You speak of the first dot-com crash, but there was a lot of stupidness back then. One of my favorites is furniture.com http://www.ecommerce-digest.com/early-dot-com-failure-case-s...
12,245 karma · joined April 30, 2012
Reach me at <lastname><firstname> on gmail. First name has 3 letters.
You speak of the first dot-com crash, but there was a lot of stupidness back then. One of my favorites is furniture.com http://www.ecommerce-digest.com/early-dot-com-failure-case-s...
Then again, we didn't actually try raising it and face backlash. It's possible we were just too cowardly to try and fail.
And they are protected in your possession. If you turn over all your papers to a third-party, though, that changes things.
eta We may need more privileged communications, but they are very rare. Creating one is probably a good idea, but this will have to happen legislatively. Geek Squad finding child porn isn't much different from the photo processors of old finding it.
This guy did it to land a job. Hopefully he's done with spec-work like this and his new employer makes sure to negotiate rates ahead of time for security reviews.
Seriously, how do they get lock-in of riders or drivers? Installing a second app is a really really low bar. You can't do predatory pricing forever.
Lots of people are scared to use Uber/Lyft at first and need to be convinced to ride.
When you try to play things on the sly, it's your fault if some third party thinks you're a rat.
Susan Fowler's post has me pretty fed up with Uber, but for some reason greyballing doesn't bother me at all.
Is there a legal requirement to make it easy for cops to use your service? Are they a protected class?
If I didn't want to sell donuts to the cops, I sure wouldn't tell them it's because they are cops. I would just be mysteriously out of donuts every time they come in.
It's that there are so many different standards for installing software, overlapping in sometimes conflicting ways.
Holy cow, you've put into words what I've been thinking and practicing. Thank you.
If we were to hollow out an asteroid, would there still be a blob of intangible dark matter inside of it?
This is really a terminology question. I had a clear understanding of "length extension attacks" but it seems on this comment page people are using something else now. I've been looking over crypto.stackexchance and twitter to see if I missed the memo but this looks like a new usage.
The length extension attack leverages the weakness that people think HASH(secret + message) is a signature only they can create as long as only they know "secret".
(Edit: Any newly signed documents, or documents signed recently, are not safe, because an nasty person could have made two, one to get signed by the system, another to do evil with.)
SHA-1 is officially deprecated for certificates, because of the example that OP shows. You can create two certificates, have the decent one get signed by a CA, and then use the evil one to intercept traffic.
But I wasn't expecting that google's 110 GPU-year work meant that we could create colliding PDFs on demand.