Readit News logoReadit News
phonethrowaway commented on Show HN: A VNC viewer for eInk devices capable of 30 FPS when writing text   github.com/everydayanchov... · Posted by u/_8rlb
phonethrowaway · 4 years ago
I'm so excited for this: https://www.kickstarter.com/projects/bigme/bigme-worlds-firs...

Basic color support for syntax highlighting is what I've been waiting for...

phonethrowaway commented on Skip: A programming language to skip the things you have already computed   skiplang.com/... · Posted by u/bpierre
dapids · 4 years ago
It literally says 2022
phonethrowaway · 4 years ago
it doesn't say meta, duh
phonethrowaway commented on Bittersweet Symfony: Devs accidentally turn off CSRF protection in PHP framework   portswigger.net/daily-swi... · Posted by u/feross
BiteCode_dev · 4 years ago
A bit unrelated, but I find funny most frameworks don't even have something to prevent CSRF. Most devs don't even know what CSRF are, and some know it only as "the stuff I need to disable because some ajax POST won't work otherwise".

In fact, every time somebody choose flask over Django, I ask what they are going to do about CSRF, only to get a blank stare. Same with manual PHP or using most nodejs web libs.

There are so many websites that are vulnerable to this, and it's something we know well, and have solutions for. Imagine what we don't know about. The internet is really made of swiss cheese.

phonethrowaway · 4 years ago
flask-security is a trivial addon.
phonethrowaway commented on Is your Python code vulnerable to log injection? – Arie Bovenberg   dev.arie.bovenberg.net/bl... · Posted by u/rbanffy
phonethrowaway · 4 years ago
they don't even address shell escape injection which is definitely possible...
phonethrowaway commented on A Survey of Programmers' Cannabis Usage, Perception, and Motivation   arxiv.org/abs/2112.09365... · Posted by u/say_it_as_it_is
ok_dad · 4 years ago
I used to vape full spectrum THC+CBD cartridges and other forms of "vape juice" ("sugar", "oil", etc. are in that category) and consume THC+CBD edibles all day long, every day (except when I had to drive somewhere, I would stop for 4-6 hours or more prior to the trip), for about 2-3 (maybe 4?) years when I was in a legal state, but then I had to move to a non-legal state and since I have a kid it's no longer possible for me to use any weed (don't want to lose him to the system). I miss it so much, I was so much less stressed and calm with weed, and I was much more focused on work and I slept better. Now, I basically have to take shitty OTC sleep drugs and drink a pot (haha) of coffee a day in order to survive, and I yell way too much at my kid and get too angry at work. I wish we could just legalize it everywhere (fat chance of that happening) and make it like tobacco and alcohol, both of which are way worse for you than a daily weed habit.
phonethrowaway · 4 years ago
The farm bill made all hemp derived products legal federally at long as they contain only trace amounts of Delta 9 THC. Delta 8 and THC-O/acetate are legal. Not as strong, slightly different, but it gets the job done... kinda. Check it out... if you can. Check your state laws.
phonethrowaway commented on What’s the jankiest piece of tech you’ve seen a company depend on?   twitter.com/_brohrer_/sta... · Posted by u/fortran77
jamal-kumar · 4 years ago
I've seen some 1980s shit running THIS YEAR.

I'm working on porting a foxpro database from 1988 that's running an active business which I won't talk about much before it's done, and have actually encountered in Costa Rica an auto parts shop in one of the sketchiest parts of the capital city of this country with a green on black phosphor screen running what looked like dBase III for what they were doing on old IBM PCs.

It's pretty crazy what's out there still. I think the one everyone here is familiar with but might not know is really ancient is the travel booking systems for your plane tickets and accommodations, dating back to the 1960s:

Karsten Nohl - Where in the World Is Carmen Sandiego? (33c3) [1]

[1] https://www.youtube.com/watch?v=vjRkpQever4

phonethrowaway · 4 years ago
Old isn't janky... hmm... to me janky means duct tape and bubble gum.
phonethrowaway commented on Show HN: Play Zork with your friends via SSH   sayitwith.ink/boyd.html... · Posted by u/pheasantquiff
throwaway47292 · 4 years ago
Gentle reminder: when sshing into unknown places remember to check your forwarding and dont use your github/etc username.
phonethrowaway · 4 years ago
shell escapes are real attack vector too...
phonethrowaway commented on Log4j RCE Found   lunasec.io/docs/blog/log4... · Posted by u/usmannk
hawk_ · 4 years ago
While that's an interesting vector for attack, is it realistically an issue? Terminals are run as root all the time. I would guess any mainstream ones are well reviewed to not have such exploits work. Are you aware of any actual attacks exploiting terminal parsing in the wild?
phonethrowaway · 4 years ago
the point is it's a feature, not an exploit. control and escape codes are a thing for a reason.

it's worse with web stuff though... and it's a real vector.

https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=terminal+es...

https://packetstormsecurity.com/files/162518/AWS-CloudShell-...

https://nvd.nist.gov/vuln/detail/CVE-2017-0899

https://github.com/InfosecMatter/terminal-escape-injections

phonethrowaway commented on FBI's ability to legally access secure messaging app content and metadata [pdf]   propertyofthepeople.org/d... · Posted by u/sega_sai
freeflight · 4 years ago
Just like the NSA spying on Americans is unlawful [0] the FBI terrorizing political movements is unlawful [1] or the CIA operating in the US is unlawful [2]

Yet, I'm pretty sure all these are still happening, to a certain degree, to this day.

[0] https://www.reuters.com/article/us-usa-nsa-spying-idUSKBN25T...

[1] https://en.wikipedia.org/wiki/COINTELPRO

[2] https://en.wikipedia.org/wiki/Operation_CHAOS

phonethrowaway · 4 years ago
The NSA doesn't need to illegally spy on Americans when an ally can do it for them and then share the data legally.

https://www.nationalarchives.gov.uk/ukusa/

https://en.wikipedia.org/wiki/Five_Eyes

phonethrowaway commented on Missouri website that leaked SSN   web.archive.org/web/20210... · Posted by u/tantalor
frankosaurus · 4 years ago
phonethrowaway · 4 years ago
ASSESSEE NAME AND ADDRESS ARE NOT AVAILABLE ONLINE PER CA GOV CODE §6254.21

u/phonethrowaway

KarmaCake day94May 26, 2019View Original