HN2new | past | comments | ask | show | jobs | submit | xxs's commentslogin

that doesn't help either. 'Salt' is public and usually different/unique per entry/name.

If you mean to use a "secret" prefix (i.e. pepper) then, that would generate effectively globally unique names each time (and unpredictable too) but you can't change the pepper and it's only a matter of time it'd leak.


Random pepper. Or just, y'know, randomly generate the effing string. Can't be that hard.

If they can't make the bucket before you do then they are not "bucket squatting", and they can't do so for a salted and hashed bucket name without knowing the salt at runtime.

The public/private distinction seems moot here, too: the salt is a throwaway since you just need the bucket name.

Even if you do need to keep track of the salt, it should be safe for the attacker to know, at least with respect to this attack, because you already own the bucket which the attacker would otherwise hoard.


>For every "20 min max" take home assignment, there will be people who are willing to spend 4+ hours doing it to outshine candidates who have jobs, families and lives.

The ones we use have a clear scoring system and prepared inputs - all it matters is the generated output.


If you cant do the sarcasm yourself (and be witty enough), it's just not fun or improved in any way. Use of corporate speak is sarcasms on its own right, of course - but it only makes sense if it's something your are exposed to (and people can relate), instead of being fake.

Also, if you have to mark the sarcasm, then it's proper bad.


Easier to read is mostly related with predictability of the text. Any time the brain mispredicts the next word, you'd have to go back and re-read.

Unless you are purposely train on that specific way to expression, it ain't easier to read.


I don't know why this is confusing. If I forget to put the "not" qualifier in a sentence, do we agree that it can confuse (or worse, mislead) the reader?

I never said - confusing. Just not easier to read as in relative term.

The edited version is an example of a sterile/canned response. No one talks like that.

While I do edit my comments to fix typos, certain spelling oddities and other peculiarities would be present.


8 points in 3 hours, that has to be some boost to reach the front page indeed.


In these case our only solution is to flag, right? Or is there any other way to report it?


run y-cruncher if you'd like to test memory and overall stability. It's decent test and a lot better than memtest (in my experience)

while true that month being 1st making little sense, the good format usually features leading zeros, so '22/07'


>lower the bar

the classic: "aim low, avoid disappointment"


The scan phase is proof of liveness. Photo is a still image.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: