HNHacker News
TopNewBestAskShowJobs

nathanmills

31 karma · joined January 5, 2025

ycombinator is a fraud
submissionscomments
nathanmills··on What Apple and Google are doing to push notifications
[flagged]
nathanmills··on What Apple and Google are doing to push notifications
Then why is it whenever I watch someone use their computer they always accept cookies?
nathanmills··on Stripe is friendly to “friendly fraud”
They're doing it because of a preceived result, not an actual result.
nathanmills··on Stripe is friendly to “friendly fraud”
Sounds like your projecting a bit.
nathanmills··on Dropbox CEO Drew Houston to step down
They seem pretty human to me.
nathanmills··on Stripe is friendly to “friendly fraud”
I don't see many people upset at Stripe over this, I certainly am not.
nathanmills··on Stripe is friendly to “friendly fraud”
No, vagueness gets me much more upset, but there's just nothing to write about in those cases.
nathanmills··on Why some children have iPad-induced rage
If you never give it back, then there can't be any more rage from turning it off.
nathanmills··on AI chatbots show bias toward Catholicism, researchers say
Bias is usually the result of something, yes, but it's still bias.
nathanmills··on AI chatbots show bias toward Catholicism, researchers say
Then what is it?
nathanmills··on Build Adafruit projects right from Firefox
You must be a child.
nathanmills··on Dropbox CEO Drew Houston to step down
Wow, that means 13 minutes ago must've been the first time they've ever used the site
nathanmills··on She can mentally time travel. Why did everyone think she was lying?
The fact we have no clue how it works or why it happens just proves that they are plain lying
nathanmills··on The user is visibly frustrated
Whenever I throw slurs at them they just refuse to respond
nathanmills··on She can mentally time travel. Why did everyone think she was lying?
Not actually possible though. Humans have constraints.
nathanmills··on She can mentally time travel. Why did everyone think she was lying?
Yeah buddy dude I read it. Thats just not possible.
nathanmills··on New Jersey judges rule man can't cash $59000 in gaming chips from defunct casino
He would've just gambled it all anyway.
nathanmills··on Migrating from Go to Rust
You are Evil.
nathanmills··on Build Adafruit projects right from Firefox
I don't remember that being there, maybe it was edited. But 2 buttons are not "aggressive". C'mon. Really dude? You believe that shit?
nathanmills··on Build Adafruit projects right from Firefox
WebUSB next? I would like to be able to configure my keyboard but it can only be done via their website which requires WebUSB.
nathanmills··on Build Adafruit projects right from Firefox
What makes it aggressive?
nathanmills··on New Rocket League is using Unreal Engine 6
Not pulled, just no new purchases on Steam. Existing owners like yourself can still use it and get updates: https://store.steampowered.com/app/252950/Rocket_League/

It works on Linux with Proton.

nathanmills··on JWT is a scam and your app doesn't need it
No, I will not send you malware. This scenario is about post-hacked where the malware is removed, but the attacker still has the cookies they collected. There should be a way to invalidate those cookies, just like how you can change your password if they got your password.

If you want, however, we can simulate the scenario. Find your JWT token, change your password (commonly invalidates tokens aswell), and then post it here post-invalidation. If it works still, then thats the issue. Though, changing your password commonly requires your current password and not just a cookie, so I wouldn't be able to do that. But I could probably change your username as proof. If it doesn't work, then it was checked against some revocation database that the article talks about, where at that point, where you have you check a database anyway, you might as well just store the session on the server, since the JWT is no longer stateless and provides no advantage over typical sessions.

nathanmills··on JWT is a scam and your app doesn't need it
Why would it require immediate action? Most chat services have a rate limit, stopping them at ANY point prevents it from spreading further. The messages don't get all sent at once, they will use the full access period to send as much as they can. Accounts can't typically be taken over with just a cookie, changing passwords normally requires you to confirm your current one. I hope you haven't designed any services where a cookie is enough to lock people out.
nathanmills··on JWT is a scam and your app doesn't need it
Geez, I need to re-sign in every time my mobile data switches IP?? IPs are NOT static. Mobile networks change IPs CONSTANTLY. What if I use a VPN (I do) and my IP changes constantly? What if an IOT device on your network is serving as a public residential proxy that anyone can use (more common than you may think), or hell, you have CGNAT and your neighbor does? What if an entire country only goes through one IP[1]? Have you done this in practice?

[1] https://en.wikipedia.org/wiki/User:82.148.97.69

nathanmills··on JWT is a scam and your app doesn't need it
Can you explain how 30 minutes of unauthorized access is safe enough for most use cases? I feel like you glossed over that.
nathanmills··on JWT is a scam and your app doesn't need it
No, it's called an example. I refuse to provide an example for every possible scenario, as that would not fit in the Hacker News comment limit.
nathanmills··on JWT is a scam and your app doesn't need it
Let's say a friend sends you an exe file, a game they made. You run it, and immediately realize it wasn't actually your friend. The attacker has stolen your JWT session cookie. The attacker hasn't done anything yet - they are configuring their browser cookies to match yours. You go to invalidate your session / change your password, but it doesn't help. The attacker has a full hour to do whatever they want on your account. They use it to send the same malicious exe from your account. If you would've been able to invalidate the session, you could've stopped it.
nathanmills··on JWT is a scam and your app doesn't need it
> I am tired of pretending JWT is fine.

I don't get it. Why were you lying to people??? Why were you pretending? Thats not healthy and pretty anti-social.

nathanmills··on Trump Mobile exposed customers' personal data
Was the /s needed?
Page 1 of 4Next →