997 karma · joined October 30, 2015
There's also another important detail. Due to delayed ACKs on Windows and battery-preserving TCP stacks on most mobile devices/laptops, some of your packets will be delayed. Even with TCP_NODELAY. Desktop OSX/Linux do not display this behavior.
The only solution I have found, and it's a rather crude one, is to blast the server every 50ms with a 1-byte packet. It is ugly but it works well.
Might I ask what OS/Browser/ISP are you using?
I remember donating back in the day!
A lot of trial and error.
I use 2 WS connections mirroring some packets on both, to deal with head-of-line blocking.
I don't have a BT KB so I didn't test that case. Will do!
I would like to see native ECC support and a more stringent validation mode that allows more than 3 months of certificate lifetime.
Temporal dithering. Also called FRC - frame rate control.
You might not notice it, but if you are on a TN monitor right now (almost all non-professional monitors) this technique is being used to emulate 24 bit color. Most TN panels can only display 6 bits per channel.
Some kind of torque vectoring deal in the rear wheels? Like the Electric AMG SLS.
v8 6.2 fixes a lot of Turbofan related regressions, for example: for in object performance [1]
[1] https://medium.com/the-node-js-collection/get-ready-a-new-v8...
This could easily be fixed by adding a -!> operator that disables implicit returns, but no, they are so opinionated that a change like that will ruin their perfect little universe. I know that there are forks that add this sort of functionality among fixing some of my other gripes with CS but my point still stands: I'm not going to invest my time into a cult.
I get 15 ms better ping to Frankfurt Linode compared to Vultr, for example.
I don't want fucking software I paid for to make my PC a part of a botnet, so I deleted all their stuff and tried to cancel my subscription to CC. I couldn't do that because their terms allow them to charge your credit card for the remainder of the year, even if you receive no service. After a few angry emails with a supervisor they finally agreed to cancel my subscription.
What a shady POS company.
Same goes for SHA-224 and SHA-384.
[1] https://en.wikipedia.org/wiki/Length_extension_attack
Edit: yes, looks like it is.
As sp332 and JoachimSchipper mentioned, the novelty here is that it contains specially crafted code in order to conditionally display either picture based on previous data (the diff). I can't grok PDF so I still can't find the condition though. Can PDFs reference byte offsets? This is really clever.
Edit #2: I misunderstood the original Google attack. This is just an extension of it.
Creating a file with the same hash as legit file is a preimage attack and is much more difficult to perform (many orders of magnitude more difficult).
This still doesn't mean that SHA-1 isn't dogshit however. It should have been phased out years ago.
If the file is corrupted at the edge server an SRI attribute [1] can detect it, although it's not supported on IE and Safari yet.
[1] https://developer.mozilla.org/en-US/docs/Web/Security/Subres...