Live data from Hacker News

Viewing profile — tshadwell

tshadwell

HN member
Joined
Tue, Apr 17, 2012, 3:56 PM UTC
HN karma
798
Public activity
195 items

About tshadwell

Infosec @Twitch twitter.com/zemnmez

I can be contacted at my gmail: thomas.shadwell

Recent public activity

  1. comment
    Comment #15713023

    this is an article about the UK.

  2. comment
    Comment #14353381

    'we've taught this robot to move small uniform blocks and we're going to make it perform arbitrary complex tasks on a variety of objects' sounds a lot like 'i'm trying to draw the …

  3. comment
  4. comment
    Comment #14204378

    from experience, I wouldn't recommend other than context-aware safe templating systems for html safety in this day and age. to an even greater extent than templating systems, sanit…

  5. comment
    Comment #14181435

    So in order to use a function that exposes the software to serious undue security risk unless used correctly, the engineer is pushed to do research? That really doesn't seem like a…

  6. comment
    Comment #12328600

    in a similar vein, I often close browsers with ^W, expecting to delete a word. Thanks Vim.

  7. story
  8. comment
    Comment #12111055

    Really cool product presented beautifully. But perhaps from being a security engineer, I wish it would say anything at all about how they're going to ensure a 16 year old kid can't…

  9. comment
    Comment #12105236

    See also: https://github.com/shockone/black-screen

  10. comment
    Comment #12100902

    I tried to enjoy ingress, but didn't and I enjoy pokemon go. Obviously the Pokémon brand is a draw, but ingress felt like a platform for a game that people had to construct. I got …

  11. comment
    Comment #11792491

    That's an amazingly regressive point of view. Sure, in the past such things risked prosecution but why exactly does it mean we have to figuratively knock stones together on vulnera…

  12. comment
    Comment #11790671

    What are you proposing to replace cookies with? Auth tokens and XHR? Localstorage? Why?

  13. comment
    Comment #11790056

    The primary problem this hopes to solve is actually CSRF. Simply generating an HTML form for a website for any website and submitting it sends the cookies of the target website, re…

  14. comment
    Comment #11731121

    I might look into this. People are always surprised by how long it takes for me to notice them in a crowd

  15. comment
    Comment #11730794

    I have a really excellent visual imagination. I can imagine myself walking or driving great distances, and I can imagine all the scenery, the trees, the colour of the sky. I can pu…

  16. comment
    Comment #11663212

    See also: https://github.com/StackExchange/blackbox "blackbox by StackExchange"

  17. comment
    Comment #11653453

    > I'm sure threat modelling is something everybody does implicitly. You may work somewhere that this is the case, but I can't count the number of times I have tested an application…

  18. comment
    Comment #11653405

    This aricle falls foul of what I might call 'security shopping'-- passing mentions of lots of brightly coloured complex sounding security things with very little regard to what exa…

  19. story
  20. comment
    Comment #11427179

    I think it's super important to understand that removing the preflight request practically kills the security measures of CORS. With no preflight request, the browser has no idea w…

  21. comment
    Comment #11393468

    Some notes: 1) Never blacklist. Seriously, unless you are in the business of writing and securing browser parsers, you are never going to catch everything. There are many vectors n…

  22. comment
    Comment #11354010

    What area of 'cybersecurity' would I be finding myself breaking substitution ciphers based on wingdings in? I work in the information security industry, and I feel like I'm missing…

  23. comment
    Comment #11269775

    All understood, and you're right, but the tone of this article and that of its kin is at least equally bad at idea discussion -- it's not weighing out positives and negatives or tr…

  24. comment
    Comment #11269374

    > How to make it reusable? ` I can understand arguments for generics, but they're complaining about trying to warm a whole pizza with a toaster. You need to put individual slices i…

  25. comment
    Comment #11134179

    So I typed my name and clicked one of my repos and I have a small green butterfly model to view at low resolution, and I can read the description I can read on github. If I click o…