What is Hackers' Pub?

Hackers' Pub is a place for software engineers to share their knowledge and experience with each other. It's also an ActivityPub-enabled social network, so you can follow your favorite hackers in the fediverse and get their latest posts in your feed.

0
0
0
0

> “한국 복지제도가 복지 대상의 직접 신청이 있어야만 혜택을 받는 ‘신청주의’를 기반으로 하고 있어서 문제” “지금은 부모가 적극적으로 나서야만 자녀가 혜택을 받을 수 있는 구조인데, 정부 부처별로 쪼개진 전달체계를 국가 차원에서 마련해야 한다”

“몰라서 지원 못 받아”…발달장애 부모연대가 ‘일타강사’로
출처 : 한겨레 | 네이버 naver.me/GRuhV6CX

0
0
0
0
0
0
0
0
0
1

Amazon search results are so, so, broken.

E.g. search for "electric skateboard", get pages of relevant results. Sort that search by average customer review, and get page after page of junk results, with actual electric skateboards finally turning up at page 6.

I assume what's going on here is that Amazon wants people only to buy from their chosen products, and so has intentionally broken all other sort options.

0

Good morning! ☕

Now that I can't find any other bugs in any more, I'm thinking again about how I could improve it.

Would anyone consider deploying it on a busy site right now? Either as a replacement for (proof-of-work against bots), or for simple non-federated , or maybe even both?

I'm currently not sure how well it would scale. The reason is the design with server-side sessions, which is simple and very light-weight "on the wire", but needs server-side RAM for each and every client. It's hard to guess how this would turn out on very busy sites.

So, I'm thinking about moving to a stateless design. The obvious technical choice for that would be to issue a signed (Json Web Token), just like Anubis does it as well. This would have a few consequences though:

* OpenSSL/LibreSSL would be a hard build dependency. Right now, it's only needed if the proof-of-work checker and/or TLS support is enabled.
* You'd need an X509 certificate in any case to operate swad, even without TLS, just for signing the JWTs.
* My current CSRF-protection would stop working (it's based on random tokens stored in the session). Probably not THAT bad, the login itself doesn't need it at all, and once logged in, the only action swad supports is logout, which then COULD be spoofed, but that's more an annoyance than a security threat... 🤔
* I would *still* need some server-side RAM for each and every client to implement the rate-limits for failed logins. At least, that's not as much RAM as currently.

Any thoughts? Should I work on going (almost) "stateless"?

0
0
0
0
3
0
0
0

My 25 years of palaeoart chronology...

Here's my 2023 illustration of some Morrison Formation sauropods, from DINOSAUR BEHAVIOUR, by Prof Michael Benton (published by Princeton University Press). It features , , and ; plus two and a skeleton.

0
0
0
0
0

創作をする人自身は障害者のこと考えなくていいよ、という声を身近な人から聞いたことあって結構衝撃だったな。その時はきちんと議論する勇気は出なかった・・・

0
1
0
0
0

垂死病中驚坐起,四邊包繩不打洞
停杯投箸不能食,四邊包繩不打洞

踏破鐵鞋無覓處,四邊包繩不打洞
人生得意須盡歡,四邊包繩不打洞

少年不識愁滋味,四邊包繩不打洞

0
0

四邊包繩不打洞創作大賽開始了

剛想到兩句:
躺著領錢又舔共,四邊包繩不打洞。
藍白問政普攏拱,四邊包繩不打洞。

"普攏拱"我不知道台語正字要怎麼寫 :dogsad:

0

이준석 개혁신당(..) 후보가 내세우는 정부효율화 운운, AI로 일러스트 던지다가 어설픈 오류 발생, 남초온라인 공간 구미에 맞추기만 하되 사회갈등에 대한 전체적 인식력 낮음, 능력주의 신화 몰입하며 자신 띄우기 등. 이건 미국 일론 머스크의 테크-극우 정치를 걍 열화복제한 느낌. 아직 머스크와 달리 본격 나치즘의 길로 들어서지만 않았을 뿐.

0
5
0
0
0
0

My 25 years of palaeoart chronology...

Here's my 2023 illustration of some Morrison Formation sauropods, from DINOSAUR BEHAVIOUR, by Prof Michael Benton (published by Princeton University Press). It features , , and ; plus two and a skeleton.

0
0

When I shop for laptops, I don't care much about battery life. My minimum requirement is 3 hours or a little more than that (~3:30) with the throughput-performance setting, because my brain doesn't go much longer than that in one sitting either. Seems that people who want 8–10 hours of battery life can concentrate for that long without losing their attention. Wow!

0
0
0
0

권영국 후보의 성별인정법이 된다면... 어차피 성별인정법 차별금지법이 생겨도 내가 트랜스라는게 알려지면 지금회사에서 짤릴거임.. 법적 대응을 할 수 있게 된 것이 달라지는 점이겠지만 여튼 성별인정법이 생긴다면 나는 더 빨리 새로운 삶의 기반을 만들어 법적 성별정정을 하고, 안정이 되었을 때 수술을 받을 수 있을것.

0
0
0
0
0
0
1
1