Readit News logoReadit News
pitay commented on JEdit – Programmer's Text Editor   jedit.org/... · Posted by u/Tomte
slavapestov · 4 years ago
I started working on jEdit when I was 14 and developed it for 6 years or so. While I haven’t used it in a very long time I’m humbled to see that it is still being maintained and has users.
pitay · 4 years ago
This reminds me of BlueJ. Does anyone remember BlueJ with its auto generated class diagrams?
pitay commented on Show HN: WildCard, a retro Hypercard/HyperTalk simulator   hypervariety.com/WildCard... · Posted by u/hyperhello
gcanyon · 4 years ago
This is awesome! I'm trying it on an iPad and doing pretty well.

For anyone looking for a deeper experience, you can try https://livecode.com/ -- runs on Mac, windows and Linux, produces single-file executables, and has many enhancements over HyperCard while retaining many oF HC's strengths.

pitay · 4 years ago
https://news.ycombinator.com/item?id=26062977

I posted the linked comment almost a year ago, but the incident happened much closer at the start of Covid. I didn't say it at the time, but I willingly say it now, LiveCode were the perpetrators. They employ the dark pattern of graciously offering free stuff for education during lockdown, because they are such good guys, and then will charge $1500 if someone forgets to cancel their offer. After the dashes is copy of the text from the other comment:

--------

I treat 'free but remember to cancel' plans as scams.

About 10 months ago I got emails from a company that developed an development environment that was I was mildly interested in. They presented an offer with said it was free so that people could help educate themselves during lockdown. Unfortunately the terms was after 1 year you needed to pay something like $1500 if you didn't cancel, these terms were right at the bottom of the page and very hard to spot. Paid through PayPal and the about $1500 was there right in front of me. I cancelled it on the same day.

A company offering that sort of deal waiting for people not to cancel and saying it is to help people during the lockdowns is just awful.

---------

Addenda: Unfortunately I don't have the original email for this any more, as I was annoyed and marked it as spam before copying any text like an idiot, and it vanished. Although I may be able to use the internet archive to recover the page the email sent me to. Aside: if anyone doesn't copy the text they wrote in a webpage to a text editor or something before they press the 'submit' button or equivalent, they may regret as I have a couple of times, if an AI or site error swallows their text, it's a good habit to get into.

pitay commented on PHP is worth learning and using   bulletproofphp.dev/yes-ph... · Posted by u/omegavesko
gbba · 4 years ago
Be careful as this syntax can potentially introduce SQL injections.

PHP's parameterization features in PDO can be abstracted so you can turn this into:

  $vars = array(":userid" => $userid);
  q("select name from users where id = :userid", $vars);
It's still pretty concise and is much safer.

pitay · 4 years ago
Parameterized queries and statements are great. They solve problems where the paramaterized queries are used. However care must be taken, a script running on the database after information has been entered can still inject long after the initial parameterized statement put it into the database if that script itself does not use parameterized queries, making a SQL injection still work, in a delayed way.
pitay commented on Dangerous bug in Chrome’s ‘New Tab’ page bypassed security features   portswigger.net/daily-swi... · Posted by u/PaulHoule
eyeundersand · 4 years ago
Is this not a one-time thing that's shown after every update? Or is it recurring?
pitay · 4 years ago
It was one time for me. Although I do think what they advertised there and the way they advertised it was nonsensical and disrespectful to the user.
pitay commented on Dangerous bug in Chrome’s ‘New Tab’ page bypassed security features   portswigger.net/daily-swi... · Posted by u/PaulHoule
ldng · 4 years ago
Recently they also changed the urlbar to do a search when you type anything... even localhost. INFURIATING. To stay polite. Messed with about:config but did not find a way to disable that crap.

So Chrome and FF are in the same boat: "UX" "designer" taking non-sensical decisions for the whimsical greater good.

pitay · 4 years ago
I do not have this issue, but I have a very customized about settings.

Here is the relevant about:config settings I have these changed for the URL bar:

  browser.urlbar.suggest.searches false
  browser.urlbar.searchSuggestionsChoice false 
  browser.urlbar.showSearchSuggestionsFirst false
Also for your urlbar you want to change it so it always shows the scheme and every part of the URL.

  browser.urlbar.trimURLs false
Stop Firefox trying to help with incomplete urls and loading the wrong site:

  browser.fixup.alternate.enabled false
Setting the above about:config entries should stop URLS you type being sent to a search engine and also stop some other surprises in the URL bar.

pitay commented on I hate password rules   schneier.com/blog/archive... · Posted by u/CapitalistCartr
matheusmoreira · 4 years ago
Yeah, my bank does that too. Asks for my birthday for "security" reasons. They also kill their website's usability by forbidding physical keyboards and forcing users to use a virtual keyboard with randomized key layouts in order to type passwords in a feeble attempt to defeat keyloggers. Some banks even make it extra annoying by generating ambiguous keys like "1 or 7" or "2 or 3".

The saddest thing is banks can't be too secure. If they were, then they would be too hard for normal people to use and they would get locked out of their funds.

pitay · 4 years ago
My bank used to have a virtual keypad, they now have a normal password field. So they actually saw reason. I think there is reason to be optimistic about bank password security getting better; what is known to be good password policies and interfaces are getting more widespread. It may take some time, but it should get better because it is accidental or ignorant password policies from the past, not deliberate attempts to make their customers trip up (unless someone knows better).

As for the asking birthday for security reasons, relic from the past, getting more useless as time goes by. With so many websites asking for that information, and then they get hacked, sold or leaked. Yes, this said the completely obvious, but it still amazes me that any organisation that I have a financial relationship with asks that for identification over the phone, usually my address as well, but that is almost as public.

pitay commented on Making the dislike count private across YouTube   support.google.com/youtub... · Posted by u/minimaxir
mikeyjk · 4 years ago
This makes me think of how steam does indeed have some smarts to warn users when a game may be getting review brigaded. I think it's a combination of volume of reviews by time, and perhaps the referrer (?). It does seem to work fairly well afaict.
pitay · 4 years ago
Steam also allows a user to view the raw information if they want. At least the last time I looked. The option could definitely be more obvious though. Giving the user the ability to see the like/dislike data over time gives them their own ability to decide whether likes/dislikes come from an external source to the page. This information should include a graph of the total views over time as well as likes and dislikes over time in parallel.

Not giving users this information and removing like dislike counts just makes it so that a small number of people at YouTube have even more ability to control what is pushed on that site. With this change users have even less ability to check the validity of a video; validity means different things to different users here. People who stay at YouTube will just have to deal with the fact that they will have videos pushed to their screen for reasons that are hidden to them, that they don't have the ability to check out anything other people think about the video, and can't even signal that there is something wrong to them about the video (sure, they could comment, but any comment can be deleted by the video author and there is the fear of losing your Google account, which can include their email contact to everyone and authentication information also, which can have huge consequences for their ordinary life).

pitay commented on Windows 11 upgrade tool that bypasses Microsoft´s requirements   github.com/coofcookie/Win... · Posted by u/donutloop
josteink · 4 years ago
> Remember, you run Linux on modern hardware only because Microsoft allows you to.

Factually wrong.

Any regular PC owner can run Linux on modern x86 hardware in at least three ways:

- Legacy BIOS MBR boot

- UEFI boot

- UEFI secure boot

Only the last one of those three options requires a signed shim, and only if you don’t enrol your own keys.

> Microsoft signed the Red Hat shim, and if you disabled Secure Boot, it's only because a Microsoft policy gave you the ability to disable it -- a policy they can later reverse.

This FUS has been repeated the last 10 years+ and it gets less convincing every year.

No OEM or PC vendor wants to limit their amount of potential in what is already a cut-margin business.

Taking away the ability to disable secure boot or taking away the legacy BIOS boot option will only cost them customers, and they literally have nothing to gain.

pitay · 4 years ago
Microsoft could just not give discounts to computer suppliers that don't have UEFI secure boot on forced on.

I definitely recall Microsoft killing hardware manufacturers putting Linux on the machines that they sold by mandating that if they put Linux on any consumer desktop they would not get the OEM discount for a Windows licence for any computer they sold. It stopped new non Windows PC sales dead at the time IIRC. This was something like over a decade ago.

pitay commented on Never update anything   blog.kronis.dev/articles/... · Posted by u/cesarb
jart · 4 years ago
Looking at Google Trends for GNOME,KDE,LXDE,XFCE from 2004 to present is interesting. https://trends.google.com/trends/explore?date=all&geo=US&q=%... Back then GNOME and KDE stood head and shoulders over all alternatives, whereas these last twelve months, all the Linux desktop choices appear more or less in the same league. Open source sort of behaves the opposite way as markets where instead of shakeout we get shakein.
pitay · 4 years ago
Interestingly just removing the US location restriction it looks quite different, with KDE being far more frequently searched for than the others at the moment. Searches for Linux desktop environments look to have reduced a lot in total since 2004, on Google at least. https://trends.google.com/trends/explore?date=all&q=%2Fm%2F0...
pitay commented on Should a dog's sniff be enough to convict a person for murder?   science.org/content/artic... · Posted by u/pseudolus
FpUser · 4 years ago
Well, not really. After reading about some cases I've long lost any trust I may have had in the system. It might be ok in general (do not have enough real stats) but when it comes to fucking up particular person's life without any consequences the government / their institutions shine.
pitay · 4 years ago
Yeah the lack of consequences for those that administer justice is (I believe) the strongest reason an innocent person is convicted or punished far too harshly for the given crime. The only time I have heard of judges ever getting punished for their judgments is either when it is revealed that they have been taking bribes or their nation lost a war.

u/pitay

KarmaCake day282June 5, 2013View Original