Live data from Hacker News

If you’re trying to hack/deface a website, don’t submit a pull request

github.com

111–114 of 114 posts

Re: If you’re trying to hack/deface a website, don’t submit a pull request

#111
post #110

Earlier quoted context omitted.

Because it works even if you can't find a proper codepath to exploit. It might gain you anything you want: A quiet path to leak admin account info to a server of your choice. An attack vector into a system trusted by more than one person. You don't need to provide much information to get a github account, so the risk is not very much elevated.

or better yet, write some code in the same way like this coding contest (where you write some innocent looking code that contains a subtle bug that you can plausibly deny it was intentional... http://underhanded.xcott.com/?page_id=7 ). This way, the blame trail isn't useful in proving anything!

Thats the ticket!

Re: If you’re trying to hack/deface a website, don’t submit a pull request

#112

Earlier quoted context omitted.

I assumed that was because of changes in Skitch. Everyone I know used to take screenshots with Skitch, upload them and Skitch would copy the URL into your clipboard and you could post into Github. But since Evernote bought them they closed things down and they're basically useless now, so I figured that was why Github was motivated to add this feature.

I know that so much. Skitch is so crippled now. It was my favorite fast and simple "here let me point it out and show you" tool for everything. I annotated everything with it. With evernote killing the ease of "let me show" half, whats the point of annotating things and taking screen shots? If there was ever an opportunity for a disruptive simple startup idea it would be to replicate what skitch did before evernote b…

I agree, and apparently so do the developers because they still have a download link to the old Skitch on their site: http://evernote.com/skitch/

Re: If you’re trying to hack/deface a website, don’t submit a pull request

#113
post #109
post #99

Earlier quoted context omitted.

You can still download the old version (the real skitch) right there from evernote: http://evernote.com/skitch/ (small link at the bottom, "previous version"). Skitch supports FTP-upload, so if they turn off sharing in the future you can just switch to your own webspace. No need to mess with lesser tools (or the evernote-garbage) while Skitch still works!

yep this is what i did. But free FTP services online are hard-ish to come by =( i wish there is a plugin or kernel extension that modified skitch so that you could upload it to say dropbox. The other method is to point skitch to the local machine and use dropbox to sync, but i think you lose the clipboard thingy. May be i will just switch to monosnap. But it looks so ugly compared to skitch!

You are right, free was an euphemism. However, you could use a cheap webhoster, those can be had for as low as $0.50/mo and usually come with FTP.

I'm definitely sticking with skitch as long as it works and until a suitable replacement appears.

Re: If you’re trying to hack/deface a website, don’t submit a pull request

#114

Earlier quoted context omitted.

I assumed that was because of changes in Skitch. Everyone I know used to take screenshots with Skitch, upload them and Skitch would copy the URL into your clipboard and you could post into Github. But since Evernote bought them they closed things down and they're basically useless now, so I figured that was why Github was motivated to add this feature.

I know that so much. Skitch is so crippled now. It was my favorite fast and simple "here let me point it out and show you" tool for everything. I annotated everything with it. With evernote killing the ease of "let me show" half, whats the point of annotating things and taking screen shots? If there was ever an opportunity for a disruptive simple startup idea it would be to replicate what skitch did before evernote b…

I've still been using the old version of Skitch, but without the instant upload and copy to clipboard it was a lot less useful.

Then I found these this week:

Skitch to S3 upload (through webdav) — http://brad.me/skitchs3

Skitch to CloudApp upload — http://brad.me/skitchcloud

If you are a CloudApp user (http://getcloudapp.com/) the second one is super slick. Pretty much duplicates the old Skitch functionality and returns a short URL that you can use to post. You can also use a custom domain with CloudApp if you use the paid service.

Totally made Skitch useful again.

Post reply on HN