Hacker News new | past | comments | ask | show | jobs | submit | jasonyan's comments login

Looks like someone already wrote a post about it: https://blog.filippo.io/komodia-superfish-ssl-validation-is-...


We actually already do that with our API version of the plugin. We're currently working on a new plugin which should deprecate our old JavaScript version.


Done :)


Hey can you publish the source code of the search tool?


wow, that was quick:-)


I can play songs with Opera 9.5 build 9665 on Windows.


Awesome site guys! You also just reminded me about the new ATAL EP that came out yesterday.


Thanks, Jason. We love Disqus.


Affects Django users with 'USE_I18N' set to True and the LocaleMiddleware activated. Fix prevents a potential DoS attack from a malformed HTTP request.


All the recommendations Amazon is showing me are from things I was looking at years ago.


I noticed the indexer broke sometime last week, but I had been too busy to debug the issue. I'll try to take a look at it sometime tonight.


Thanks!


I guess it's a good thing there's no authentication on that site.


Any domain cookies for .bigheadlabs.com are vulnerable, which could be a real problem (Wordpress admin maybe?).

Domains are so cheap now that I almost always buy one for every project (even hacks) these days, partially just to isolate potential XSS issues.

I didn't mean to imply anything disparaging towards you, this kind of annoying stuff pops up even at Google. It's so easy to miss a spot, especially on quick hacks.

Thanks for creating that site, it's an awesome contribution.


The nice thing about these web frameworks is that it makes rapid prototyping easy, and in doing so, it does things which may seem "magical". I would recommend that one should gain a certain level of understanding of what's going on behind the scenes. In doing so, it won't be as "magical" after all.


'... would recommend that one should gain a certain level of understanding of what's going on behind the scenes ...'

The upside of this is you work less & do things faster because there is a lot of functionality pre-built. Solutions become a lot simpler because you are utilising more of the framework, less custom code leaving more time to solve the real problems.


Not to mention, less custom code = less bugs. Although I can only speak for RoR, most of these frameworks have probably done a good share of testing.


That's a great perspective.


Consider applying for YC's W25 batch! Applications are open till Nov 12.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: