HNHacker News
TopNewBestAskShowJobs

moakakala

17 karma · joined May 27, 2013

submissionscomments
moakakala··on Show HN: BoundIt CAPTCHA: highlight objects in photos to prove you're human
I think the site/service is pretty slick and well-made. It worked well for me -- I'd be curious to see what kinds of boxes these people failing were drawing (or whether it's just a browser issue for them or something).

These comments are all pretty negative, and I think the criticisms are mostly valid, but I don't think you've made a bad product (though it may need some tweaking, and captchas may be on their way out now for the reasons others have posted).

I just know that I've felt awful before when receiving similar comments to these others, and I would have liked someone to remind me: you made something pretty good, and it wasn't a stupid idea.

moakakala··on Ask HN: How did you move from a salaried job to contracting?
You've advised "get a client" and "people will ask to hire you," but that only works if people are already aware of you. What if you are unknown? Where do you find these people people who will ask to hire you?
moakakala··on Join Wall Street. Save the world
I don't think he's planning to start a foundation, he's donating to existing ones, like the against malaria foundation.
moakakala··on Join Wall Street. Save the world
> If you want to save the world, save the world first. > Stop. Fucking. Waiting.

I don't understand what you're suggesting. Is Trigg (the programmer who joined Wall Street) "waiting"? What does "not waiting" look like?

moakakala··on My Teenage Son Does Not Know How To Mail A Letter
He probably also doesn't know how to use a sliderule or churn butter.
moakakala··on You are dangerously bad at cryptography
Is the risk any greater with APIs (like described in the article) compared to typical username/password login systems?
moakakala··on You are dangerously bad at cryptography
>Also, out of curiosity, in his timing attack example, the difference in time caused by the string being equal seems like it'd get absolutely swallowed up by the random nature of the universe - do those things actually work in the real world, on real servers with varying loads and numbers of users and network traffic?

You could make each request many times, and then average them together. I don't know how many requests you'd have to make to overcome the random fluctuations though -- probably a lot.

moakakala··on You are dangerously bad at cryptography
> This means that as long as you have one example of a signed message, you can forge signatures for that message plus any arbitrary request parameters you like and they will authenticate under the above described scheme.

If all requests are made over HTTPS, how could a third party intercept a signed message? How is this any greater of a risk than a third party intercepting user login information? (This is a serious question; I'm not being flippant or saying 'gotcha')