Hacker Newsnew | past | comments | ask | show | jobs | submit | Shorel's commentslogin

For my own agent one of the design constraints is that it can't get out of the work directory, and it can't even try to guess the full path of that directory. Interesting that VSC has gone the other way entirely.

There's a category in the OWASP Top 6, called: Insecure Design.

It is top 6 in their vulnerabilities ranking.

This is definitely insecure design.


It's because it means they can't fix it themselves. The actual reason is their acquired helplessness, compared to previous generations.

I have a wallabag setup for my interesting bookmarks, and it downloads and indexes the contents of these bookmarks. I read the contents later in a PocketBook, free of distractions from the normal devices. It is a bit of setup work, but just totally frictionless after it was setup. Firefox also has Pocket, which I used before switching to wallabag.

How does wallabag know about your bookmarks? Or do you mean that you're using a wallabag extension for firefox?

I'm using a wallabag extension in every browser. Also using a wallabag app on Android. And also a wallabag app on PocketBook.

It's a very fun tic tac toe!

(I have not reached single digit kyu)


Don't let yourself get too comfy with 9x9! I stayed on it for too long. No way to know but I feel like it added 2 years to the time it took to get there

Not all all. It merely indicates that this is an strict logic approach to the topic.

https://commonplacefacts.com/2022/07/27/principia-mathematic...


What part of GP's one-sentence explanation is not strictly logical? Does obfuscating a simple logical concept by describing it in academia-wanky-terms like Liskov's Substitution Principle make it More Logical? Or does it just make the author and their in-crowd feel more intelligent?

Note, also, that the article isn't even objective. It asserts that the definition of a subtype is Liskov's principle. However, Liskov's principle is only one of multiple possible definitions. In other words, the article is really only invoking Liskov's name as an appeal to authority. So much for strict logic.


intelligence is overrated

If the article is written for human consumption, then it fails the primary goal (or logic?) of being useful. If a human has to digest a flood of this logic slop just to get convinced about this simple concept, they are not going to be able to do anything useful.

No D-lang? It seems quite incomplete without it.

For me passkeys work wonderfully synced in Bitwarden on Windows, Linux, and Android. I have no idea what this article trying to say, except some negative opinion that should IMO be ignored.

The article was clear and reflects my own opinions:

If you use an untrusted machine, you either revert to the least secure backup method (your master password in Bitwarden) or don't log in.

If your phone is your trusted device and becomes lost/stolen and then replaced, you revert to the least secure backup method e.g. password, security questions, or even waiting to be manually verified. This can be problematic if your online bank requires 2FA so you can purchase the replacement phone.

The QR + Bluetooth thing sounds dumb as hell.

Kiwi Browser doesn't support passkeys even with Bitwarden on my device. I have to choose between an inferior (for my needs) browser or passkeys.

-----

Rather than passkeys, which always rely on a trusted device, my preference is, "I use a password manager and site-specific generated passwords, and when I try to log in with only a password on your site, send me an email (whether pass or fail), plus never require 2FA except for banking and perhaps to change email/password"

It's unlikely I'll lose access to email notifications at the same time someone tries logging in with a phished password (except, obviously, my email password, which should only be changeable with 2FA) unless I am specifically physically targeted or astonishingly unlucky.

If someone uses a fake website or other MITM method to grab my credentials, I'll be fine because I'll get the "hey PennRobotics you logged in to crabcakes.com just now from a iPhone" message and then immediately triage that unexpected situation.

If I need to log in to a website in private mode or on a different device, it takes an extra 30 seconds to log in to my password manager plus no device dependency.

-----

The passkey problem for me? You need some hardware or else it's glorified 2FA or even (in the case of the Paypal app) 1FA applied twice, and as soon as you lose EITHER the hardware or the "what you are/what you have" part of 2FA you enter a world of trouble.

Also, ToS lockouts happen. When Google terminates your account (for any variety of imaginative or realistic reasons) there isn't really any method to use or export your passkeys anymore.


No guarantee at all that a new exploit will be found, and even much lower probability that a suitable lead developer will be found. The slop kiddy was just an asshole TBH.

That's because they destroyed the market for native windows programming by pushing so heavily on .NET.

Also, everyone else using web platforms (Electron ugh...) for what should be desktop applications.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: