December 2021

Ask HN: How did my LastPass master password get leaked?
612 by gregsadetsky | 326 comments on Hacker News.
Hi, I've just had a bizarre thing happen and wanted to see if the HN community could come up with some theories as to what happened. LastPass blocked a login attempt from Brazil (it wasn't me). According to an email I received from LastPass, this login was using the LastPass account's master password. The email doesn't look like it's a phishing attempt. What troubles me is that the master password was stored in a local encrypted KeePassX file. I can imagine that someone has my KeePassX file and the (completely different) password to this file. If that's the case, I'm in a world of hurt. But are there any other possibilities? Is the email from LastPass accurate i.e. was the login attempt actually using my master password? Is there some LastPass extension installed on some computer still having a valid auth token allowing them to login as me to LastPass..? I'm really confused, and scared. Thanks for your help. P.S. The LastPass account had 2FA set up, but I was able to simply remove it (since I didn't have access to the token anymore). That's scary too -- what's the point of a 2FA you can remove...?? --- Update: - the email was truly not phishing -- the same information regarding the login attempt appears in my LastPass dashboard. I also talked to LastPass support over the phone, and they confirmed seeing the same information. - There are 2 separate users in the thread below confirming that the same exact same thing happened to them, from the exact same IP range as me. Either the 3 of us had the same malware/Chrome extension or somehow had our master passwords compromised...? Or...? Is this a LastPass issue?

25-Dec. Shout-out to everyone else at work
565 by sandworm101 | 120 comments on Hacker News.
I made a similar post last year at this time and, again, I am in my office on Christmas morning. There are a few days every year that really show which jobs are vital and which can be left aside for a day. I started my car this morning (-32, -40 with wind chill). On my way to work I drove past a hospital and a care home, both were manned. The dairy farm had its lights on. A cop with his flashers drove past me on the way to some emergency. The macdonalds drive-through was open too. I had to be at work by 0600, but I was relieving someone who had been sitting in another office since 1800. On my computer were the same dozen emails I get every morning, each from someone else who drew the short straw. There aren't many of us on HN that work weekends let alone Christmas morning, but If you too are sitting in a dark office remember that all across the world are millions of other people working the truly important jobs.

Ask HN: Are most of us developers lying about how much work we do?
680 by ConfessionTime | 466 comments on Hacker News.
I have been working as a software developer for almost two decades. I have received multiple promotions. I make decent money, 3x - 4x my area's median salary, so I live a comfortable life. I have never been fired or unemployed for more than a few months total over my entire career. Through most of that time I have averaged roughly 5 - 10 hours of actual work a week. I'm not even discounting job related but non-coding time as not work. There are literally days in which the only time I spend on my job is the few minutes it takes to attend the morning stand-up. Then I successfully bullshit my way through our next stand-up to hide my lack of production. No one has ever called me out on this and my performance reviews range from mediocre to great. I'm generally a smart person. I went to a top 30 university, but it's not like I'm a genius or I'm coasting off connections made while getting a Harvard education. I wouldn't consider myself an abnormally talented developer. I often don't understand the technical details other engineers discuss in meetings. I have probably bombed more tech interviews than I have passed. All my jobs have been between 2-5 years so I'm neither finding a place to stagnate or leaving before anyone could judge my production. It feels like I am in the middle of the bell curve in terms of career success. So what gives? Are most of us secretly lying about how much we are working? Do people regularly run into coworkers like me during their career and simply ignore it because they find it too awkward to criticize them? Have I just been incredibly lucky and every boss I have had is too incompetent to notice? Do I have imposter syndrome and I am actually a 10x developer whose laziness makes them a 1x developer? These questions have kept popping up in my mind over the last year. Remote work during the pandemic has allowed me to finally be honest with myself and stop pretending I am working when I am not. I want to know if I was the only one pretending.

Ask HN: Best Way to Contact YouTube
466 by S_A_P | 135 comments on Hacker News.
I woke up this morning to an email from YouTube stating that my channel is banned for repeated violations. They didn’t specify what I violated but it could be anything from copyright to hate speech. Let me explain the content of all 5 videos on my 11 year + old channel. 1) a video of a squirrel that carried half a loaf of French bread along a fence and jumped into a tree. He dropped the bread during the jump but somehow managed to one hand/paw catch the bread and save it. 2) a friend of mine who was unable to ride a spring horse on a playground. 3)my son reacting to a scene from the movie hot rod(cool beans) this was a private video. 4) music video of my own music. No samples or other copyrighted material contained. 5) another music video also with no copyrighted material. I submitted a request to the YouTube forum but I suspect that is a black hole where support requests go to die. I’m not really all that upset and I have all the videos that are on the channel locally but the 1 strike you are banned seems awfully extreme. The fact that I wasn’t told that something was flagged or given any sort of heads up is really what bothers me. How can I get YouTubes attention?

YouTube suspended my account for posting DeFi hackathon video
582 by thijser | 349 comments on Hacker News.
I knew Google's automated processes were pretty bad from earlier stories here, but today I got hit by it myself. I participated in the totally legit EthGlobal "Hack Money" hackathon ( https://ift.tt/3c6VSHN ) earlier this year and one of required submissions of that event was a video describing your work. I made one and uploaded it to Youtube. The hackathon went great and we won some prizes but that's not relevant to this story. Yesterday evening I received an email from Youtube that they've removed my channel because "Spam, scams or commercially deceptive content are not allowed on YouTube.". I thought this certainly must be an error so I used the attached appeal link and got a response within less than 15 minutes that they appeal has been rejected and that no further replies will be processed. I am a paid Youtube Music subscriber and I can't login to even listen to my own music anymore. Amazing. I would like to think that Google's AI systems are smarter than just videoTitle.contains("hack") && videoTitle.contains("money"), but apparently not. If anybody has connections who can help get me unsuspended that would be highly appreciated. The google cache of my channel is still available here: https://ift.tt/3ouRFad...

Ask HN: What are these low quality “code snippet” sites?
561 by endofreach | 309 comments on Hacker News.
Whenever i am trying to google a code issue i have, there is countless low quality sites just showing SO threads with no added value whatsoever. It is so annoying it actually drives me mad. Does anyone know what's up with that? I am really disappointed because the guys creating these sites (i guess for some kind of monetization) must have some relation to coding. But i feel this is an attack against all of us. Every programmer should be grateful for the opportunity to find good quality content quickly. Now my search results are flooded with copy & paste from SO. They are killing that. Am I the only one experiencing this or being that annoyed by it? P.S: I don't name URLs because if you don't know what I am talking about already, you probably don't have that issue.

MKRdezign

Contact Form

Name

Email *

Message *

Powered by Blogger.
Javascript DisablePlease Enable Javascript To See All Widget