@SheriefFYI Intel is undervalued stock wise I guess but I also think it's fair to be doomer on them because their board of directors is the most retarded in the industry and cucks the company at every turn
@SheriefFYI Or in the case of windows applications, there is no native look anymore every single app looks different. Even Microsoft's own apps have zero visual cohesion.
@SheriefFYI Your logic layer (IE: layout, reactivity) should be fully independent from your visuals, imho. Every device, even within the same brand (macos vs iPhone for example) all have their own stylistic quirks.
It's been like five years since this now and I still think it's really funny.
Tbf I hold nothing against Rake, I think the paranoia is justified when you're in the gamehacking space
But it's still the funniest ban I've ever received in any community ever.
I'm still laughing at how I got IP banned from guided hacking's site a few years ago now because I, and I'm not joking, had the audacity to visit their thread that talks about every ddos that hits them. Still probably the funniest way I've been banned from anything ever
@matiasgoldberg@SheriefFYI Genuinely one of the most irritating and downright idiotic issues I've ever encountered because our only solution was to base64 encode it which admittedly will save the data but that's just. So. Dumb. While we're saving a decent bit of storage still it just makes zero damn sense.
@matiasgoldberg@SheriefFYI Don't forget to test for ORM stupidity.
At work we were storing compressed text data for blog posts, and found out apparently DrizzleORM reads varbinary and blob back as strings for some reason. It'd write to the DB fine but come back mangled as it tries to encode it as utf8.
@SheriefFYI There's nothing problematic there off the top of my head. Most of the concern with rolling your own auth is how you handle authorization rather than authentication. It's pretty hard to make a password based flow insecure.
@SheriefFYI Splitting the salt and putting it half and half around the password
Adding a few junk discardable bytes to the salt in locations only the application knows
And also just running a rotating encryption key for it.
At work the auth solution we rolled has the salts in another db
@SheriefFYI Is the salt unique per user?
If so not that much. Knowing the salt makes it easier to crack but it's still extremely far from easy to brute force argon2id even knowing the salt.
Some people do obscure the salt though, a few techniques I've seen are (1/2)
@ThreatInteract@pointandcircle@SheriefFYI@EpicGames Their new interface can't even do dedicated servers, because for whatever reason to use the online services interface you must be considered running as a real player, which you aren't if you're running as dedicated. It'd be really funny if it weren't. So. Fucking. Irritating.
@ThreatInteract@pointandcircle@SheriefFYI@EpicGames Never said Unreal is competent. I've bashed them pretty extensively in the past. Their entire networking stack is a fucking embarrassment. Especially the newer Online Services Interface which is a genuine fucking nightmare that should never have been allowed free.