424587

    Of course - but that requires the owner to know they were attacked, know the attacker added a TXT verification, potentially overcome fear of deleting it breaking something unexpect…

  6. comment
    Comment #44421359

    > DNS auth would be okish if it was simply tied to a txt entry in the DNS and valid as long as the txt entry is there. Why does LetsEncrypt expire the cert while the acme DNS entry…

  7. comment
    Comment #44421008

    I think the parent commenter would be satisfied if they could authorize their DNS by creating a DNS challenge entry one time, and then continue to renew their certificate as long a…

  8. comment
    Comment #44415302

    I had to completely turn off notifications for Instagram because none of the provided settings appear to disable the almost-daily "for you" and "trending" notifications. Now I don'…

  9. comment
    Comment #44300205

    I was wondering exactly how hard factoring RSA-1024 would be today and found this stackexchange answer: https://crypto.stackexchange.com/a/111828 In summary, it estimates the cost …

  10. comment
    Comment #44296400

    > Encryption for 30 years ago? Trivially breakable with quantum I wouldn't be so sure - quantum computers aren't nearly as effective for symmetric algorithms as they are for pre-qu…

  11. comment
    Comment #44290697

    The headline here makes it sound (to me) like Salesforce did the study.

  12. comment
    Comment #44104633

    In practice, whether or not this actually works can be very hit-or-miss. We've found several UEFI implementations will not consider a disk bootable if the pMBR doesn't exactly matc…

  13. comment
    Comment #43139219

    Why? We are running the exact same images that we would be mirroring into and pulling from our private registry if we were doing that, pinned to the sha256sum.

  14. comment
    Comment #43128591

    It is a trade-off. For many services I would absolutely agree with you, but for hosting public open-source binaries, well, that really should just work, and there's value in keepin…

  15. comment
    Comment #43128298

    > Your case is simply prioritizing work that you would have wanted to complete anyway It's busy-work that provides no business benefit, but-for our supplier's problems. > specific …

  16. comment
    Comment #43128238

    Amazon ECR for instance provides the option to host a public registry.

  17. comment
    Comment #43127647

    Let me give you an alternative perspective. My startup pays Docker for their registry hosting services, for our private registry. However, some of our production machines are not s…

  18. comment
    Comment #43048083

    Yeah, I agree that's problematic. And I would have no objection to implementing a UI feature that displayed a warning banner of some kind if it detected that the page had been tran…

  19. comment
    Comment #43048071

    They probably understand it just fine. Someone higher-up has just over-ruled them. There may even be a good reason for it, but because of the way companies work, we will probably n…

  20. comment
    Comment #43047336

    Locale I'm using as a shorthand for "the bundle of variables that your service or business needs to tweak between customers in different markets". It may determine things like curr…

  21. comment
    Comment #43046482

    > When I first ran into this issue back in 2017, I posted in the React issue tracker that I had ”fixed” my app by blocking translation entirely. Please do not do this! In almost ev…

  22. comment
    Comment #42206113

    I was recently looking for an article I remember reading a bit over a year ago. I could even remember some exact phrases that appeared. I tried to find it on Google for more than 1…

  23. comment
    Comment #42204203

    One day I will give a lighting talk about the load bearing teapot, or how and why I made HTTP Status 418 a load bearing part of an internal API, and why it was the least bad option…

  24. comment
    Comment #41390723

    > I've had to do some ridiculous things to get them to behave after installing Linux, like tricking the BIOS to deal with UEFI correctly I would suggest going for a couple of gener…

  25. comment
    Comment #41301157

    This was actually shown off at CES earlier this year, here's the only video I can find: https://www.youtube.com/watch?v=GqCwLjhb4YY In this it's claimed that Intel is doing a direc…