HNHacker News
TopNewBestAskShowJobs

imnotjames

172 karma · joined June 26, 2018

[ my public key: https://keybase.io/imnotjames; my proof: https://keybase.io/imnotjames/sigs/QpNrcfxVTd5Png4grrtKHrCGdV1-O6r3zrkF1M3qCfI ]
submissionscomments
imnotjames··on KOReader
Booklore maintenance stopped a while ago. Grimmory maintenance continues. The original author of Booklore has seemingly moved on to a new project.
imnotjames··on Starship's Tenth Flight Test
They are extremely hydrophilic.
imnotjames··on Lowe's and Home Depot are sharing customer data with law enforcement
Aren't most overstaying their visa rather than improperly entering?
imnotjames··on Tj-actions/changed-files GitHub Action Compromised – used by over 23K repos
If you are using the action and were as of 10p ET last night I would assume everything is compromised, remove the action, and rotate secrets.
imnotjames··on Tj-actions/changed-files GitHub Action Compromised – used by over 23K repos
Your secrets will be published to the CI log if you were affected.

I believe it's everything since around 10pm ET last night. I would consider any runs in the past 24 hours to be suspect.

imnotjames··on Teen on Musk's DOGE team graduated from 'The Com'
Wouldn't normalizing transgender people through the arts help prevent crimes against said people that bud out of fear of the unknown?
imnotjames··on New Year's Security Incident
The Celery Organization on github had a security breach which has led to organizational activity halting. A number of contributions to the Celery project (apparently) have been reversed.

In case anyone is wondering where the next Celery release was.

imnotjames··on TikTok goes dark in the US
As far as I understand it, they wouldn't be able to advertise with US companies in the US so it's a lot of cost for no benefit. Unless they're hosting all that bandwidth for an altruistic reason..
imnotjames··on It's time to get back to our roots around free expression
There is no note on the first one.
imnotjames··on I automated my job application process
What happens when you get an interview and spend time for a company you don't want to work for?
imnotjames··on I automated my job application process
What do you suggest?
imnotjames··on I automated my job application process
I've run into the same thing.

We don't even have the job posted publicly anywhere and we get >100 submissions per day. Many are duplicates. I've found some that with some minor research turn out to be foreign organized crime. A large number of them had the exact same cover letter with changes in the names and past jobs.

Not only is it difficult to find candidates that actually fit the job role, it's hard to go through any that are even real people.

I've told many friends of mine to use connections and not online job postings because it's basically impossible right now with the automated resume submission companies.

And then the candidate management tools such as lever told me that no, every one of those candidates that applied were real people -- even when I provided proof that at least 40 of them were linked to a single organized crime group out of China.

imnotjames··on Grok is now free for all X users
Partially. He basically kept ignoring the board and lying to the board -- and that was one such case.

Another example was he decided that all of PayPal needed to be Windows computers so every engineer has to stop what they were doing and convert. Board said stop, he said okay, then continued.

imnotjames··on Mongo but on Postgres and with strong consistency benefits
Looks like it natches the mongo node API
imnotjames··on SpaceX starts booking places for space tourists to fly
I'm sure it'll happen like the dearmoon project when SpaceX had flown people around the moon in 2018
imnotjames··on Google wins reprieve from $32M verdict in Sonos patent fight
The biggest difference I saw because of the Sonos lawsuit was you couldn't change the volume of every device at once.
imnotjames··on Defining a new HTTP method: HTTP Search (2021)
This is why the RFC suggests you redirect to a GET like /resource/queryABCD
imnotjames··on Defining a new HTTP method: HTTP Search (2021)
Sure except POST has its own set of issues - like not being cachable. But SEARCH or QUERY can be cached safely!
imnotjames··on Firefox displayed a pop-up ad for Mozilla VPN over an unrelated page
Per https://support.mozilla.org/en-US/questions/1414266#answer-1...

> Thank you for reaching out with your concern. Firefox is committed to creating an online experience that puts people first, as such we quickly stopped running the ad experience, and are reviewing internally.

imnotjames··on Twitter Has Stopped Working in NetNewsWire
Who in their right mind would pay 44 billion for Twitter?
imnotjames··on Password Requirements: Myths and Madness
It's on NIST SP 800-63B 5.1.1.2[1]:

> Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.

[1]: https://pages.nist.gov/800-63-3/sp800-63b.html#memsecretver

imnotjames··on The Twitter Files, Part Six
In practice, yes. They did.

I have worked at another organization (hosted server provider) where I was in contact with the FBI and other law enforcement.

There's a world of difference between what was shown they did at twitter by noting things that were "worrisome" or against a reasonable site's ToS and forcing anyone to take things down.

I have told agents that certain materials were acceptable and that we would take no action. Not much they could do there without an actual warrant.

imnotjames··on Twitter applies 7-day suspension to half a dozen journalists
How is it illegal?
imnotjames··on The Twitter Files
You mean this?

https://www.theverge.com/2022/12/2/23490863/elon-musk-twitte...

imnotjames··on Why it is a bad idea for source control sites to ban crypto projects
I'm sorry, what? Controlled by the government "behind the curtains"?

You might want to take a step back and evaluate that thought process.

Private entities are not violating freedom of speech as a legal construct and as an issue of an ideological construct - isn't it violating the private entities freedom of speech when they're being forced to host speech they don't agree with?

If you're saying that you believe a shadow governnent is controlling twitter and that's why it's considered free speech - since it's a government entity in that case, uh, I don't really think that's plausible.

imnotjames··on Why it is a bad idea for source control sites to ban crypto projects
By banishment of free speech, you mean the right of a private entity to decline to host content that they seem to not be a fit with their ideals and brand?

I don't think this is a freedom of speech issue.

Instead, it's an issue that the private operators (codeberg & sourcehut) are looking to apply their own freedom of speech to take a stance against projects that have a high case of fraud.

You see the same thing from Stripe[1]: they ban similarity predatory systems from using their services & tarnishing their brand.

[1]: https://stripe.com/legal/restricted-businesses

imnotjames··on Launch HN: Medplum (YC S22) – Open-Source Firebase for Healthcare
It's so awesome to see the medplum team here!!

Medplum is a truly amazing solution to so many problems of building healthcare apps quickly. Before I had started chatting with the Medplum team it felt like an insurmountable task to experiment in the EHR area - the amount of infra & prep work we'd have to do made it so even for a proof of concept we'd have months before we could see anything useful.

It's really awesome to have so much of the hard part of handling health records done for us - and the depth of knowledge of the Medplum team is bar none when it comes to this area.

Y'all rock, congrats on the launch.

imnotjames··on Was everyone stupid back then?
Well, there was the time that the Krikkit decided to wage war on the entire universe for 2000 years - I believe the estimate was about two grillion casualties.
imnotjames··on Why JWTs Suck as Session Tokens (2017)
Assuming you mean express' cookie parser signed cookies? Or maybe rails?

Solves some of the session problems..

Benefits:

Cookies - when set to http only + secure only are safer?

Drawbacks:

They're not cross-compatible No expiration baked in No not-before baked in Limited to hmac validation (no public key crypto options that I know of)

Unless you mean using a JWT as a cookie value. I guess that could work?

imnotjames··on Why JWTs Suck as Session Tokens (2017)
I know a good spec for signing json data to store it as a token here, too
Page 1 of 2Next →