Readit News logoReadit News
kevinyew commented on A modern approach to preventing CSRF in Go   alexedwards.net/blog/prev... · Posted by u/todsacerdoti
zwnow · 2 months ago
Also cant you just spoof the origin header?
kevinyew · 2 months ago
You can if you want to deliberately CORF yourself for some reason - it's there to protect you, but spoofing it doesn't give you any special access you wouldn't otherwise have.

The point is that arbitrary user's browsers out in the world won't spoof the Origin header, which is protecting them from CORF attacks.

kevinyew commented on Windows 3.1 saves Southwest Airlines during CrowdStrike outage   tomshardware.com/software... · Posted by u/smsm42
smsm42 · a year ago
> this is not the fault of Microsoft, Windows, etc.

Partially, it is. The expected lifetime of unprotected Windows machine connected to the Internet is in minutes, and I think there's some fault of Microsoft and Windows in that. And people want a solution to this problem, and when Crowdstrike offers one they take it. The reason "Windows + Crowdstrike" became so omnipresent is because "Windows without Crowdstrike" is too big a risk. It may be not a direct fault but certainly a contribution to the whole situation.

kevinyew · a year ago
Maybe it you're running Windows XP, but that is absolutely not true for a supported version of Windows. It is absolute FUD to say simply connecting a Windows 10/11 machine to the internet will cause it to be automatically infected.
kevinyew commented on CVE-2024-4367 – Arbitrary JavaScript execution in PDF.js   codeanlabs.com/blog/resea... · Posted by u/todsacerdoti
rough-sea · 2 years ago
kevinyew · 2 years ago
This doesn't make any sense, this vulnerability is in the context of browsers, not server side runtimes.
kevinyew commented on Reproducing the printer hack of Windows 95   dpolakovic.space/blogs/wi... · Posted by u/dpola
dpola · 2 years ago
With .net ported back to 95, one should get his security ready too.
kevinyew · 2 years ago
Love this reference, that MattKC video is so good.

For the uninitiated, I present this masterpiece: https://youtu.be/CTUMNtKQLl8

kevinyew commented on Show HN: I made a site that lets you punish yourself   punishme.app... · Posted by u/MarkVenison
kevinyew · 2 years ago
I didn't know Typeform offered payment processing, huh.
kevinyew commented on Show HN: Boardzilla, a framework for making web-based board games   boardzilla.io/... · Posted by u/joshbuddy
kevinyew · 2 years ago
Been enjoying playing a couple games of Seven Wonders Duel so far, but one immediate issue is that there is no way to unsubscribe from the emails telling me it's my turn. I've already got browser notifications turned on, so these emails are filling up my inbox fast.

I've also reported a couple bugs so far, the main one being not being able to build Wonders even though I have adequate resources, but other than that, amazing work! I'm keen to implement a game myself sometime soon.

kevinyew commented on Intel to drop the “I” moniker in upcoming CPU rebrand   boringtextreviews.com/202... · Posted by u/albert-thomas
iforgotpassword · 3 years ago
Yeah, that hard r was totally uncalled for.
kevinyew · 3 years ago
WAN show reference?
kevinyew commented on Kristall – a browser without support for CSS/JS/WASM or graphical websites   kristall.random-projects.... · Posted by u/tsujp
rollcat · 3 years ago
Distraction-free access to information. Like reading a book.
kevinyew · 3 years ago
There is nothing about HTML/CSS/JS that prevents simplicity. It is purely how it has been used and abused. You can also disable JS and use user agent stylesheets in any modern web browser.
kevinyew commented on Consider Disabling Browser Push Notifications on Family and Friends Devices   lloydatkinson.net/posts/2... · Posted by u/lloydatkinson
spiffytech · 3 years ago
BoardGameArena uses push notifications to let players know it's their turn.

I prefer running Slack in the browser, and I need to receive message notifications.

Push notifications aren't any less useful to have in browsers than in native apps.

Though I would like to see the prompt locked behind "add to home screen".

kevinyew · 3 years ago
Sadly, boardgame arena also pushes advertising for new games and features through the notifications as well. I'm sure it's possible to disable specific categories, but it unfortunately undermines their value even more when otherwise legitimate sites still somewhat abuse push notifications.

u/kevinyew

KarmaCake day223June 27, 2019View Original