Hacker Newsnew | past | comments | ask | show | jobs | submit | makr17's commentslogin

I remember being in Tel Aviv for work, and pulling up maps to plot out a bike route from the hotel to the office. Only to find that the entire route is blurred out online. Turns out our office was a few 100 meters from something important to the IDF, so no map/route data available. Too far to reasonably walk, and didn't want to try a bike without knowing there was a reasonable route...


This does remind me of driving on the western edge of the Dead Sea in 2014 with my family. The only device we had that was capable of 3G-less navigation was my Nokia Lumia 620 (windows phone) with bing maps. I had maps downloaded for all of Israel and Palestine, but they refused to work at that particular spot. Still not sure if it was some kind of GPS/map blocking or just being at a really low altitude. Pretty sure that once we passed Jericho and turned towards Jerusalem, it started working again.


I suspect a lot of software does not behave well at negative altitude. I heard of an ECU having trouble on one of the rare negative altitude roads.


Why would a road or route be blocked from OpenStreetMaps? That doesn't really provide any security if the area is public.


In what way do you mean “public”?


Not parent poster, but I'd describe a commute road as "very public".


My question still stands. What does “public” mean here?


It means people walk by, take photos and post it on Instagram 500 times per day.

You can also refer to Merriam Webster.

You'll need to clarify what your question means for more detail than that.


Stupid question: Did you rent the bike? You nerd sniped me here! How did you have a bike on a work trip? That sounds fun.


Afaik Tel Aviv has city wide bike share, so guessing that's what OP was using.


Cool, I was not aware. I found the website here: https://metrofun.co.il/


Did something like the android 'osmand' app with offline openstreetmap data for .IL downloaded function?


I still remember being "invited" to a meet-and-greet with the VP of Tech at my college after a fork bomb run amok. 17yo me was sure my academic career was at an end. He let me sweat for a few of minutes and then smiled and offered me a job. <whew>


That's a good sysadmin. They are few and far between.


I'm working on something similar. My biggest annoyance is that the overly-helpful LLM was making every die roll succeed. I ended up building some tooling around rolling dice. Also some tooling around character stats and inventory management, so those don't get lost in context compression.


Presumably stack depth and overflow.


I used to work somewhere that did that. Several of us in Eng pointed out that it was likely impossible to sell anything to DoD personnel since the reply would route internally. But I don't know if it was _fixed_, was still an issue when I left.


I remember in jazz class the instructor had a stack of jingles that showcased particular "weird" intervals. The only one I really remember now is the "Alway Coca Cola" jingle and a M6, but this was a _long_ time ago.


Yes! "My Bonnie Lies Over the Ocean" is another popular one for demonstrating a major 6th.

Side note but I'd love to see a nicely printed stack of physical cards with popular melodic hooks/jingles, the demonstrated intervals, notation, etc.


In the sitcom Mad About You there is an episode where Jamie tells Paul to put on a tie. Specifies the "navy blue one". "I don't own a navy tie." "Yes you do, it's the one that you think is dark green."

My wife and I go round and round about what is and isn't blue and/or green.


I have had similar conversations with my wife a few times, but I'm the one with working color vision.


But navy blue is just dark blue


Yeah that scene doesn't make any sense. A dark teal that could be confused between blue or green would look nothing like navy blue.


Coming up on 20 years ago I was building a system that was going to be deployed at various locations throughout a very large country. All locations had internet access; but the throughput, latency, and quality (e.g. packet drops) were all over the map.

For testing we ended up building a small linux box to proxy for the test environment in the office. We could throttle the throughput to any arbitrary level, introduce latency, and introduce packet drops. It's amazing how poorly a frontend will work when you throttle the network to 128kbps, and introduce a small percentage of dropped packets. But once you get the system to work (for some definition of "work") under those conditions you feel pretty good about deploying it.


California has a low-double-digit percentage of the US population, and mandates organic waste separation/collection.

https://calrecycle.ca.gov/Organics/SLCP/collection/


Years ago I worked for a company that bought another company. Our QA folks were asked to give their site a once-over. What they found is still the butt of jokes in my circle of friends/former coworkers.

* account ids are numeric, and incrementing

* included in the URL after login, e.g. ?account=123456

* no authentication on requests after login

So anybody moderately curious can just increment to account_id=123457 to access another account. And then try 123458. And then enumerate the space to see if there is anything interesting... :face-palm: :cold-sweat:


I did some work ~15 years ago for a consulting company. The company pushes their own custom opensource cms into most projects - built on top of mongodb and written by the ceo. He’s a lovely guy, and good coder. But he’s totally self taught at programming and he has blind spots a mile wide. And he hates having his blind spots pointed out. He came back from a react conference once thinking the react team invented functional programming.

A friend at the company started poking around in the CMS. Turns out the login system worked by giving the user a cookie with the mongodb document id for the user they’re logged in as. Not signed or anything. Just the document id in plain text. Document IDs are (or at least were) mostly sequential, so you could just enumerate document IDs in your cookie to log in as anyone.

The ceo told us it wasn’t actually a security vulnerability. Then insisted we didn’t need to assign a CVE or tell any of our customers and users. He didn’t want to fix the code. Then when pushed he wanted to slip a fix into the next version under the cover of night and not tell anyone. Preferably hidden in a big commit with lots of other stuff.

It’s become a joke between us too. He gives self taught programmers a bad rep. These days whenever I hear a product was architected by someone who’s self taught, I always check how the login system works. It’s often enlightening.


Being self-taught isn't the problem. I've self-taught myself 10x more than I learned in school (and yes I was CS in school).


I'm self taught and have worked on several auth systems... I've seen plenty of bad ones from professional programmers with Masters degrees. So it definitely can go both ways.

I've also have spent 10-15 hours a week beyond work assignments on reading/experimenting, etc. in terms of honing my craft/skills over the course of three decades. Most devs don't do that much consistently in general though.


A person who is like that is rarely called a "lovely person": how does that lovely interaction look like when you point such an egregious flaw out to them?

And tbh, this has nothing to do with being self-taught: by the time I enrolled in CS program, I was arguably self-taught and could spot issues like this myself. But I pride myself in learning from my mistakes and learning fast.

So it's more likely a character thing: if you are willing to admit when you are wrong, you'll learn much faster!


You might as well make them sequential if they're numeric, making them non-sequential just puts more load on your server when the brute force happens.


Agreed, the lack of per request auth, and a single exposed record as a raw cookie for auth are pretty egregious.

I did once have a system that started with a incremental sequence was 17, then the number was passed through a reversible obfuscation to get a 6+ character output ID... it wasn't that bad, was an inspection record for a vehicle entry... meant to be able to be shared and looked up by anyone with the sequence (semi-public), it was desired to be short, and it just moved the guess-ability factor slightly.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: