Viewing profile — tshadwell
tshadwell
HN member- Joined
- Tue, Apr 17, 2012, 3:56 PM UTC
- HN karma
- 798
- Public activity
- 195 items
- HN profile
- View on Hacker News ↗
About tshadwell
I can be contacted at my gmail: thomas.shadwell
Recent public activity
-
comment
Comment #15713023
this is an article about the UK.
-
comment
Comment #14353381
'we've taught this robot to move small uniform blocks and we're going to make it perform arbitrary complex tasks on a variety of objects' sounds a lot like 'i'm trying to draw the …
- comment
-
comment
Comment #14204378
from experience, I wouldn't recommend other than context-aware safe templating systems for html safety in this day and age. to an even greater extent than templating systems, sanit…
-
comment
Comment #14181435
So in order to use a function that exposes the software to serious undue security risk unless used correctly, the engineer is pushed to do research? That really doesn't seem like a…
-
comment
Comment #12328600
in a similar vein, I often close browsers with ^W, expecting to delete a word. Thanks Vim.
- story
-
comment
Comment #12111055
Really cool product presented beautifully. But perhaps from being a security engineer, I wish it would say anything at all about how they're going to ensure a 16 year old kid can't…
-
comment
Comment #12105236
See also: https://github.com/shockone/black-screen
-
comment
Comment #12100902
I tried to enjoy ingress, but didn't and I enjoy pokemon go. Obviously the Pokémon brand is a draw, but ingress felt like a platform for a game that people had to construct. I got …
-
comment
Comment #11792491
That's an amazingly regressive point of view. Sure, in the past such things risked prosecution but why exactly does it mean we have to figuratively knock stones together on vulnera…
-
comment
Comment #11790671
What are you proposing to replace cookies with? Auth tokens and XHR? Localstorage? Why?
-
comment
Comment #11790056
The primary problem this hopes to solve is actually CSRF. Simply generating an HTML form for a website for any website and submitting it sends the cookies of the target website, re…
-
comment
Comment #11731121
I might look into this. People are always surprised by how long it takes for me to notice them in a crowd
-
comment
Comment #11730794
I have a really excellent visual imagination. I can imagine myself walking or driving great distances, and I can imagine all the scenery, the trees, the colour of the sky. I can pu…
-
comment
Comment #11663212
See also: https://github.com/StackExchange/blackbox "blackbox by StackExchange"
-
comment
Comment #11653453
> I'm sure threat modelling is something everybody does implicitly. You may work somewhere that this is the case, but I can't count the number of times I have tested an application…
-
comment
Comment #11653405
This aricle falls foul of what I might call 'security shopping'-- passing mentions of lots of brightly coloured complex sounding security things with very little regard to what exa…
- story
-
comment
Comment #11427179
I think it's super important to understand that removing the preflight request practically kills the security measures of CORS. With no preflight request, the browser has no idea w…
-
comment
Comment #11393468
Some notes: 1) Never blacklist. Seriously, unless you are in the business of writing and securing browser parsers, you are never going to catch everything. There are many vectors n…
-
comment
Comment #11354010
What area of 'cybersecurity' would I be finding myself breaking substitution ciphers based on wingdings in? I work in the information security industry, and I feel like I'm missing…
-
comment
Comment #11269775
All understood, and you're right, but the tone of this article and that of its kin is at least equally bad at idea discussion -- it's not weighing out positives and negatives or tr…
-
comment
Comment #11269374
> How to make it reusable? ` I can understand arguments for generics, but they're complaining about trying to warm a whole pizza with a toaster. You need to put individual slices i…
-
comment
Comment #11134179
So I typed my name and clicked one of my repos and I have a small green butterfly model to view at low resolution, and I can read the description I can read on github. If I click o…