That vacation is not eligible for pay out if I resigned.
333 karma · joined June 13, 2021
That vacation is not eligible for pay out if I resigned.
Usually one article a month. The content is driven for what I feel strongly about in the moment, be it cryptography or managing teams to tech-social issues.
While not malicious, this has been shown to be possible by 1Password. See https://www.future.1password.com/passkeys/ and I have confirmed it is possible to modify this function.
JavaScript can be monkey patched, in some ways this is great for polyfills. For other cases this can be a threat.
If browsers had an explicit mechanism to register extension provided Authenticators and locked down a way to modify the original navigator credentials interface, then we may be able to protect the "first" bytes that come back from the authenticator to the application.
Here’s what I was sent.
> Hope you're doing well.
> We're a tightly-knit team of full-stack developers and we need someone who can help us with client communications. Most of our developers are not native English speakers and we often face communication issues. That's why we need someone who's based in the U.S and has technical background.
> The main responsibility will be taking job interviews on our behalf. You should be able to join the meetings under someone else's name.
> This is an hourly engagement and the rate is $40 ~ $80 / hr depending on your experience.
> Please kindly reply to this email if you're interested.
I do not think it is well known among application developers, which is why I wrote this post. In fact, my base64 implementation elsewhere is vulnerable to this and it never occurred to me.
Thank you for the rust library recommendation, I was using base64ct.