1,024 karma · joined March 26, 2019
- dang.matcha.life
- dang.moka.moe
One tea related and one coffee related, of course.
I'll aim to have them live by December 1st.
https://www.theverge.com/21300261/ios-14-update-smoke-alarm-...
Word and like jumps in Windows also felt backwards to me, doing the equivalent of w instead of e in vim, and couldn't be consistently combined with shift.
Support for Alt+Dpad(+Shift) and Command+Dpad(+Shift) is important IMO. As well as Double/Triple-click+Drag: it should select additional units not letters.
These last paragraphs are OS-level but the features were missing or inconsistent.
Highly recommend reading "On Tyranny", it's a great small, pertinent book for $10 at most book stores.
Edit: to be clear China's social credit system is extremely dystopian to me and is already taking shape, but I trust most/all democratic societies (including US) to fend it off.
Blocking tracking scripts does thwart fingerprinting. I really hope we can figure out a decent access model for JavaScript someday.
> Suppose a proposal was on the ballot next year to add a monthly fee to consumers' monthly electricity bill to combat climate change. If this proposal passes, it would cost your household $____ every month. Would you vote in favor of this monthly fee to combat climate change, or would you vote against this monthly fee?
$1/month: 57% favor
$10/month: 28% favor
$20/month: 30% favor
$40/month: 23% favor
$75/month: 15% favor
$100/month: 16% favor
A more useful question would be: "Would you oppose climate change regulations that had the effect of increasing your energy bills $10/month?"I can't recall the technical term for it though, and my search engine couldn't help me find it within a few minutes.
I adore the format and writing style too.
I'd pay $5/month.
It's reasonable to expect companies to honour their spec sheets, and to not lie in their firmware.
Once they're caught doing otherwise it's important to hold them accountable, not throw our hands up and pay up anyway.
The downside for the scheme is complexity and limited upside; complexity gets a lot more attention when it comes to security considerations.
Best practice especially needs to be simple; it's easy to mess this stuff up and hard to understand. A lot of the comments on this post betray a very poor understanding of password storage; they simply haven't come across the correct information.
Overall pepper is good as long as you include salt. There are times when the db gets leaked and the env variables don't.
There's nothing wrong with your scheme if it's implemented properly, but being able to change the site-wide key is a limited upside compared to using a pepper. There is an upside though.
And all of this doesn't matter much as long as you do the bare minimum of using a tuned pbkdf+salt and keep your stuff patched.
The SHA-family cryptographic hash functions are purposefully designed for throughput, if you combine them thousands of times like in PBKDF2 they can be fine. One round of SHA256 is trivial to brute-force especially with the plethora of ASICs available.
HMAC is also completely unnecessary here, and see the article title for your variable naming: it's not encrypted_pw it's hashed_pw.
FWIW there are ASICs now that will get orders of magnitude faster hash throughput than your servers.
HN eats the last period; you can use %2E to avoid that.
I try to only favourite the cream of the crop, in the hopes someone will stumble into my favourites list and enjoy them.
I mostly favourite comments not submissions though.