It's not a Claude generated website without at least one `backdrop-filter: blur(1000px)` element that slows older machines to a crawl
addandsubtract 3 hours ago [-]
It's missing the captcha that fails to load and then makes you retry three times.
JK-Swizzle 17 hours ago [-]
It is missing the fade in on scroll.
possan 4 hours ago [-]
Needs a cookie banner, 3s delayed sign up to our newsletter and enable push request
Bolwin 17 hours ago [-]
Love the X logo that goes to bluesky
noman-land 16 hours ago [-]
This needs bluish dark mode with accent color and pills with a little rounded colored border on just the left side.
walrus01 15 hours ago [-]
> $ curl -fsSL install.sh | sh # you'd be stupid to run that, slop or not
I wish more people would point this out.
Akronymus 11 hours ago [-]
I've legitimately seen one project that basically says to do that, but with "your ai agent". At least piping to sh is deterministic and, you can pipe to a filw and check the script
"Claude, install these 215 npm dependencies from unvetted repositores, make no mistakes"
xigoi 7 hours ago [-]
I still haven’t seen anyone point out how this is more dangerous than running an executable that you obtain any other way.
ffsm8 6 hours ago [-]
you can detect `curl | bash` server-side and serve a different payload for those (compared to curl -O file, wget etc), hence its an effectively undetectable attack vector.
Executables on the other hand can be inspected and prodded, so the likelihood of something going amiss and consequently security agencies finding out about it is significantly higher.
neither of those is secure of course, we're just discussing different levels of dangers. And curl|bash being worse, albeit not that much
(and the -L here is the extra cherry on top. piping a redirect to a shell is just monkas)
chunkyguy 6 hours ago [-]
What is wrong with this layout?
addandsubtract 3 hours ago [-]
There's nothing wrong with it, per se. It's just that it's overused and filled with random garbage stats that no one cares about.
0: https://news.ycombinator.com/item?id=49297469
https://news.ycombinator.com/item?id=49307700
I wish more people would point this out.
https://github.com/0xeb/ghidrasql
Executables on the other hand can be inspected and prodded, so the likelihood of something going amiss and consequently security agencies finding out about it is significantly higher.
neither of those is secure of course, we're just discussing different levels of dangers. And curl|bash being worse, albeit not that much
(and the -L here is the extra cherry on top. piping a redirect to a shell is just monkas)
I giggled.
https://news.ycombinator.com/newsguidelines.html