<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: chavesn</title><link>https://news.ycombinator.com/user?id=chavesn</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 09 Apr 2026 09:40:41 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=chavesn" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by chavesn in "Google’s OAuth login doesn’t protect against purchasing a failed startup domain"]]></title><description><![CDATA[
<p>Right, and how would you further verify “the person paying for your subscription”?</p>
]]></description><pubDate>Tue, 14 Jan 2025 21:20:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=42704031</link><dc:creator>chavesn</dc:creator><comments>https://news.ycombinator.com/item?id=42704031</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42704031</guid></item><item><title><![CDATA[New comment by chavesn in "Google’s OAuth login doesn’t protect against purchasing a failed startup domain"]]></title><description><![CDATA[
<p>Genuine question, what would that flow look like?</p>
]]></description><pubDate>Tue, 14 Jan 2025 20:39:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=42703519</link><dc:creator>chavesn</dc:creator><comments>https://news.ycombinator.com/item?id=42703519</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42703519</guid></item><item><title><![CDATA[New comment by chavesn in "Google’s OAuth login doesn’t protect against purchasing a failed startup domain"]]></title><description><![CDATA[
<p>>  all of those cases very well justify a manual check, or some sort of extended identification before the user is let in.<p>Just curious, what would that check look like that's not open to the same vuln?</p>
]]></description><pubDate>Tue, 14 Jan 2025 20:38:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=42703512</link><dc:creator>chavesn</dc:creator><comments>https://news.ycombinator.com/item?id=42703512</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42703512</guid></item><item><title><![CDATA[New comment by chavesn in "Google’s OAuth login doesn’t protect against purchasing a failed startup domain"]]></title><description><![CDATA[
<p>If oauth makes an authenticity claim, it should be true. Saying it's the same user when it's not is bad, clearly.<p>in other words: Google could make a more accurate authenticity claim than they currently do.<p>This problem would be worse without oauth, though, right? With plain email login, all they would need to do is "forgot password" and there wouldn't even be a way to tell.<p>in other words: Email login would never be able to make a more accurate authenticity claim.</p>
]]></description><pubDate>Tue, 14 Jan 2025 20:36:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=42703493</link><dc:creator>chavesn</dc:creator><comments>https://news.ycombinator.com/item?id=42703493</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42703493</guid></item><item><title><![CDATA[New comment by chavesn in "Google’s OAuth login doesn’t protect against purchasing a failed startup domain"]]></title><description><![CDATA[
<p>> Failed startups don’t always shut down cleanly like that.<p>Agreed, and with the number of services and the "ease" of oauth it's likely impossible to even track. You could make a list of the major ones, but there could be hundreds per user, ultimately thousands of unique services used depending on the breadth of the startup's activities.</p>
]]></description><pubDate>Tue, 14 Jan 2025 20:32:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=42703440</link><dc:creator>chavesn</dc:creator><comments>https://news.ycombinator.com/item?id=42703440</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42703440</guid></item><item><title><![CDATA[New comment by chavesn in "I'm So Old: Web Edition"]]></title><description><![CDATA[
<p>> NPM stood for "not my problem"<p>wait...</p>
]]></description><pubDate>Mon, 18 Mar 2024 14:50:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=39745349</link><dc:creator>chavesn</dc:creator><comments>https://news.ycombinator.com/item?id=39745349</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39745349</guid></item><item><title><![CDATA[New comment by chavesn in "900 Sites, 125M accounts, 1 Vulnerability"]]></title><description><![CDATA[
<p>I think it's more like there's more surface area to forget when you have humans handling so many concerns, and it's not likely the part that's changed the most so it's a likely candidate for being "pushed out of the buffer" (of the human).<p>In a more typical model, backend devs focus more on security, while not needing to know the frontend, and vice versa.</p>
]]></description><pubDate>Mon, 18 Mar 2024 14:19:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=39744922</link><dc:creator>chavesn</dc:creator><comments>https://news.ycombinator.com/item?id=39744922</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39744922</guid></item><item><title><![CDATA[New comment by chavesn in "DoorDash raises minimum pay to $29.93 per hour in NYC"]]></title><description><![CDATA[
<p>It seems like that's the point of the story -- they were willing to tip well, and received bad service.  If it came after, then drivers would have a reason to make sure food was delivered fast and efficiently.</p>
]]></description><pubDate>Mon, 04 Dec 2023 21:30:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=38523402</link><dc:creator>chavesn</dc:creator><comments>https://news.ycombinator.com/item?id=38523402</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38523402</guid></item><item><title><![CDATA[New comment by chavesn in "DoorDash raises minimum pay to $29.93 per hour in NYC"]]></title><description><![CDATA[
<p>obviously drivers would <i>want</i> to know it, but is that good for everyone involved? It would make more of an auction but should it even be an auction?</p>
]]></description><pubDate>Mon, 04 Dec 2023 21:27:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=38523362</link><dc:creator>chavesn</dc:creator><comments>https://news.ycombinator.com/item?id=38523362</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38523362</guid></item><item><title><![CDATA[New comment by chavesn in "JetBrains Mono Typeface"]]></title><description><![CDATA[
<p>The ligatures are really interesting, but at a glance I process them so much slower than the raw characters, especially the ones that change the graphical semantics such as <= vs ≤. Does anyone have experience getting used to these and 1) does it end up faster? 2) once you are used to it is it harder than it was before to process the raw characters when reading code in fonts that don't have the same ligatures?</p>
]]></description><pubDate>Wed, 19 Jul 2023 16:40:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=36789284</link><dc:creator>chavesn</dc:creator><comments>https://news.ycombinator.com/item?id=36789284</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36789284</guid></item><item><title><![CDATA[New comment by chavesn in "Times New Bastard"]]></title><description><![CDATA[
<p>Those sans-serif spaces tho...</p>
]]></description><pubDate>Fri, 26 May 2023 22:17:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=36090161</link><dc:creator>chavesn</dc:creator><comments>https://news.ycombinator.com/item?id=36090161</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36090161</guid></item><item><title><![CDATA[New comment by chavesn in "Reroom AI: Test interior design ideas and styles before hiring a designer"]]></title><description><![CDATA[
<p>Keep the same amount of garbage, but make it <i>minimalist</i> garbage</p>
]]></description><pubDate>Tue, 18 Apr 2023 17:51:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=35617352</link><dc:creator>chavesn</dc:creator><comments>https://news.ycombinator.com/item?id=35617352</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35617352</guid></item><item><title><![CDATA[New comment by chavesn in "Mortal Kombat+"]]></title><description><![CDATA[
<p>Ok but I can't unsee that the first two say plus plus ("plus+") and the 3rd just says "plus"?<p>(Very cool project though)</p>
]]></description><pubDate>Fri, 07 Oct 2022 15:23:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=33122593</link><dc:creator>chavesn</dc:creator><comments>https://news.ycombinator.com/item?id=33122593</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33122593</guid></item><item><title><![CDATA[New comment by chavesn in "Types of Deceptive Design"]]></title><description><![CDATA[
<p>"Hey, this looks like darkpatterns.org. ...oh, it is."</p>
]]></description><pubDate>Mon, 18 Apr 2022 04:03:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=31067295</link><dc:creator>chavesn</dc:creator><comments>https://news.ycombinator.com/item?id=31067295</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=31067295</guid></item><item><title><![CDATA[New comment by chavesn in "Netflix Originals: Production and Post-Production Requirements v2.1"]]></title><description><![CDATA[
<p>Yeah, but what about "zoom and enhance"? :)<p>Seriously, sure, 4K is enough for <i>output</i> but who says it's enough for input?  As long as sensors keep getting better, the industry will keep finding ways to take advantage of it until it's essentially required.<p>Imagine a future where you can zoom in on any detail as well as you could with a high-res sensor at capture time?<p>It's not necessary for today's viewing experiences, but we know little enough about what is going to become popular that I wouldn't put ANY bets on "4K" being enough forever.</p>
]]></description><pubDate>Thu, 22 Jun 2017 20:38:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=14615159</link><dc:creator>chavesn</dc:creator><comments>https://news.ycombinator.com/item?id=14615159</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=14615159</guid></item><item><title><![CDATA[New comment by chavesn in "The Correct Way to Validate Email Addresses"]]></title><description><![CDATA[
<p>All of that statistical analysis was actually a bit silly, because I've never heard the "typo" argument as a reason for email grammar validation[1].  Sounds like a straw man.  It didn't need to be disproven.<p>The conclusion is sound (although leaves out a discussion of the whether an email confirmation field is at least better than nothing).<p>[1]: <i>(As a side note, I think the most common explanations for grammar validation are programmer perfectionism and proactively stopping user garbage, such as copy-paste errors or intentionally fluffed fields that will result in a bounced email anyway.)</i></p>
]]></description><pubDate>Thu, 08 Sep 2016 00:11:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=12449160</link><dc:creator>chavesn</dc:creator><comments>https://news.ycombinator.com/item?id=12449160</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=12449160</guid></item><item><title><![CDATA[New comment by chavesn in "Vesper, Adieu"]]></title><description><![CDATA[
<p>It sounds to me like the point is that the market could be much larger if the transaction value were clear to consumers.<p>In the current app store, with the methods that consumers are used to spending money on their phones, for whatever reasons, it's not.<p>It's like when you'll easily spend $30 on drinks on a Friday night, but suffer a shitty note-taking system for years when you could have many of your problems fixed for $5 one time just because you don't know the possible transaction exists.</p>
]]></description><pubDate>Wed, 24 Aug 2016 05:13:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=12349820</link><dc:creator>chavesn</dc:creator><comments>https://news.ycombinator.com/item?id=12349820</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=12349820</guid></item><item><title><![CDATA[New comment by chavesn in "How to Pass a Programming Interview"]]></title><description><![CDATA[
<p>> To do well in an interview, then, you need to be able to solve small problems quickly, under duress, while explaining your thoughts clearly.<p>I certainly hope they aren't interviewing anybody under duress.</p>
]]></description><pubDate>Tue, 08 Mar 2016 19:50:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=11247986</link><dc:creator>chavesn</dc:creator><comments>https://news.ycombinator.com/item?id=11247986</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=11247986</guid></item><item><title><![CDATA[New comment by chavesn in "How Google’s Web Crawler Bypasses Paywalls"]]></title><description><![CDATA[
<p>I agree with you that this is what the law seems to think (being overly broad), but not if you are arguing this is sensical.<p>In other words, yes, the WSJ does intend to only give Google access to their content, and not the general public.<p>But no, the WSJ has not "authorized" Google by anything more official than a bank telling their security guards to let anyone into the vault who is wearing a blue t-shirt.<p>So yeah, I agree with you, there is a lot of conflation of technical means and the law, but we also shouldn't be granting to the WSJ that they are doing any real "authorizing" here, beyond wishing it and hoping it stays true.</p>
]]></description><pubDate>Sat, 20 Feb 2016 02:01:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=11138277</link><dc:creator>chavesn</dc:creator><comments>https://news.ycombinator.com/item?id=11138277</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=11138277</guid></item><item><title><![CDATA[New comment by chavesn in "The bug that almost killed Google's Pac-Man doodle"]]></title><description><![CDATA[
<p>Where did this title come from?  Not only is it not the title of the post in question, but it's quite inaccurate -- the article doesn't even come close to claiming that anything "almost killed" the doodle.<p>With that said, I clicked the click-bait title, and I enjoyed the article.  (shrug.)</p>
]]></description><pubDate>Tue, 17 Nov 2015 04:04:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=10579106</link><dc:creator>chavesn</dc:creator><comments>https://news.ycombinator.com/item?id=10579106</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=10579106</guid></item></channel></rss>