Hacker Newsnew | past | comments | ask | show | jobs | submit | gertburger's commentslogin

Over 90% of english capable internet users use the metric system so maybe it should be the primary unit system...


My understanding is that they use the IP range assigned for CGNAT as their private address range to avoid conflicts, but do they use CGNAT?


For the oauth login it requires the following permissions: View basic information about your account, Manage your data in Google Reader, View your email address Manage your contacts, View and manage your Google Contacts, Perform these operations when I'm not using the application

Why would it want access to view AND MANAGE my contacts? This seems a bit odd.


I understand your concern ... see my response here:

https://news.ycombinator.com/item?id=5373701

Short answer, we don't want access to manage your contacts, there's just not a read-only option (last time I checked).


If only...


I had to google 'revieled' ;P


Memcache is designed to be run on a trusted network and only accessed by trusted clients. Therefore sharing a memcache daemon in its current state is not recommended at all.

See http://www.slideshare.net/sensepost/cache-on-delivery on what can be done with a publicly accessible memcache daemon.


Many sites also use memcache to cache page fragments that will be sent verbatim to clients with the rest of the webpage.

As Marco demonstrated in his slides one can easily inject into caches and if one can change the values of keys related to page fragments then it is a major security risk.


South Africa


Johannesburg, in my case.


Typo in domain that is in title.


oops, thanks!


Since the Guidelines/FAQ has nothing on this specifically and it might be useful to one(Maybe more) HN readers I believe you should post a "We are hiring" thread.

Especially if no one gives any good reasons why not to in this thread.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: