315 karma · joined July 6, 2012
I know Wikipedia isn't exactly a great primary source here, but:
> From 2002 to 2009 there were many defect petitions made to the NHTSA regarding unintended acceleration in Toyota and Lexus vehicles, but many of them were determined to be caused by pedal misapplication, and the NHTSA noted that there was no statistical significance showing that Toyota vehicles had more SUA incidents than other manufacturers.
— https://en.wikipedia.org/wiki/Sudden_unintended_acceleration...
In any case, I believe companies can definitely be guilty of criminal negligence (and Toyota did a lot of bad things during their SUA crisis). But I think the use of SUA in the comment I originally responded to sort of misrepresents the situation and mostly spreads a lot of FUD around self-driving cars.
[0]: https://www.engadget.com/2013/07/28/auto-hacked-ford-toyota-...
That is, many other brands of cars had been reported to have the same issues by drivers. And basically a driver was put into a stressful situation, thought they were hitting the brakes, but were actually hitting the gas. Then, panicking that they can't stop the car, hit the "brakes" harder, exacerbating the problem.
Requests against endpoints like this are going to be unauthenticated, since by their very nature they happen before the user is actually authenticated against the system. So you can burn through a few thousand (or hundred thousand) possibles and find out which ones actually have accounts.
From there, you can use one of many other email/password dumps and try authenticating. Hitting an endpoint where you can use an email and password is (hopefully) going to be much more guarded and will start blocking IPs when the rate or variance is too high.
That being said, I don't really know how you can stop the first step. There are plenty of answers here that say you should just let them "sign up" and then send them an email if they already have an account. But what happens if your signup process includes something like accepting payment? Obviously you don't want the user filling out all of that information again.
It made the mobile experience pretty bad (all I get are links to the gists) and it would definitely "pollute" my gist history with a lot of little code snippets.
On the note of the topic itself, though, this was a fun read for building fractals in JavaScript!
Also, if you have more than one commit before you noticed you were on the wrong branch, this only grabs the one commit.
* open issues to address
* review state, such as "changes requested" or "approved" (along with users that are in each state).
We've been using Phabricator's[1] Differential tool for code reviews and it feels superior to this process, but it would certainly be nice to have an all-encompassing solution for this.
Unfortunately "let the user decide" is not the best answer if you want to link to something like "terms and conditions" in the middle of a sign up flow or something. If the user doesn't know how to open it in a new tab on their own, this can be extremely frustrating I'd imagine.
EDIT: Looks like I posted without reading all of the comments in regards to the class name thing. I see some other people have mentioned it as well. It also looks like the author states that this isn't a hard requirement. I guess that would solve that problem at least.
On the other hand, the fact that it would fail at all would help you see that you have a bug. Something you might not have caught before.
I don't know that I would ever use it, but I like the novel concept of it. If this was just a for-fun kind of project, I'd think it was pretty awesome. If you're trying to market it as a business, you're going to run into all the problems everyone else has already mentioned.
But yeah, I definitely remember seeing this in the past. Feels slightly like a case of http://xkcd.com/1053/, though?
And I don't see anything in the guidelines about re-posts. (https://news.ycombinator.com/newsguidelines.html) You've got more HN experience than me, though, so I could very easily be wrong. :)
I'm also not too fond of anything that would cause people to work later in the evening. The one problem I see this potentially fixing is the feeling of forgetting everything you did over the weekend.
I've found that many problems, even software problems, can be solved in a completely dark, quiet room. At the very least, it helps reduce stress levels and allows you to try to tackle the problem again when you get back with a fresh mind.
To be fair, I'm not sure how secure YoAuth would be, but this particular hack seems like an awesome use of it. It's simple to use and could compete alongside something like Google Authenticator as a simple way to log in to something.